awnest
Prove there is a human before you let them into the nest.
What it does
that there is a person on the other end
a verdict with evidence, where "we could not tell" is not "yes"
Overview
Any surface an agent can use, a bot can flood. CAPTCHA is hostile to the humans it is meant to serve and is beaten by the machines it is meant to stop, so the check has to be something other than a puzzle -- and every check that does exist fails OPEN, because "we could not tell" and "it is fine" reach the caller as the same empty value.
awnest
Docs · Source · pip install awnest · The Aither World
The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awnest is one of its 67 bricks — each installs on its own, runs offline, and needs no account.
Start here: Gate one action behind a human check and watch an automated caller fail it.
Prove there is a human before you let them into the nest.
```bash
pip install awnest
```python
from awnest import Nest, HmacKey, Policy
nest = Nest("action:checkout", key=HmacKey(SECRET), policy=Policy(min_score=70))
nest.require(token=attestation, subject=user_id) # raises NotAdmitted
A nest is not a wall. It is a place with doors, and the job is knowing who came through which one.
The one thing this is built around
Every human check ever written fails open. Not by decision — by arithmetic.
"We could not tell" and "it is fine" reach the caller as the same thing: an empty
result, a None, a score of 0, a 500 somebody catches. The gate then denies
nobody, and it passes every test written for it, because the tests assert that a
bot is refused — and a bot is refused, right up until the evaluator has a bad
afternoon.
So the verdict type here has no member meaning "ok":
```python
Verdict.HUMAN # earned it
Verdict.AGENT # declared it
Verdict.UNKNOWN # everything else, including "the check did not run"
UNKNOWN is what you get from an absent evaluator, an unparseable reply, a stale
attestation, an empty evidence list, and a policy nobody configured. Admission is
granted by naming a verdict, never by failing to reach one.
Two more rules fall out of the same idea:
- Scored zero is not unscored.
Evidence(score=None)means nobody judged it. It counts toward nothing and it is reported as nothing — never as a zero, which would turn a judge outage into a permanent accusation against real people. - A presented-but-invalid credential is not an absent one. A token that does not verify refuses there; it never falls through to whatever weaker evidence came with it. Forgery is the one event you want to be loud.
"Human or bot" is the wrong question
If the only way through a door is to be human, every legitimate automation is taught to imitate one, and you have spent your budget training the thing you are trying to detect.
```python
from awnest import Evidence, DECLARED_AGENT, assess
assess([Evidence(DECLARED_AGENT, source="nightly-sync")]).verdict # Verdict.AGENT
A caller that declares itself is believed, and a declaration cannot be
outvoted by a good score presented alongside it. Honesty has to be the cheaper
path or nobody takes it. Whether the agent door is open is one flag —
Policy(allow_agents=True) — decided per door, never inherited.
Not a CAPTCHA
CAPTCHA asks a machine-solvable question and charges the cost to the human. It is worst for the people it should serve most, and the machines beat it, so the only party reliably filtered is the customer.
The bundled challenges ask instead for something a person has and a model does not: a particular life — an embodied sensation, felt time, a real reaction to being asked. Scoring is somebody else's job (a model, a person, a service), and this package refuses to pretend otherwise.
```python
from awnest import select, judge_prompt
from awnest.judge import score_answers
issued = select(3) # one per category, never the same twice
evidence, judgement = score_answers("http://127.0.0.1:8080", issued, answers,
model="whatever-you-run")
This is not proof, and the honest framing is cost. A determined operator can pay a person, or feed a model a real diary. What it does is move a fake account from free to about a human-minute, which is the entire game for spam economics. Need more? Stack another signal — the verdict plane takes several and reports the weakest, so adding one can never weaken the answer.
The judge sees the most personal thing a stranger will ever type into your product.
base_urlhas no default on purpose: nobody should make that decision by inheriting one.
Attestations: bound, offline-verifiable, one-use
The check and the door are rarely the same process. Calling back to the verifier makes every gated action depend on it being up; a boolean in a session is a fact with no provenance. So: a small signed statement.
