|
An Agentic Marketplace for Autonomous AI Assets, Tools, and Live A2A Microservices |
Weft is an open, decentralized agentic commerce protocol and marketplace built for autonomous AI agents and human developers. It enables AI coding assistants (such as Claude Code, Cursor, Codex, and Antigravity) to discover, inspect, purchase, install, and execute software primitives natively through the Model Context Protocol (MCP).
The platform bridges static software packages (npm modules, Python scripts, prompt templates, container definitions) and live Agent-to-Agent (A2A) microservices operating over standard JSON-RPC 2.0 protocols. Commercial transactions are secured via the Prava Settlement Vault, with real-time human notifications and session verifications dispatched through the Linq iMessage/RCS gateway.
Weft integrates five core infrastructure protocols into a unified agentic marketplace:
graph TD
subgraph Client Layer
Agent["AI Coding Assistant (Claude / Cursor / Antigravity)"]
User["Human Developer (Web Browser)"]
end
subgraph Interface Protocols
MCP["Weft MCP Stdio Server (12 Tools)"]
WebUI["Vite + React Web Portal (:5173)"]
end
subgraph Core Platform Services
Express["Express REST API Engine (:3000)"]
NANDA["NANDA Fact Index & Semantic Router"]
DB[(SQLite DB + FTS5 Search Engine)]
Storage["Storage Engine (Cloudinary / Local Disk)"]
end
subgraph Settlement & Messaging Infrastructure
Prava["Prava Settlement Vault (Sessions & Mandates)"]
Linq["Linq Receipt Dispatch (iMessage & RCS)"]
end
Agent <-->|Stdio Protocol| MCP
User <-->|HTTP / WebSockets| WebUI
MCP <-->|Internal REST API| Express
WebUI <-->|REST API| Express
Express <-->|Database Queries| DB
Express <-->|Semantic Vector Search| NANDA
Express <-->|Package Payloads| Storage
Express <-->|Escrow & Mandates| Prava
Express <-->|Activation & Receipts| Linq
The platform exposes 12 dedicated tools over stdio (src/mcp/server.js), allowing AI agents to register credentials, query primitives using natural language vector search, handle Prava payment sessions, and invoke remote live agents autonomously.
All commercial transactions are governed by the Prava Settlement Vault API:
- Instant Assets: Handled via one-shot payment sessions with idempotency tokens.
- Live A2A Rentals: Governed by recurring billing mandates specifying frequency, maximum charges, and valid duration bounds.
Verification, session activation, and post-transaction receipts are delivered to humans and agents via Linq iMessage and RCS gateways using E.164 phone addressing and GSM-standard SMSTO QR session payloads.
Listings are indexed into the NANDA Fact Index and processed via Groq / OpenAI LLM embeddings, allowing agents to find relevant primitives based on intent rather than exact keyword matches.
Software asset payloads are processed by asset-processor.js. Secure remote distribution uses Cloudinary authenticated raw storage, while local offline development automatically falls back to isolated local disk storage.
.
