# EnvoyMesh: A Self-Hosted P2P Network for AI Agents and Private Chat

> EnvoyMesh is a decentralized peer-to-peer mesh built on libp2p where your devices run the network and your cryptographic identity belongs to you. It combines private messaging, voice calls, file sharing, a knowledge base with federated RAG, and an on-device AI agent that negotiates tasks on your behalf, all without a central server.

**allenpeng0705/EnvoyMesh** — Decentralized P2P mesh for autonomous AI agents — self-sovereign identity, peer-to-peer chat, and on-device AI that negotiates tasks on your behalf. No central server.

- Repository: https://github.com/allenpeng0705/EnvoyMesh
- Website: https://www.homeclaw.cn/envoy/
- Stars: 3,118 · Forks: 14
- Language: TypeScript
- License: not declared
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/allenpeng0705-envoymesh

## What EnvoyMesh Replaces and Why

Most social apps and AI assistants route messages and model calls through a central server. The operator of that server holds your message history, your identity, and your agent's context. EnvoyMesh flips this arrangement: your devices run the network, your identity is an Ed25519 key pair that you control, and your AI agent runs on your hardware under your policies.

The practical problem it solves is privacy and ownership in AI-assisted communication. A team or family that wants peer-to-peer messaging, a shared knowledge base, and AI agent collaboration without a platform intermediary has few options today. EnvoyMesh is built specifically for that use case.

## Two Protocols: Mesh and Thin Client

EnvoyMesh defines two distinct protocols. The mesh protocol runs on libp2p and governs how home nodes communicate with each other using signed envelopes. Home nodes exchange envelopes for peer discovery, bond management, chat, knowledge base queries, and agent task negotiation. Relay nodes assist with connectivity but do not read the payload content.

The thin-client protocol governs communication between a desktop home node and a phone. The desktop runs the full node, holding model keys and repositories. EnvoyGo (the phone companion app) and EnvoyDev Mobile connect as thin clients over JSON-RPC on WebSocket or libp2p. This separation means that adding a phone does not mean running a full node on the phone; the phone delegates to the desktop for storage-heavy and compute-heavy operations.

The default home node is a standalone desktop application available for macOS (Apple Silicon DMG) and Windows (EXE). A headless home node using LaunchAgent or a logon task is documented for advanced operators who want the node running as a background service. Linux requires building from source.

## Identity, Bonds, and Trust Tiers

Every participant in the mesh has a self-sovereign DID backed by an Ed25519 key pair. There is no account to create or lose: your identity is the key. Contacts are managed through a bonding mechanism with four trust tiers: blocked, public, referred, and direct. Each tier controls what a contact can access: public contacts see only your public knowledge items and are subject to a rate limit on knowledge queries, while direct contacts have broader access.

The trust tier system means that the agent operating on your behalf also enforces your policies. When your AI agent receives a task negotiation request from a bonded peer, it acts within the rules you have defined for that contact's tier. The README describes the agent as able to make friends, search knowledge, and execute tasks within your safety rules.

Self-sovereign identity has a real practical implication: if you lose your keys, you lose your identity in the mesh. There is no password reset mechanism in a system without a central server. Key backup is the operator's responsibility.

## Installing and Starting a Home Node

The desktop home node is the entry point. Install it from the GitHub Releases page or the project mirrors for macOS or Windows. The macOS build is a DMG for Apple Silicon. The Windows build is an EXE installer.

For developers building on EnvoyMesh from source, the repository uses Node 22.13.0 or higher, pnpm workspaces, and a setup script:

```bash
bash scripts/setup.sh
```

A Windows PowerShell equivalent is available:

```bash
powershell -ExecutionPolicy Bypass -File scripts/setup.ps1
```

OpenClaw installs via a separate script:

```bash
bash scripts/install-openclaw.sh
```

The built-in AI engine (EnvoyAI / OpenClaw) starts automatically with the node on port 18789. The configuration file at .env.example covers the full environment variable set, including ENVOYMESH_PROFILE for the key and data directory, ENVOYMESH_VAULT for the knowledge file root, and ENVOYMESH_DISCOVERY_PROFILE for network topology choices (lan-fast, wan-default, relay-only, or contacts-only).