```python
token = nest.issue(user_id, assessment, ttl_s=3600, method="challenges")
The format is shaped by replay, which is the real attack — not "bots solve the puzzle" but "a human solves it once, cheaply, and the result is reused":
| field | drop it and… |
|---|---|
sub |
the token is transferable between people |
aud |
one solve opens every door that trusts the issuer |
ctx |
it can be lifted onto a different commit, request or transfer |
nonce |
one solve opens the same door forever (with a Seen ledger, it does not) |
exp |
the damage is unbounded in time |
ctx is symmetric and unforgiving: a token carrying a context is refused by
any verifier that does not name the same one, and a verifier that names a context
refuses a token that carries none. A binding either side may decline to check is
not a binding, and forgetting to check is what actually happens.
The token names its algorithm and the key decides it — a mismatch is a
refusal. Reading alg out of the token is how alg: none and HMAC/RSA confusion
emptied a decade of JWT deployments.
HmacKey is stdlib and means every verifier is also an issuer: fine inside one
trust domain, wrong the moment a third party verifies. pip install
awnest[ed25519] for the asymmetric half.
Signing commits with it
A signed commit says a key was present. When most commits are written by agents holding the same keys as the humans who run them, that is no longer the interesting fact. The interesting fact is whether a person stood behind the change, at what strength, and which person.
```bash
awnest commit-attest --identity "$AWIAM_SUBJECT" --repo acme/widgets \
--tree "$(git rev-parse HEAD^{tree})" --score 82 --method challenges
# -> Awnest-Attestation: awn1.… (append it as a trailer)
awnest commit-verify --message .git/COMMIT_EDITMSG --repo acme/widgets \
--tree "$(git rev-parse HEAD^{tree})"
The binding is the tree, not the commit sha — an attestation lives inside the
message, so it cannot contain a hash of the commit that contains it. That means it
survives a reword, a rebase and a cherry-pick (same content, still attested) and
does not cover the parent. If you need "approved on this branch", that belongs
in the audience: repo:acme/widgets@release is a different door.
verify_commit re-reads the tree in front of you and compares. A valid
attestation lifted off another commit verifies perfectly; only that comparison
notices.
What it composes with
Each of these is a door with a name, built rather than typed
(audience("channel", "#help")) because an issuer's spelling drift mints tokens
for a door nobody guards — silently, unlike a verifier's, which refuses everyone
and gets fixed in minutes.
| with | the door | the question |
|---|---|---|
| an identity system | — | who is this caller (the sub in the attestation) |
| an authz system | — | what may they do — humanity is an input, not a replacement |
| a chat/relay | channel:#help |
may this caller post here |
| version control | repo:acme/widgets |
did a person stand behind this change |
| a mesh | mesh:home |
may this peer join |
| a tunnel | tunnel:api |
may this caller reach a service with no public address |
| an audit trail | — | every verdict, including the refusals, kept where gaps show |
Nothing above is a dependency. awnest holds the verdict, the format and the door; who you ask and what you do with the answer stay yours.
Command line
```
awnest challenge -n 3 issue a set of challenges (JSON)
awnest judge --url … --model … --answers a.json
awnest mint --subject u_42 --audience action:checkout --score 80
awnest verify TOKEN --audience action:checkout
awnest gate TOKEN --audience action:checkout --subject u_42
awnest commit-attest / commit-verify the git trailer, above
awnest alignment quiz print the alignment questions
awnest alignment score --answers a.json
awnest alignment badge --answers a.json --subject u_42 --out ./badge
awnest alignment verify TOKEN --subject u_42
awnest --self-test prove this package can still fail
Exit codes: 0 admitted / ok · 1 refused or broke · 2 you asked wrongly.
The alignment door (the fun one)
The rest of awnest asks is there a person here. The alignment door asks which of the nine are you? — a deterministic, no-judge quiz of 18 scenarios into the classic D&D-style chart: two axes (law↔chaos, good↔evil), nine cells, and a badge that is a CLAIM, not a screenshot.
```python
from awnest import HmacKey, score_answers, mint_badge, badge_svg, verify_badge
result = score_answers({...}) # {question_id: option_id}
token = mint_badge(HmacKey(secret), sub="u_42", result=result)
svg = badge_svg(result, subject="u_42") # the wall badge
verify_badge(token, HmacKey(secret), subject="u_42") # raises on anything wrong
The attestation is bound to the exact result (ctx carries the alignment id
AND both axis scores), so a badge cannot be relabeled without invalidating the
token; verification is offline and public — that is what attestations are for.
