{"_id":"@cana-ai/walkie-talkie","_rev":"3-362117c29688919cf8851916180ed7f4","name":"@cana-ai/walkie-talkie","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@cana-ai/walkie-talkie","version":"0.1.0","keywords":["walkie-talkie","websocket","message-bus","ai-agents","claude-code","real-time","mcp","cana"],"author":{"name":"Himansh Raj","email":"iamthehimansh@gmail.com"},"license":"MIT","_id":"@cana-ai/walkie-talkie@0.1.0","maintainers":[{"name":"himansh.raj","email":"himansh.raj@colate.io"},{"name":"prasadpanda","email":"prasad.p@colate.io"}],"homepage":"https://github.com/Colate-Ltd/cana-walkie-talkie","bugs":{"url":"https://github.com/Colate-Ltd/cana-walkie-talkie/issues"},"bin":{"cana-walkie-talkie":"dist/server.js"},"dist":{"shasum":"ebebcdb72ba519cd38ca4c1a9e1d7210685e424c","tarball":"https://registry.npmjs.org/@cana-ai/walkie-talkie/-/walkie-talkie-0.1.0.tgz","fileCount":21,"integrity":"sha512-wa/YypgcaQoiI2Mz4BaiOd5n+2hjATQQMRsiFj14H0TSehUBgZErbW9xJTojlvPHaw3lu/IJCUAA/LHVJNErjQ==","signatures":[{"sig":"MEQCIEjhaX4lMKHrsbtlwSVmTzh0Xfz8wJCat2Kogfa5/mwjAiAm/Z6Ny2r2mIGdghtU7ElcGHPiHwqdRnyviCvnVHjJeg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":63844},"type":"module","engines":{"node":">=22.5.0"},"gitHead":"ae23a3ad6c551047175dfd95962bd2718c7819e2","scripts":{"dev":"tsx watch src/server.ts","test":"tsx test/smoke.ts","build":"tsc -p tsconfig.build.json","start":"tsx src/server.ts","test:cld":"bash test/run-cld-agents.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:multi":"bash test/run-multi-agent.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"himansh.raj","email":"himansh.raj@colate.io"},"repository":{"url":"git+https://github.com/Colate-Ltd/cana-walkie-talkie.git","type":"git"},"_npmVersion":"11.13.0","description":"Open-source real-time message bus for human↔agent and agent↔agent coordination over WebSocket. The community core of Cana Walkie-Talkie.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ws":"^8.18.0","zod":"^3.24.1","express":"^4.21.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","@types/ws":"^8.5.13","typescript":"^5.7.3","@types/node":"^22.10.5","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/walkie-talkie_0.1.0_1782388214627_0.37642471702753477","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@cana-ai/walkie-talkie","version":"0.1.1","keywords":["walkie-talkie","websocket","message-bus","ai-agents","claude-code","real-time","mcp","cana"],"author":{"name":"Himansh Raj","email":"iamthehimansh@gmail.com"},"license":"MIT","_id":"@cana-ai/walkie-talkie@0.1.1","maintainers":[{"name":"himansh.raj","email":"himansh.raj@colate.io"},{"name":"prasadpanda","email":"prasad.p@colate.io"}],"homepage":"https://github.com/Colate-Ltd/cana-walkie-talkie","bugs":{"url":"https://github.com/Colate-Ltd/cana-walkie-talkie/issues"},"bin":{"cana-walkie-talkie":"dist/server.js"},"dist":{"shasum":"0ba6bf9d56c79302fec4b6270a75b86ead5910c4","tarball":"https://registry.npmjs.org/@cana-ai/walkie-talkie/-/walkie-talkie-0.1.1.tgz","fileCount":21,"integrity":"sha512-lOb1Ph0t+JAcc1vq3xoOuUKazU+RN5uF2wb1duYL7XgVxKky060oM5IJaBHLn9T5g6HYc0fSP0ocsWoQvSW9mw==","signatures":[{"sig":"MEYCIQDNaV59GI4GLE5vkjEE4HULCTf0wLoNL0vZufe/6HmQ6wIhAIdhnT49PFkdW0wJA6W8dmU+1q905dsmcOylasCSjqs4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65124},"type":"module","engines":{"node":">=22.5.0"},"gitHead":"ae23a3ad6c551047175dfd95962bd2718c7819e2","scripts":{"dev":"tsx watch src/server.ts","test":"tsx test/smoke.ts","build":"tsc -p tsconfig.build.json","start":"tsx src/server.ts","test:cld":"bash test/run-cld-agents.sh","typecheck":"tsc -p tsconfig.json --noEmit","test:multi":"bash test/run-multi-agent.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"himansh.raj","email":"himansh.raj@colate.io"},"repository":{"url":"git+https://github.com/Colate-Ltd/cana-walkie-talkie.git","type":"git"},"_npmVersion":"11.13.0","description":"Open-source real-time message bus for human↔agent and agent↔agent coordination over WebSocket. The community core of Cana Walkie-Talkie.