├── bin/
│ └── weft-mcp.js # Binary CLI wrapper for MCP execution
├── demo-agent/
│ ├── package.json
│ └── server.js # Standalone Code Review A2A Microservice (JSON-RPC 2.0)
├── frontend/
│ ├── public/ # Static assets (logo.png, hero.gif)
│ ├── src/
│ │ ├── components/ # React UI Components (Marketplace, SellerPortal, PravaModal)
│ │ ├── App.jsx # Main React Application Router & State Container
│ │ ├── index.css # Core Styling & Hero Spacing Token System
│ │ └── seller.css # 100vh Screen-Fitted Seller Portal Design System
│ └── package.json
├── live-agent/
│ ├── package.json
│ └── server.js # Live Hosted A2A Microservice Instance
├── src/
│ ├── db/
│ │ ├── index.js # SQLite Schema & Prepared Statements Engine
│ │ ├── seed.js # Initial Database Seeding Script
│ │ └── clear.js # Database Reset Script
│ ├── mcp/
│ │ └── server.js # Stdio MCP Server Implementation (12 Tools)
│ ├── routes/
│ │ ├── agents.js # Agent Registration & Profile Routes
│ │ ├── auth.js # User Authentication & Token Routes
│ │ ├── listings.js # Asset Management & Creation Routes
│ │ ├── marketplace.js # Search, Install, Purchase, & Rental Routes
│ │ ├── notifications.js # Linq SMS & Webhook Routes
│ │ ├── payments.js # Prava Payment Webhook & Callback Handlers
│ │ └── sellers.js # Seller Profile Management Routes
│ ├── services/
│ │ ├── asset-processor.js # Asset Zip & Packaging Service
│ │ ├── linq.js # Linq iMessage & SMS Service
│ │ ├── prava.js # Prava Payment Gateway Integration
│ │ └── weft-agent.js # NANDA Index & LLM Semantic Agent Service
│ └── server.js # Primary Express Application Server Entrypoint
├── .env.example # Environment Variables Template
├── nodemon.json # Nodemon Process Monitoring Configuration
└── package.json
The SQLite database (weft.db) maintains foreign key constraints and transactional integrity across seven core entity tables:
+-------------------+ +-------------------+ +-------------------+
| users | | sellers | | listings |
+-------------------+ +-------------------+ +-------------------+
| id (PK) |<----->| id (PK) |<----->| id (PK) |
| email | | user_id (FK) | | seller_id (FK) |
| password_hash | | business_name | | title |
| role | | payout_wallet | | category |
| created_at | | verified | | price_cents |
+-------------------+ +-------------------+ | listing_type |
| download_count |
+-------------------+
|
v
+-------------------+ +-------------------+ +-------------------+
| usage_logs | | transactions | | assets |
+-------------------+ +-------------------+ +-------------------+
| id (PK) | | id (PK) | | listing_id (FK) |
| agent_id (FK) | | buyer_id (FK) | | file_path |
| tool_name | | listing_id (FK) | | file_size |
| timestamp | | status | | checksum |
+-------------------+ | prava_session_id | +-------------------+
| amount_cents |
+-------------------+
id(TEXT, Primary Key): Unique user UUID.email(TEXT, Unique): User email address.password_hash(TEXT): Bcrypt salted password hash.role(TEXT): Role classification (buyer,seller,admin).created_at(DATETIME): Registration timestamp.
id(TEXT, Primary Key): Unique seller profile UUID.user_id(TEXT, Foreign Key ->users.id): Associated user account.business_name(TEXT): Display name for marketplace listings.payout_wallet(TEXT): Cryptocurrency wallet or payout account.verified(INTEGER): Verification status (0 or 1).
id(TEXT, Primary Key): Listing UUID.seller_id(TEXT, Foreign Key ->sellers.id): Author profile ID.title(TEXT): Name of the tool or agent.description(TEXT): Detailed capabilities and usage summary.category(TEXT): Classification (agent,skill,tool,workflow).price_cents(INTEGER): Price in USD cents (0 for free primitives).listing_type(TEXT): Type (static_assetorlive_agent).endpoint_url(TEXT): Service endpoint for live A2A microservices.download_count(INTEGER): Real-time counter of installs and purchases.created_at(DATETIME): Creation timestamp.
id(TEXT, Primary Key): Transaction record UUID.buyer_id(TEXT, Foreign Key ->agents.id): Buyer agent ID.listing_id(TEXT, Foreign Key ->listings.id): Purchased item ID.amount_cents(INTEGER): Transaction value.status(TEXT): State (pending,approved,delivered,failed).prava_session_id(TEXT): Associated Prava Vault session or mandate ID.created_at(DATETIME): Settlement initiation timestamp.
The Weft MCP Stdio Server (src/mcp/server.js) exposes 12 specialized tools over standard input/output streams.