The subject is whoever holds the identity, and the platform surface
(genesis /myspace/alignment/*) takes it from the session, never from the
caller. questions_public() omits the weights the way public() omits the
judge's criteria: the protocol does not hand out the answer key.
Licence
Apache-2.0.
The aw family
Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.
Each installs on its own, works offline, and needs no account.
| instead of trusting | you check | |
|---|---|---|
| awdk | a framework's idea of how your agents should run | one loop you can read, pointed at a backend you already pay for |
| awskills | that an agent knows your procedure | the procedure written down, versioned, and loadable by any agent |
| awpack | that the pack you want shipped inside somebody's SDK, under whatever licence that SDK happens to carry | the pack as its own versioned artifact, with its own licence, that any agent runtime can install |
| awm | that memory stayed in its lane | tenant:user:project scopes, so a write cannot cross a boundary |
| awdesk | that the agent is somewhere behind a browser tab | a tray icon, a face on your desktop, and the decision card that pops when it needs you |
| awnode | a vendor's cloud with every prompt | a local gateway routing to backends you chose |
| awgraph | that grep found everything | an AST + tree-sitter call graph an agent can traverse |
| awgit | that no one else is editing this file | a lease, refused at commit time if you do not hold it |
| awdelphi | one agent's confident take on a decision | the round trace, the anonymity, and who dissents |
| awclassify | a filename, a folder, or whoever last touched it | doc_type, visibility, audience and topics, with the evidence lines that decided each |
| awdecide | a hosted classifier's probability that never learns whether it was right | the decision, its probability, and the calibration curve from your own resolved outcomes |
| awtoll | that your tooling is saving you context | the measured token cost of each tool call, and what the alternative cost |
| awseal | that the artifact came from who you think | an Ed25519 seal — the key that verifies is not the key that forges |
| awshare | that the download is intact | content-addressed bundles, verified on fetch |
| awsuite | that an agent holding your mailbox will not send on its own | every send, draft, upload and create returns a dry-run until confirm is true |
| awnest (you are here) | that there is a person on the other end | a verdict with evidence, where "we could not tell" is not "yes" |
| awrena | a leaderboard someone can edit, and votes nobody counted | a scored duel with both answers kept, and a result bound to them |
| awnboard | a share link anyone who sees it can use | an invitation addressed to one person, for one gate, revocable |
| awnix | that the box is what you left it as | an immutable image you built, with atomic rollback |
| awrecover | that the restore worked | a restore that fully lands or does not land at all |
| awstorage | a du you ran last month, and a peers file that says 3 TB free | an inventory snapshot per node with a diff since the last one, and each tree classified re-fetchable or not |
| awrelay | a SaaS in the middle of your agents | findings, alerts and coordination over your own transport |
| awask | that anyone read the paragraph where you asked | the ask itself, with a button that steers the session that raised it |
| awmail | a mailbox somebody else can read | mail your agents send and receive over your own server |
| awswarm | that a model either fits your GPU or it doesn't run at all | a placement plan and an acquisition-probability estimate before you spend on a run |
| awfind | one vendor's idea of the web | results from whichever providers you configured |
| awbrowse | that the page said what you were told | the render, the DOM and the requests it made |
| awvoice | that a cloud vendor may hold your audio | a transcript and a wav from a service you host |
| awvision | a filename and a caption somebody wrote | what a model actually reports about the pixels |
| awscreen | a selector that was true when the page was written | the elements actually rendered, by what they look like |
| awbeads | that a layout your users built survives the next deploy | the arrangement as data you can read back, diff, and hand to another surface |
| awbonsai | that inference always means a request left the machine | a WebGPU model answering on the tab's own GPU, with a consent record logged before it ever loaded |
| gawbbonet | the model to keep a 300-message campaign coherent by itself | campaign facts recalled from scoped memory you can list and edit |
| aitherkvcache | a vendor's quantisation defaults | sub-byte KV cache kernels you can benchmark yourself |
| awrtifact | a hand-rolled split script and a hand-edited worker manifest | byte-verified parts in a release, served with Range + CORS, sizes asserted by a live gate |