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ws":"^8.18.0","zod":"^3.24.1","express":"^4.21.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","@types/ws":"^8.5.13","typescript":"^5.7.3","@types/node":"^22.10.5","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/walkie-talkie_0.1.1_1782388505779_0.6622746276613418","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@cana-ai/walkie-talkie","version":"0.1.2","publishConfig":{"access":"public"},"description":"Open-source real-time message bus for human↔agent and agent↔agent coordination over WebSocket. The community core of Cana Walkie-Talkie.","type":"module","license":"MIT","author":{"name":"Himansh Raj","email":"iamthehimansh@gmail.com"},"homepage":"https://github.com/Colate-Ltd/cana-walkie-talkie","repository":{"type":"git","url":"git+https://github.com/Colate-Ltd/cana-walkie-talkie.git"},"keywords":["walkie-talkie","websocket","message-bus","ai-agents","claude-code","real-time","mcp","cana"],"engines":{"node":">=22.5.0"},"bin":{"cana-walkie-talkie":"dist/server.js"},"scripts":{"dev":"tsx watch src/server.ts","start":"tsx src/server.ts","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run build","test":"tsx test/smoke.ts","test:multi":"bash test/run-multi-agent.sh","test:cld":"bash test/run-cld-agents.sh"},"dependencies":{"express":"^4.21.2","ws":"^8.18.0","zod":"^3.24.1"},"devDependencies":{"@types/express":"^4.17.21","@types/node":"^22.10.5","@types/ws":"^8.5.13","tsx":"^4.19.2","typescript":"^5.7.3"},"gitHead":"ae23a3ad6c551047175dfd95962bd2718c7819e2","_id":"@cana-ai/walkie-talkie@0.1.2","bugs":{"url":"https://github.com/Colate-Ltd/cana-walkie-talkie/issues"},"_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-RN70Pro1wuOZrfpkxzpiGRnKZdnKshcf15L3/uiGzVvoGepUgH/GsG4JPvEl+wfZ44ZjKJ+TiwsE0/jkL47MeA==","shasum":"b7f5904690d2fac81be99dfbb7e8ce2f4c68036b","tarball":"https://registry.npmjs.org/@cana-ai/walkie-talkie/-/walkie-talkie-0.1.2.tgz","fileCount":25,"unpackedSize":139976,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCm5DzIiBuwGZkH8KfVD7oCE8rFfGkZ6WOuZggiZ/VDlgIgYKkqU6qCVtNFnO9uSIb/5ANUlt8dHiW8uusZMA9RgFU="}]},"_npmUser":{"name":"himansh.raj","email":"himansh.raj@colate.io"},"directories":{},"maintainers":[{"name":"himansh.raj","email":"himansh.raj@colate.io"},{"name":"prasadpanda","email":"prasad.p@colate.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/walkie-talkie_0.1.2_1782389943643_0.5249158321390022"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-25T11:50:14.486Z","modified":"2026-06-25T12:19:03.916Z","0.1.0":"2026-06-25T11:50:14.807Z","0.1.1":"2026-06-25T11:55:05.934Z","0.1.2":"2026-06-25T12:19:03.776Z"},"bugs":{"url":"https://github.com/Colate-Ltd/cana-walkie-talkie/issues"},"author":{"name":"Himansh Raj","email":"iamthehimansh@gmail.com"},"license":"MIT","homepage":"https://github.com/Colate-Ltd/cana-walkie-talkie","keywords":["walkie-talkie","websocket","message-bus","ai-agents","claude-code","real-time","mcp","cana"],"repository":{"type":"git","url":"git+https://github.com/Colate-Ltd/cana-walkie-talkie.git"},"description":"Open-source real-time message bus for human↔agent and agent↔agent coordination over WebSocket. The community core of Cana Walkie-Talkie.","maintainers":[{"name":"himansh.raj","email":"himansh.raj@colate.io"},{"name":"prasadpanda","email":"prasad.p@colate.io"}],"readme":"<p align=\"center\">\n  <a href=\"https://cana.build\">\n    <img src=\"https://raw.githubusercontent.com/Colate-Ltd/cana-walkie-talkie/main/public/cana-logo.png\" alt=\"Cana\" width=\"72\" />\n  </a>\n</p>\n\n<h1 align=\"center\">Cana Walkie-Talkie</h1>\n\n<p align=\"center\"><b>A real-time message bus for human↔agent and agent↔agent coordination.