Contents

Learn · 1 of 10

What is PACT

One person’s agent calling another’s, directly, under an identity the person holds and a contact both people approved.

Alina’s wallet holds the root: her identity Bharat’s wallet holds the root: his identity issues a leaf issues a leaf Alina’s host: an MCP server https://a.example/mcp Bharat’s host: an MCP server https://b.example/mcp both approved direct, sealed her agent and her private tools calendar, mail: MCP as well his agent and his private tools calendar, mail: MCP as well no directory no relay no platform in between
Two people, two hosts, one call. Each wallet issues its own host a leaf; the hosts call each other directly once both people have approved the contact.

Two agents, one call

Both sides are symmetric: every participant runs, or is hosted with, an agent and exposes an MCP server over HTTPS. “A messages B” is A’s agent making one mTLS-authenticated MCP tool call to B’s server. B’s server identifies the caller by the certificate chain it proves, validates that chain to a root pinned in B’s contact list, and shows exactly the tools B’s permission settings grant that contact (§ 1). Humans sit above their agents: they approve contacts, set permissions, hold the wallet that issues their host its certificate, and can type messages that travel the same rails.

The person is the authority

An identity is a root certificate: self-signed, its private key held by the person in a wallet and used for one thing, issuing certificates. A host — the person’s own machine, or a provider — serves the identity under a leaf certificate the root issued, which carries the host’s own key, the one address the identity answers at, and the dates between which the host’s authority runs (§ 2). The root can be derived from a passkey rather than stored (§ 2.1). Contacts pin the root and learn the current leaf from every exchange, so a renewal needs no announcement and moving hosts loses nobody (§ 5.3, § 14.3). Identity: root, leaf, passkey draws this out.

Nobody reaches you until you both say yes

There is no directory: a bare fingerprint resolves to nothing, and every relationship starts from a contact card or an invite (the non-goals). A card is a standard vCard carrying the leaf certificate, shared over any channel people already use (§ 3); an invite is a short URL whose settings live with the issuer (§ 4). Contacts are always mutual and always human-approved (§ 5). A stranger reaches a guest tier of two tools, redeem_invite and request_contact, and nothing else (§ 6.1).

Everything a contact may do is a tool

Sending a message is calling the other party’s send_message tool. Messages, media, status, availability and calendar booking are MCP tools, visible and callable only per the owner’s permission settings for that contact (§ 6.2, § 8). Anything else a person wants to expose — a document dropbox, a task intake — is another MCP tool on the same server behind the same switchboard.

What it leaves out, on purpose

The text states its non-goals up front (the non-goals): no forward secrecy at the envelope layer; edges see metadata; no anonymity; no directory; no store-and-forward, because a person who must be reachable while their own machine is off is hosted (§ 9); no recovery of a lost root; and no post-quantum cryptography yet, with the path recorded in § 13.5. Security model and trade-offs goes through each.