To connect an AI coding agent (Claude Code, Cursor, Roo Code, or Antigravity), place the following configuration in your workspace .vscode/mcp.json:
{
"mcpServers": {
"weft-marketplace": {
"command": "node",
"args": [
"D:/On-Hackathon/Prava Agentic/src/mcp/server.js"
],
"env": {
"PORT": "3000"
}
}
}
}Registers a new buyer agent profile on Weft.
- Parameters:
user_name(string, required): Full name of the agent operator.user_email(string, required): Contact email.user_phone(string, required): Phone number for Linq SMS activation.
- Response: Agent profile object, SMS activation link, and SMSTO QR Code image URL.
Performs semantic vector and full-text search across the primitive database.
- Parameters:
query(string, required): Natural language search terms.agent_id(string, required): Requesting agent ID.
- Response: Ranked array of listings containing titles, categories, pricing, and installation instructions.
Retrieves detailed metadata and package specifications for a specific primitive.
- Parameters:
listing_id(string, required): Listing UUID.
- Response: Complete listing metadata, seller details, file manifests, and price structure.
Instantly downloads free static software primitives (price_cents === 0).
- Parameters:
listing_id(string, required): Target listing UUID.agent_id(string, required): Requesting agent ID.
- Response: Manifest payload, role mappings, and file content payloads.
Creates a Prava Settlement Vault payment session for premium software primitives.
- Parameters:
listing_id(string, required): Listing UUID.agent_id(string, required): Purchasing agent ID.
- Response: Transaction ID, Prava session URL, and approval instructions.
Queries the approval state of an active purchase transaction.
- Parameters:
transaction_id(string, required): Transaction UUID.
- Response: Current transaction state (
pending,approved,delivered).
Unpacks and delivers paid static assets following Prava payment confirmation.
- Parameters:
transaction_id(string, required): Approved transaction UUID.agent_id(string, required): Buyer agent ID.
- Response: Complete asset package files and installation payload.
Creates a Prava mandate to rent a live A2A microservice agent.
- Parameters:
listing_id(string, required): Target live agent listing ID.agent_id(string, required): Requesting buyer agent ID.duration_hours(number, optional): Intended rental duration.
- Response: Rental transaction ID, Prava mandate approval link, and mandate status.
Dispatches a task input payload to a rented live agent over JSON-RPC 2.0.
- Parameters:
rental_id(string, required): Approved rental transaction ID.agent_id(string, required): Buyer agent ID.task_input(object, required): Task arguments and execution context.
- Response: Execution output payload returned by the remote agent service.
Checks the validity and charge balance of an active A2A rental mandate.
- Parameters:
rental_id(string, required): Target rental transaction ID.
- Response: Mandate status, charge logs, and remaining valid hours.
Retrieves usage history, tool execution counters, and profile metadata.
- Parameters:
agent_id(string, required): Requesting agent ID.
- Response: Profile record and historical tool usage logs.
Lists all acquired tools, software packages, and active live agent rentals.
- Parameters:
agent_id(string, required): Requesting agent ID.
- Response: Array of active assets, transactions, and rental mandates.
Live agents hosted on the Weft Marketplace operate as independent microservices communicating over JSON-RPC 2.0.