</b></p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@cana-ai/walkie-talkie\"><img src=\"https://img.shields.io/npm/v/@cana-ai/walkie-talkie?color=6366f1&label=npm\" alt=\"npm version\" /></a>\n  <a href=\"LICENSE\"><img src=\"https://img.shields.io/badge/license-MIT-6366f1\" alt=\"License: MIT\" /></a>\n  <a href=\"https://nodejs.org\"><img src=\"https://img.shields.io/badge/node-%E2%89%A522.5-43853d\" alt=\"Node ≥ 22.5\" /></a>\n  &nbsp;·&nbsp;\n  <a href=\"https://cana.build\">cana.build</a> ·\n  <a href=\"https://cana.build/docs\">Docs</a>\n</p>\n\nSpin up a WebSocket bus where people and AI agents (Claude Code, your own\nscripts, anything that speaks WebSocket) join shared **channels**, exchange\n**broadcast / directed / private** messages with live history and presence, and\noperate under a server-authored **policy** that keeps agents on-task and\nprompt-injection-resistant.\n\nThis is the **open-source core** of [Cana](https://cana.build)'s Walkie-Talkie —\nsingle-node, zero-config, no external services. The hosted Cana product builds\non the same wire protocol with multi-region scale, team RBAC, audit, mobile\npush, and deep agent-platform integration (see the table below).\n\n```\n┌─────────┐   wtk_ token over WS    ┌──────────────────┐\n│  Agent  │ ──────────────────────▶ │                  │\n└─────────┘                         │  Walkie-Talkie   │   ┌─────────┐\n┌─────────┐   admin token over WS   │   bus (this)     │──▶│ SQLite  │\n│Dashboard│ ──────────────────────▶ │  Express + ws    │   └─────────┘\n└─────────┘                         └──────────────────┘\n```\n\n## Features\n\n- **Channels** — create, list, close. Durable in SQLite.\n- **`wtk_` agent tokens** — scoped to channels, with `receive`/`send`\n  capabilities, TTL, one-time reveal, instant revoke. Only a peppered SHA-256\n  hash is stored.\n- **Messaging** — broadcast, directed (`to:`), and private 1:1 DMs.\n- **Live + replay** — WebSocket fan-out plus per-channel monotonic `seq` and\n  history replay on (re)connect.\n- **Server policy frame** — authoritative, anti-prompt-injection rules pushed to\n  every agent on connect.\n- **Safety rails** — high-confidence secret blocking, body-size + rate limits,\n  Origin allow-list (CSWSH), mid-stream token revalidation.\n- **Bundled dashboard** — a no-build web UI to run channels, watch live, and\n  mint agent tokens with a copy-paste `/walkie-talkie` command.\n- **Zero native deps** — Express + `ws` + Zod, SQLite via built-in `node:sqlite`.\n\n## Quickstart\n\nRequires **Node ≥ 22.5** (for built-in `node:sqlite`).\n\n### Run instantly with `npx` — no clone, no install\n\n```bash\nnpx @cana-ai/walkie-talkie\n```\n\nThat boots the bus **and** the bundled dashboard on **http://localhost:8787** and\nprints a generated **admin token** on first run. Configure it inline with env vars:\n\n```bash\nPORT=9000 ADMIN_TOKEN=$(openssl rand -hex 32) npx @cana-ai/walkie-talkie\n```\n\nPin a version with `npx @cana-ai/walkie-talkie@latest`, or install it globally:\n\n```bash\nnpm i -g @cana-ai/walkie-talkie\ncana-walkie-talkie            # same binary, now on your PATH\n```\n\n### Or clone for development\n\n```bash\ngit clone https://github.com/Colate-Ltd/cana-walkie-talkie.git\ncd cana-walkie-talkie\nnpm install\ncp .env.example .env        # optional — sensible defaults otherwise\nnpm start\n```\n\nThe server prints a generated **admin token** on first boot (or set `ADMIN_TOKEN`\nin `.env`). Open the dashboard at **http://localhost:8787**, paste the admin\ntoken, create a channel, and mint an agent token.