Parley - Provable non-betrayal for AI agents of rival owners
by•
Self-hosted consensus for AI agents of different owners with conflicting, private interests. Red lines are enforced in code, verdicts are masked, and each owner checks a tamper-evident receipt locally. Zero-dependency core, Apache-2.0, MCP server included.

Replies
Maker here. I built Parley so that your agent cannot betray you and you can prove it without trusting the coordinator.
Existing tools cover two other cases: one owner's agents checking each other (AutoGen, CrewAI) and two agents trading on a chain (Fetch.ai, Olas). Parley covers three or more agents with rival owners and private, conflicting interests that must reach one outcome. Afterward every owner can prove their own red line held. Code enforces three things, and no LLM decides them:
- Red lines are deterministic predicates that reject an option outright. Nobody can negotiate your hard limit away.
- The coordinator sees only a masked verdict (acceptable, a score, ok or red-line). It never sees your reasons or your sheet.
- Consensus is max-min, so the least-happy party gets lifted first. Each run emits a SHA-256 receipt that every owner replays against their own private sheet. If no option is feasible, Parley reports a deadlock and forces nothing.
Where it stands: this is 0.2.0. The evidence is a synthetic P2P-escrow walkthrough and one anonymized real case, an early lease exit where the tenant confirmed that a mutually better outcome existed. The counterparty side of that case is inferred, so the other party never ratified it. The live demo has seven scenarios, and three come from public forum cases with the source cited. There are no paying customers and no measured usage. I am launching to learn whether provable non-betrayal is worth money to real multi-party workflows.
An agent fleet wrote most of the repo under one human's direction. Changes merge on a green gate, and you can run `scripts/ship-gate.sh` yourself. The suite is green on Python 3.11 to 3.14, and the public history has 134 commits and 76 merged PRs.
Try the 30-second demo. It runs the real engine and hands you a receipt to re-hash yourself. `pip install parley-consensus` installs the library and a stdio MCP server (`parley-mcp`), so Claude or Cursor can call it as a tool.
Question for you: if your agents cross owner or org boundaries, would you reach for a way to prove the other side's agent did not cheat? Or is trust not your bottleneck yet?
Links, since PH strips them from the body:
- Repo: https://github.com/5uper0/parley?utm_source=producthunt (Apache-2.0, Python 3.10+, no dependencies)
- Live demo: https://parleyprotocol.com/demo/?utm_source=producthunt (press Run it, then Verify on any party)
- Install: `pip install parley-consensus`. Docker has no published image yet; build from a clone with `docker build -t parley . && docker run --rm -p 8080:8080 parley`.
- Verify a receipt: the demo's Verify button recomputes the SHA-256 and replays that party's red lines. In Python, use `result.transcript.hash()` and `transcript.verify_non_betrayal(sheet, decision)`. The first README code block does exactly that.
The receipt is an unsigned SHA-256 over the public masked verdicts. It shows the record was not edited after you took the hash and that your own red lines held. It does not prove who produced a verdict. Signed verdicts (Ed25519) exist in the one-process-per-owner HTTP mode and are off by default. SECURITY.md lists the other limits.