Contents

PACT 2 against PACT 1

What’s new in PACT 2

The identity is yours, not your host’s. Everything below follows from that one change; each item links to the section of the current text that specifies it, and the removed items say what their removal costs.

What changed, in one sentence

In PACT 1 the identity was a keypair held by the machine that ran the agent — one keypair per person, per agent installation, whose TLS client certificate was the identity — and a relay named in the card carried a person’s mail while that machine was offline (PACT 1 § 2, § 9). In PACT 2 the identity is a root certificate the person holds, a host serves it under a leaf the root issued, and there is no relay (§ 2, § 9).

Added or changed

Removed, and what each removal costs

Kept from PACT 1

The shape of the protocol is unchanged. Every participant exposes one MCP server, and sending a message is calling the other side’s tool (§ 6); contacts are vCards shared over the channels people already use (§ 3); invites are short URLs whose state lives with the issuer, revocable by deleting them (§ 4); adding a contact is always a manual, human approval (§ 5); conversations are threads a human can type into (§ 7); permissions are a per-contact switchboard (§ 8); a stranger reaches a guest tier of two tools (§ 6.1); and sealed envelopes carry identity and confidentiality past a terminating edge (§ 13).

Still not there, and said so

No forward secrecy at the envelope layer: a later compromise of a leaf key decrypts ciphertext recorded while that key was current, bounded by the leaf’s lifetime (§ 13.5). No recovery and no rotation of a lost root (§ 2). No post-quantum cryptography yet, deferred by decision with the path recorded (§ 13.5). No directory, no anonymity, and metadata that carriers see (the non-goals, § 11).