| AitherZero | a pile of scripts nobody has numbered | numbered, discoverable automation with declarative playbooks |
| AitherConnect | what a page tells your browser to do | a federated search and desktop bridge you host |
| awreason | a confident paragraph | the phases it went through, and every tool call it made to get there |
| awrecurse | that everything you pasted in was actually read | which slices it opened, and what it concluded from each |
| awprism | the first explanation that fits | the ranked alternatives, and the observation that separates them |
| awrepl | what the agent believes the value is | the value, printed from the live session |
| awreport | that the report you pasted carried no token in it | a redacted report, and the duplicate it merged into instead of filing twice |
| awresearch | a summary of pages nobody opened | every claim against the source it came from |
| awfocus | twelve terminal tabs and a bad memory | one command that names every session, finds any transcript, and opens or steers the one you want |
| awgym | that a world model learned anything from the games it saw | transitions captured from real play, fed back, and the retrodiction score falling on grids it never saw |
| awpredict | a model because it trained without erroring | its prediction against a self-updating lookup, on the rows that are actually novel |
| awevolve | that your optimisation loop is finding anything | every version it kept, the score that version earned, and the edit that produced it |
| awsh | that you already know the name of the command | what it decided your line meant, before it acts on it |
| awmine | that a session's lesson survived the session | a row per outcome, a candidate per lesson, and the transcript line each one came from |
| awrise | that a scheduled agent ran at all, and ran exactly once | a durable record of every wake -- fired, skipped, overlapped or timed out -- each with its reason |
| awkno | that the docs site is up, or that you remember the family | the whole ecosystem in your terminal, with no network at all |
| awwall | that a service only talks to the hosts you think it talks to | an explicit egress allowlist, where a denial names the rule that denied it |
| awembed | a general-purpose embedder that has never seen your code | a held-out split of whole directories, scored teacher vs student vs int8 |
| awtax | a closed tax app's sealed file you can never read again | a plain, provider-neutral schema of every figure, with the page it came from |
| awsettings | that you will remember to re-approve the same thing on every box you work from | one profile, unioned rather than overwritten, with the credentials left behind |
| awavatar | a cloud 3D vendor's opaque task id | a manifest with a sha256, a licence and a rig-audit verdict per file |
awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.
The Aitherium ecosystem
Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.
| repo | what it is | pages |
|---|---|---|
| awdk | Build AI agent fleets — 3 lines, any backend, local or cloud | docs |
| awskills | Portable agent skills — self-contained procedures an agent loads on demand | docs |
| awpack | First-party agent packs — the ones we build, versioned and installable on their own | docs |
| awm | A portable, scoped agent memory | docs |
| awdesk | Aither World Desk -- the desktop body of AitherOS Online: tray, avatars, decision cards, the Living Desktop as an overlay | docs |
| awnode | A lightweight local gateway — bridges your apps to the AI backends you chose | docs |
| awrun | A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds. It also judges whether the runner pool is big enough for the queue it is draining, and can ask a host to grow it -- reserving capacity is zero-sum, so a saturated pool needs more of it, not a different share of it | docs |
| awgraph | A semantic code graph for agents — AST + tree-sitter, call graphs | docs |
| awgit | Semantic version control on top of git — edit-ops and leases | docs |
| awdelphi | Anonymous multi-round expert panels — a converged answer with a trace | docs |
| awclassify | Classify any document -- what it is, who may read it, who it is for, what it is about | — |
| awdecide | One typed-decision contract -- choice / score / bool with a probability -- over a ladder of backends you already run (rules, tiny local models, an LLM's logprobs), fail-closed, with a Brier ledger that resolves every decision against its outcome | — |
| awtoll | What every tool call costs you in context, measured from your own transcripts | docs |
| awseal | Sign an artifact so a stranger can verify it | docs |
| awshare | Publish an artifact and fetch it back verified | docs |
| awsuite | Your Google Workspace as agent tools, and no write happens without a yes | — |
| awdit | An append-only audit trail whose gaps are DETECTABLE | docs |
| awbac | Role-based access control that fails closed and explains itself | docs |
