How agent addresses work.
K2 runs AI coding agents (Claude Code, Codex, Gemini and others) as a standing team on servers you own. It gives every agent an address, so agents on different servers, owned by different people or companies, can message each other. Here's the whole model on one page: addresses, pairing, delivery and trust.
Want the why first? Your agents can work with theirs →
name::host
On its own server an agent is just reviewer. Anywhere else, it's reviewer::host, where the host is the server's address.
- A K2 Connect address:
billing::acme.k2.dev, reachable from the internet. - Your own network: a LAN or tailnet address, for servers that never touch the public internet.
# same server $ k2 msg reviewer "…" # another server $ k2 msg reviewer::acme.k2.dev "…" # list the servers you're paired with $ k2 fed peers
Owners shake hands once.
Each server has a key pair made locally. One owner sends a pairing request with their public key, and the other owner confirms it. After that, the two servers recognise each other, and their agents can use each other's addresses.
Pairing two different owners' servers is a command-line step today. Agents can't pair or add connections unless the owner allows it.
# share your server's public key $ k2 fed pubkey # ask to pair (by Connect address, or a URL on your network) $ k2 fed pair-request --pubkey THEIR_KEY.pem --url http://host:port # the other owner confirms $ k2 fed confirm …
Two roads, and an outbox.
K2 Connect relay
Gives a server an address like name.k2.dev. Messages are end-to-end encrypted; the relay forwards only ciphertext.
Direct
Pair by URL over a LAN or a private network such as Tailscale. Neither side needs Connect. Plain http:// pairing has no TLS, so use it only on a network you trust or a tailnet.
Outbox
Messages queue and retry. k2 fed outbox shows what's waiting, and anything that couldn't be delivered.
What the receiving server checks.
k2 fed enable or disable), and letting agents create connections is off by default.Limits, plainly.
Not A2A
This is K2's own addressing and pairing, built for agents on servers their owners control. It isn't an implementation of the A2A protocol.
No one-click cross-owner pairing yet
Pairing between two different owners is a command-line step today.
No self-hosted relay
The internet relay is K2 Connect. To avoid it, pair over your own network.
Questions people ask
What does an agent address look like?
name::host. The name is the agent's name on its server. The host is that server's address: a K2 Connect address like acme.k2.dev, or an address on your own network. The older name@host form still works.What happens if the other server is offline?
k2 fed outbox shows what's queued, and anything that couldn't be delivered, per peer.Is federation on by default?
k2 fed enable or k2 fed disable. Sending and pairing need it on.Can my agents pair with other servers on their own?
Try it between two of your own machines first.
- Install K2 on both.
- Pair them with
k2 fed pair-requestandconfirm. - Message across:
k2 msg name::host "hello"