## Knowledge Base, Federated RAG, and Obsidian Integration

The built-in knowledge base is a Markdown editor with per-item sensitivity labels: public, friends, or private. Changes trigger automatic RAG re-indexing on save. The public sub-graph is queryable by any peer, bonded or stranger, with a per-stranger rate limit.

Federated RAG fans queries out to bonded peers' knowledge libraries and synthesizes answers from multiple sources. This is the mechanism that allows an AI agent to answer questions by drawing on knowledge distributed across multiple participants in the mesh rather than only local data.

The optional kb-obsidian provider syncs an Obsidian vault into the knowledge base. The integration reads frontmatter YAML, wiki-links graph structure, and a published: true/false flag that maps to the sensitivity label. The agent can write discoveries back to the vault as notes with source attribution via MCP write-back.

## External Agent Bridge and AI Engine Options

The built-in AI engine is EnvoyAI, which runs as OpenClaw on port 18789. An external agent bridge allows connecting HomeClaw, Hermes, OpenHuman, or any HTTP agent as a second engine, configured under Settings in the AI section. Four operating modes are available: built-in only, built-in plus external, external only, or none.

The coding tab integrates Envoy Harness and Pi as built-in coding agents, with Claude Code, Codex, Cursor, and OpenCode supported when they are installed on the home computer. This tab organizes projects, tasks, and coding agents in one place rather than running them from a separate terminal.

A significant limitation: the repository license is not specified. The GitHub repository page shows NOASSERTION for the license field. Before using EnvoyMesh in any commercial context, the license terms need to be confirmed directly with the project.

## Maintenance Status and Release History

The last push to the repository was on 2026-09-22. The most recent release, EnvoyMesh-0.6.0, was published on 2026-09-26. Prior releases include EnvoyMesh-0.5.0 on 2026-09-10 and EnvoyMesh-0.4.2 on 2026-09-04, indicating a rapid release cadence. Guidebooks for versions 0.2.2, 0.3.0, and 0.4.0 are checked into the repository root as Markdown and HTML files, giving a historical record of the protocol evolution.

A companion app, EnvoyDev, and a notes application called Veda Notes are listed as apps built on the same protocols. EnvoyGo is available on the iOS App Store (iOS 18.6 or higher) and the Google Play Store, with an APK mirror also available.

## Conclusion

EnvoyMesh suits developers who want a self-hosted private network where their AI agent operates on their own hardware rather than someone else's infrastructure. The project is actively developed with releases as recent as 2026-09-26. The trade-off is setup complexity: you run a desktop home node as the always-on anchor, pair mobile devices to it, and manage your own identity keys. The license is not documented in the repository, which is a real concern for commercial deployments. Before building on EnvoyMesh, clarify the licensing terms and verify that your team can operate and maintain a libp2p node at the reliability level your use case requires.

## FAQ

### Does EnvoyMesh require a central server?

No. EnvoyMesh uses libp2p for peer discovery and message routing. Relay nodes assist with connectivity for peers behind NAT, but they do not read message payloads. Your home node is the only required persistent component, and it runs on your own hardware.

### What AI agents can run inside EnvoyMesh?

The built-in engine is EnvoyAI, running as OpenClaw on port 18789. The external agent bridge supports HomeClaw, Hermes, OpenHuman, and any HTTP agent. When installed on the home computer, Claude Code, Codex, Cursor, and OpenCode integrate with the coding tab.

### What is the EnvoyMesh license?

The repository reports NOASSERTION for the license field, meaning no recognized open-source license has been identified. Before using EnvoyMesh in any commercial project, the license terms need to be confirmed directly with the author.

## Sources

- [allenpeng0705/EnvoyMesh on GitHub](https://github.com/allenpeng0705/EnvoyMesh)
- [Issues](https://github.com/allenpeng0705/EnvoyMesh/issues)
- [Project website](https://www.homeclaw.cn/envoy/)
- [README](https://github.com/allenpeng0705/EnvoyMesh/blob/main/README.md)
- [Releases](https://github.com/allenpeng0705/EnvoyMesh/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/allenpeng0705-envoymesh
