Verify signed AIFeed permissions, fetch token-budgeted markdown, and verify assets for AI agents.
Publisher side — sign what agents may do with your content:
npx aifeed keygen --out .aifeed # Ed25519 key pair
npx aifeed site build ./public --domain example.com \
--key .aifeed/aifeed-private.pem --llms --inject # manifest + page markdown + index
npx aifeed validate ./public --domain example.com # verify locally
Prefer zero config? npx aifeed init --domain example.com --dir ./site creates the keys,
a signed manifest, and the DNS/host setup guide in one step.
Agent side — verify any domain in 3 lines:
npm install @aifeed/verify
const { verifyRemote } = require('@aifeed/verify');
const out = await verifyRemote('example.com'); // discovery → signature → DNS anchor
console.log(out.result, out.anchor.status); // VERIFIED anchored
TypeScript: import { verifyRemote } from '@aifeed/verify';
Where to go next: Why AIFeed? · agent quickstart ·
publisher AI guide · Studio publisher app ·
npm: aifeed CLI ·
@aifeed/verify
AI agents now drive a large and growing share of web traffic, but the signals that say what they may do are unsigned text files. Anyone can edit them, nothing binds them to a domain, and there is no way to revoke them. The asymmetry is measurable:
robots.txt rules in a single half-year (one vendor).AIFeed replaces "please respect this file" with a cryptographically verifiable declaration, plus lean agent-ready content that cuts cost on both sides.
/.well-known/ai.json: per-use permissions
(training, retrieval, quote, …), crawl limits, license, revision._aifeed TXT) so a manifest cannot be spoofed by another
domain.pk2 cross-check), keep a bounded overlap, cut over, then revoke the
old key permanently. Runbook: docs/rotation.md.For AI agents: the check-first guide (discovery → verification → permission
decisions → delta → failure handling) is in
docs/agent-quickstart.md,
with a runnable example at
examples/agent/compliant-agent.js.
Independent Python package (standard library only):
pip install aifeed
from aifeed import verify
report = verify.verify_directory('./my-site', domain='example.com')
print(report['result'], report['errors'])
Prefer the repository? The same CLI is here (zero dependencies, Node ≥ 20):
cd aifeed-protocol
node bin/cli.js keygen --out keys/
node bin/cli.js validate https://example.com
node bin/cli.js site build ./public --domain example.com --key keys/aifeed-private.pem
| Profile | Media type | Extension | Notes |
|---|---|---|---|
| AIFeed Markdown (native) | text/aifeed+markdown | .aifeed.md | In-band signed policy block, token budget, translation alternates, triage metadata |
| MAKO (compatibility) | text/mako+markdown | .mako.md | External MAKO trust profile, served from the same signed bytes with its own signature context |
Dual-stack origins serve both; cross-format replay is rejected by design.
All numbers are reproducible from committed artifacts (npm run bench:mako,
npm run bench:enforcement); the test environment is a single machine on loopback
networking with a synthetic 60-page corpus. Honest baseline included.
| What | Result | Label |
|---|---|---|
| Conversion to markdown profiles vs HTML | −68.83 % transferred bytes | measured |
| Delta consumption (10 % pages changed) | −95.73 % vs HTML crawl | measured |
| Publisher egress bytes / CPU / peak connections | −55.19 % / −56.23 % / −88.24 % | measured (simulation) |
| AI-side received bytes (all profiles / compliant client) | −54.84 % / −72.93 % | measured (simulation) |
| Unchanged pages skipped | 14 of 18 | measured (simulation) |
| Signature verification cost | 0.70 ms / page | measured |
The 30-day live pilot has not run yet; projections per 1,000 tenants are labeled as model extrapolations, and vendor claims of up to 94 % token reduction require semantic summarization this project does not perform automatically.
| Path | Contents |
|---|---|
lib/ + bin/ | Zero-dependency reference implementation and CLI |
packages/ + clients/python/ | Published packages: CLI (aifeed), SDK (@aifeed/verify), MCP server, build plugins (@aifeed/frameworks), PyPI aifeed verifier |
conformance/ | Conformance vectors: 34 manifest · 39 MAKO · 11 AIFeed Markdown |
wp-plugin/ | WordPress plugin: signed manifest, AIFeed Markdown + MAKO dual-stack, /llms.txt |
spec/ | Specifications EN/ID: manifest v0.1/v0.2, AIFeed Markdown v1.0 |
schema/ | JSON Schemas for manifests, signatures, AIFeed Markdown, MAKO |
paper/ | Preprint: LaTeX source, PDF, claim ledger, arXiv bundle |
docs/ | Agent quickstart, deploy and namespace guides, Indonesian project notes |
studio/ | Zero-dependency local publisher app: crawl, declare, build, verify, export, and rotate |
docs/REFERENCE.md | Reference implementation details, what gets verified, CLI quickstart |
spec/en · spec/id · schemasdocs/REFERENCE.mdAGENTS.mddocs/architecture.md · Release guide: docs/release.mddocs/agent-quickstart.mddocs/publisher-ai-guide.mdstudio/README.mdskills/aifeed/SKILL.md (installable via ClawHub: npx clawhub install aifeed)docs/penjelasan-aifeed.html (source of https://aifeed.md/penjelasan.html)SECURITY.mdGOVERNANCE.mddocs/deploy-site.mdpaper/ARXIV-SUBMISSION.md1.0.0-draft — the specifications are not frozen yet. Wire versions:
manifest 0.1/0.2, AIFeed Markdown 1.0, MAKO 0.2.Specifications CC BY 4.0 · reference code and plugin MIT · vectors CC0.
Contact: contact@aifeed.md — security reports per
SECURITY.md.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y aifeed-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-denyn1-aifeed-mcp-server": {
"command": "npx",
"args": [
"-y",
"aifeed-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceAIFeed works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.