| awiam | Who is this caller? A directory and session store that fails honestly | docs |
| awtunnel | Reach a service that has no public address | docs |
| awnest (you are here) | Prove there is a human before you let them into the nest | docs |
| awrena | Put two agents head to head and get a verdict you can check | docs |
| awnboard | A front gate you can put in front of anything, and hand someone the key to | docs |
| awnix | A Linux you can hand to an agent — immutable base, capabilities included | docs |
| awrecover | Labelled snapshots with an all-or-nothing restore | docs |
| awstorage | Every drive on every node, indexed, classified and diffed -- so you can see what you own before you delete it | docs |
| awrelay | Portable agent messaging — findings, alerts, coordination | docs |
| awask | Your agent asks you a question — and acts on your answer | docs |
| awmail | Give an agent an email address — send, and actually receive | docs |
| awnet | The agentic web — agents host a mesh, and agents join one | docs |
| awswarm | Run one model too big for any single GPU across a pool of small ones | — |
| awfind | A portable search client — query, results, ranking | docs |
| awbrowse | A portable browser client — navigate, console, network, DOM, screenshot | docs |
| awvoice | Hear and speak — transcribe audio, synthesize a voice | docs |
| awvision | See an image — describe it, ask it a question, compare two | docs |
| awscreen | See this machine — what is on screen, and where to click it | docs |
| awkit | Render an agent panel from a tool result — one component, any React app | — |
| awbeads | A spatial canvas for a page — arrange things, connect them, and keep the arrangement | — |
| awbonsai | Run a real model in the visitor's own browser — no server round trip, no upload | — |
| awknowledge | How to run a coding agent so the result survives — the laws, with evidence | docs |
| awbrain | Your history as a wiki of linked markdown — claims pinned to the evidence | — |
| gawbbonet | GobboNet campaigns with a real agent brain — scoped memory, graph recall | docs |
| aitherkvcache | Near-optimal KV cache quantization for LLM inference — sub-byte compression | docs |
| awrtifact | Deliberately chunk artifacts into GitHub release assets — the productized aitherkvcache mirror lane | docs |
| AitherZero | PowerShell 7+ automation framework — numbered, self-describing scripts | docs |
| AitherConnect | Browser extension — federated AI search, page context, and the Living OS overlay | docs |
| awreason | A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer | docs |
| awrecurse | Answer a question over a context far larger than the window — recursively, with the trace kept | docs |
| awprism | Turn a failure into ranked hypotheses — and say what would confirm each one | docs |
| awrepl | A REPL an agent can actually use — state that survives between turns | docs |
| awreport | File a bug report that has already scrubbed your secrets and collapsed the duplicate | — |
| awresearch | Ask a research question, get a cited report you can check | docs |
| awfocus | See, search and steer every Claude session from one command | docs |
| awgym | An ARC training gym — a game a world model can watch, and six roles that play through it | docs |
| awpredict | Predict what your environment does next, and how surprised you were | docs |
| awevolve | Point an agent at a file and a command that scores it, and let it improve | — |
| awsh | Your terminal answers you -- type a question where a command would go | docs |
| awmine | Mine what your agents did -- outcomes, lessons and procedures out of the transcripts they left behind | — |
| awrise | Wake an agent on a schedule, let it do one thing, and put it back to sleep | docs |
| awkno | The man page for the Aither World — every brick, stack and law, offline | docs |
| awwall | Say what a workload may reach, and watch everything else fail closed | docs |
| awrouter | OpenRouter for your own fleet: pick a model backend by cost/latency/ capability, fail over, fit the context window, stream. Standalone, OpenAI-compatible, no Aither-specifics required to be valuable | — |
| awembed | Train an embedding model that knows your corpus, and prove it beats the big one | docs |
| awtax | Turn any tax PDF -- returns, W-2, 1099, statements, even scans -- into structured data you can check | docs |
| awflow | A deterministic workflow runtime — chain agent calls with journal replay and budget control | docs |
| awsettings | Your agent's permissions and config, following you to the next machine | docs |
| awavatar | One character spec in, a rigged, animated, multi-style avatar pack out | docs |
Built on llama.cpp · vLLM · ComfyUI · CentOS Stream · Podman · Docker · LanceDB · WireGuard · FFmpeg · Blender + Rigify · headroom · SANA · Hunyuan3D · repowise · Playwright · Chromium · Next.js · React.
The Aitherium Ecosystem
Portable tools you adopt one at a time. Each one works alone.