Enterprise peer-to-peer application SDK

Connect services
across machines.

Your service might run in a cloud instance, a customer network, or on the machine under your desk. Aster gives you a way to call it by its cryptographic identity.

Define a typed service, connect to a peer, and control which calls it may make. One shared Rust engine, with APIs for different languages.

Connection path
Two peers connected directly or through a relay A laptop and a remote service each have a cryptographic identity. Aster attempts a direct encrypted connection. A relay can carry the encrypted connection when a direct path is unavailable. Direct encrypted connection Encrypted connection via relay Your machineIdentity A Remote serviceIdentity B Relay
Iroh tries a direct path and can fall back to a relay. Both peers still need network access.

Built on

Iroh connectivityApache Fory serializationBLAKE3 contract identity

A service and a call

The interface lives in your code.

Aster carries the call between peers. Your application defines the types, implements the handler, and decides who can use it.

Illustrative excerpts · Python + CLI
Service on machine B service.py
@service(name="Hello", version=1)
class HelloService:
    @rpc()
    async def greet(self, req: HelloRequest) -> HelloResponse:
        return HelloResponse(message=f"Hello, {req.name}!")
Call from machine A shell
$ aster call <peer-address> Hello.greet '{"name":"world"}' { "message": "Hello, world!"}

Imports, types, and server setup are omitted here. Follow the complete quickstart for runnable code.

Identity and access

Know which peer
you’re talking to.

A network address tells you where to send traffic. Aster’s peer identity tells you which endpoint is on the other side of the connection.

Read the trust model
01 Keep an identity across network changes
Persist the endpoint key to keep the same identity when its IP address changes. Protect and back up that key.
02 Authenticate the connection
Iroh establishes an encrypted connection and authenticates the remote peer. Direct and relay paths use the same peer identity.
03 Authorize the work
Configure admission and method permissions for your application. Knowing a peer’s identity is the starting point for deciding what it may do.

Put it to work

Start with something you can run.

Follow one service from its first call through streaming and access control, or connect an existing service to an AI tool.

01

MissionControl

Build a DevOps control plane. Collect agent logs and metrics, issue remote commands, and scope operator access.

Follow the walkthrough
02

Remote tools with MCP

Make an Aster service available to an AI application through the CLI’s MCP integration.

Connect a tool

Next release

More ways to use the same foundation.

We’re preparing guides for existing HTTP services, durable coordination, and a second agent example alongside the expanded language APIs.

Aster Expose

Connect an existing HTTP service to an Aster peer, or publish it through a public HTTPS edge. The edge has its own infrastructure and TLS requirements.

Coordination

Maintain one authoritative owner or active version across a small group of persistent nodes. Use leases and fencing where conflicting work would be unsafe.

AgentXchange Proposed example

A daemon on each machine receives durable messages and triggers locally configured AI agents. The example is planned; it is not available to run yet.

Language surfaces

Choose the API that fits your application.

Rust is the first-class facade over Aster’s shared engine. Python, TypeScript, and the FFI bindings expose that foundation in their own runtime’s idioms.

RustPythonTypeScriptGoJavaKotlin.NET

The next release will document each language’s installation, supported features, and platforms. The current documentation covers the published entry points.

Try a call between two machines.

Start with the quickstart, then add the pieces your application needs.

Open the quickstart