\n\nConnect an agent (a ready-made example client is included):\n\n```bash\nnode examples/agent.mjs ws://localhost:8787 <channelId> <wtk_token> \"hi there\"\n```\n\nRun the tests (see [test/TESTING.md](test/TESTING.md) for the full plan):\n\n```bash\nnpm test          # Tier 1 — fast in-process end-to-end smoke test\nnpm run test:multi # Tier 2 — real server + multiple agents, each in a PTY\nnpm run test:cld   # Tier 3 — two real Claude Code agents coordinating (opt-in)\n```\n\n## Use it from Claude Code\n\nThe dashboard's **+ Agent token** button gives you a ready `/walkie-talkie`\ncommand. Drop [`commands/walkie-talkie.md`](commands/walkie-talkie.md) into\n`~/.claude/commands/` and run:\n\n```\n/walkie-talkie ws://localhost:8787 <channelId> <wtk_token> \"You are the ops helper; stop when the incident is resolved.\"\n```\n\n## Protocol\n\nThe full JSON-over-WebSocket spec is in **[PROTOCOL.md](PROTOCOL.md)**. It's\nsmall and language-agnostic — write a client in anything.\n\n## Configuration\n\nAll optional — see [`.env.example`](.env.example). Highlights:\n\n| Var | Default | Purpose |\n|-----|---------|---------|\n| `PORT` / `HOST` | `8787` / `0.0.0.0` | listener |\n| `DB_PATH` | `./walkie.db` | SQLite file |\n| `ADMIN_TOKEN` | _generated_ | REST + dashboard bearer |\n| `AGENT_TOKEN_PEPPER` | _(empty)_ | peppers token hashes — set in prod |\n| `HISTORY_REPLAY` | `100` | messages replayed on connect |\n| `BUS_ALLOWED_ORIGINS` | _(empty)_ | browser Origin allow-list (CSWSH) |\n\n## Architecture\n\n```\nsrc/\n  server.ts        HTTP + WS bootstrap, static dashboard\n  rest.ts          /api/bus REST (admin-bearer): channels, tokens, messages\n  ws.ts            /ws/bus/:channelId WebSocket: handshake, frames, heartbeat\n  messages.ts      single emit() choke point: seq, persist, secret-scan, fan-out\n  broadcaster.ts   in-memory per-channel fan-out (the single-node boundary)\n  db.ts            node:sqlite schema + queries\n  tokens.ts        wtk_ generate / hash / verify\n  auth.ts          admin-bearer + wtk_ resolution, mid-stream revalidation\n  policy.ts        authoritative policy frame\n  secret-scan.ts   dependency-free credential detector\n  ratelimit.ts     fixed-window in-memory limiter\npublic/            no-build dashboard (index.html, app.js, styles.css)\nexamples/agent.mjs minimal reference WebSocket client\n```\n\nThe interfaces are intentionally small (`broadcaster`, `auth`, `db`) so they can\nbe swapped — e.g. Redis pub/sub for multi-node, or an OAuth/SSO adapter for\n`auth`. That's exactly the seam where the hosted product plugs in.\n\n## Open-source core vs. Cana\n\nThe protocol and single-node server are MIT and yours to run. Cana's hosted\nplatform adds what teams hit as they grow:\n\n| Capability | Open-source core | Cana (hosted) |\n|---|:---:|:---:|\n| Wire protocol + `/walkie-talkie` command | ✅ | ✅ |\n| Channels, `wtk_` tokens (receive/send) | ✅ | ✅ |\n| Broadcast / directed / private messages | ✅ | ✅ |\n| History replay, presence, heartbeat | ✅ | ✅ |\n| Single-node, SQLite, self-host | ✅ | — |\n| Multi-region horizontal scale (Redis pub/sub) | — | ✅ |\n| Org/team RBAC (viewer→owner roles, directory) | — | ✅ |\n| Compliance audit log | — | ✅ |\n| `admin`/`act` capabilities + approval workflow | — | ✅ |\n| Anomaly auto-revoke, advanced rate/secret controls | basic | ✅ |\n| Mobile + desktop push notifications | — | ✅ |\n| File attachments (S3) | — | ✅ |\n| Read receipts & persistent work-status at scale | — | ✅ |\n| Managed identity (SSO / OIDC) | adapter | ✅ |\n| MCP tool surface + Cana agent/chat/RCA integration | — | ✅ |\n| Hosted, zero-ops, SLA | — | ✅ |\n\n→ **Need scale, teams, or the agent platform?** [cana.build](https://cana.build)\n\n## Security notes\n\n- Set `AGENT_TOKEN_PEPPER` and a strong `ADMIN_TOKEN` in production.\n- Put the server behind TLS; set `BUS_ALLOWED_ORIGINS` for any browser clients.\n- The secret scanner is a safety net, not a guarantee — don't paste credentials.\n- Found a vulnerability? Email **himansh.raj@colate.io** rather than filing a\n  public issue.\n\n## Contributing\n\nIssues and PRs welcome — see [CONTRIBUTING.md](CONTRIBUTING.md). Keep the wire\nprotocol backward-compatible and additive.\n\n## License\n\n[MIT](LICENSE) © 2026 Himansh Raj / Colate Ltd.\n","readmeFilename":"README.md"}