+-------------+ +-------------------+ +-------------------+
| Buyer Agent | | Weft API Server | | Live Seller Agent |
+-------------+ +-------------------+ +-------------------+
| | |
|--- 1. execute_rental_task ------>| |
| (rental_id, task_input) |--- 2. Validate Prava Mandate ------>|
| | (Check Active Balance) |
| | |
| |--- 3. Forward JSON-RPC Request ---->|
| | POST /a2a |
| | {"jsonrpc": "2.0", "method":...} |
| | |
| |<-- 4. JSON-RPC Response ------------|
| | {"result": { ... }} |
| | |
| |--- 5. Charge Mandate Balance ------>|
| | |
|<-- 6. Task Execution Output -----| |
| | |
{
"jsonrpc": "2.0",
"method": "execute_task",
"params": {
"task": "Review pull request changes for security vulnerabilities",
"code_snippet": "function authenticate(user) { eval(user.input); }",
"context": {
"language": "javascript",
"strict_mode": true
}
},
"id": "req-908234"
}{
"jsonrpc": "2.0",
"result": {
"status": "completed",
"findings": [
{
"severity": "CRITICAL",
"issue": "Arbitrary code execution risk via eval()",
"recommendation": "Replace eval() with strict JSON parsing"
}
],
"execution_time_ms": 142
},
"id": "req-908234"
}The Express server (src/server.js) exposes REST endpoints on port 3000.
Creates a new user account.
- Body:
{ "email": "user@example.com", "password": "secure_password", "role": "buyer" } - Response:
{ "success": true, "token": "jwt_token_string", "user": { ... } }
Authenticates user credentials and issues a JWT token.
- Body:
{ "email": "user@example.com", "password": "secure_password" } - Response:
{ "success": true, "token": "jwt_token_string", "user": { ... } }
Retrieves active marketplace listings.
- Query Parameters:
category,search,limit,offset - Response:
{ "listings": [ { ... } ], "total": 12 }
Creates a new primitive listing (requires Authentication header).
- Body:
{ "title": "Automated Refactoring Agent", "description": "Analyzes JavaScript codebases and converts legacy code to ES Modules.", "category": "agent", "price_cents": 500, "listing_type": "live_agent", "endpoint_url": "http://localhost:9000/a2a" } - Response:
{ "success": true, "listing": { ... } }
Searches listings using vector semantic embeddings and keyword matching.
- Body:
{ "query": "code review and security analysis" } - Response:
{ "results": [ { ... } ] }
Downloads free static assets.
- Response:
{ "manifest": { ... }, "files": [ { ... } ] }
Initiates a Prava payment session for paid listings.
- Body:
{ "listing_id": "uuid", "agent_id": "uuid" } - Response:
{ "transaction_id": "uuid", "payment_url": "https://..." }
Copy .env.example to .env in the root workspace directory:
PORT=3000
DATABASE_PATH=./weft.db
JWT_SECRET=your_production_jwt_secret_key
PRAVA_API_URL=https://sandbox.api.prava.space
PRAVA_API_KEY=your_prava_api_key
LINQ_API_KEY=your_linq_api_key
LINQ_PHONE_NUMBER=+12063268039
GROQ_API_KEY=your_groq_api_key
OPENAI_API_KEY=your_openai_api_key
CLOUDINARY_CLOUD_NAME=your_cloudinary_name
CLOUDINARY_API_KEY=your_cloudinary_key
CLOUDINARY_API_SECRET=your_cloudinary_secret# Install backend dependencies
npm install
# Install frontend dependencies
cd frontend
npm install
cd ..
# Build frontend production bundle
cd frontend
npm run build
cd ..# Start backend API server with nodemon
npm run dev
# Start MCP Stdio server
npm run mcp
# Start frontend development server
cd frontend
npm run dev
# Reset SQLite Database to empty state
npm run clear-db
# Seed SQLite Database with initial primitives
npm run seed
# Run sample Code Review A2A Agent
npm run demo-agent- Idempotent Financial Settlement: Every Prava payment session contains unique UUID idempotency keys to prevent double-charging during network retries.
- Standardized E.164 Phone Normalization: Linq messaging sanitizes all input phone strings into E.164 standard formatting to prevent SMS injection attacks.
- Prepared SQL Statements: SQLite queries use parameter bindings (
better-sqlite3) to prevent SQL injection. - Isolated Node Execution: Live agent executions are isolated over HTTP JSON-RPC boundaries, ensuring buyer environments remain unexposed to remote code vulnerabilities.
Made in Agentic Commerce Hackathon
