Skip to content
parley.

Provable, not hoped

Zero betrayals,provably.

Personal AI agents negotiate for owners with conflicting, private interests. Parley makes it provable that none of them was betrayed, without any owner exposing a single private preference.

parley · replay af170229…transcript
abcde

Five delegates, five private sheets. Option A below, three of the five verdicts shown. One shared decision,verified, none of the sheets revealed.

bobscore 0.30acceptable
carascore 0.70acceptable
ana[masked]red-line

max-min → option P✓ sha256 verified 5/5
cara's reason stays private. only the verdict "red-line" ever leaves her agent.

The gap nobody productised

Most agent tooling solves transport (A2A, MCP), one-to-one agentic commerce, or cooperative debate between agents that already share one owner.

Parley solves a different gap: delegates of different, conflicting, private owners reaching a decisionnone of them can rig, and proving it.


Four properties, enforced in code, not left to a model's discretion.

Red lines

Hard constraints written as code predicates. A crossed red line rejects an option outright. It is never negotiated away as soft utility.

preferences.py
round 1 · option A proposed
ana → verdict: ok
cara → verdict: red-line
option A rejected

Masked verdicts

The coordinator sees only an acceptable or red-line verdict and a soft score. Never the private sheet, and never which constraint was crossed.

agent.py
leaves the agent:
acceptable · score 0.71 · reason "ok"
stays private:
the sheet, and which line was crossed

Max-min consensus

Among options feasible for everyone, lift the least-happy participant, tie-broken by total welfare. No feasible option means an honest deadlock, never a forced decision.

consensus.py

Verifiable transcript

A SHA-256 hash over the canonical, masked record. Each owner replays their own private sheet locally to confirm no red line was crossed, without revealing it.

transcript.py

AI that can't lie, and you can check.

The tape below is a real run. Five agents with conflicting private sheets, sixteen options, scored by the engine in this repository. Every verdict is recorded masked, hashed, and independently replayable by each owner against their own private sheet. The transcript hashes toaf1702294878…b7a84127, and landing/scripts/gen-tape.pyreproduces it byte for byte.

real transcript · sha256 af170229…b7a84127 · hover to pause

5/5
owners independently verified
256-bit
hash over the canonical record
0
red lines crossed, provably
Open the demo

Positioning

Multilateral (more than two owners),no cryptocurrency,self-hosted,auditable. Not single-owner orchestration like AutoGen or CrewAI. Not bilateral on-chain commerce like Fetch.ai or Olas.

Guides: run Parley as an MCP tool in Claude or Cursor, how the negotiation stays fair, what a red line is, exactly, how to verify a decision receipt afterwards, a fair group decision when everyone has private limits.


Questions

What is Parley, and what problem does it solve?

Parley is an open-source Python library for one decision among AI agents whose owners have conflicting, private interests. Each owner states red lines and preferences in private; the engine drops every option that crosses anyone's red line, picks among the rest by the max-min rule, and writes a transcript of masked verdicts that each owner can check afterwards. It is multilateral (more than two owners), uses no cryptocurrency or blockchain, and runs on your own machine.

Guide: A fair group decision when everyone has private limits

How are red lines enforced, and what does the other side learn?

A red line is a code predicate on an option, such as cost <= 700. An option that fails it is rejected before any score is weighed, and it is never traded against a preference. The only thing that leaves an agent is a verdict per option: acceptable or not, a score between 0 and 1, and the word ok or red-line, never which rule was behind it. The score is public, so a reader of the record can infer preference ordering and the feasible region, and across enough options the pass/fail pattern shows roughly where a red line sits, even though the reason field stays masked. The engine enforces whatever limit you typed; it cannot tell a real limit from a tactical one.

Guide: Red lines for LLM agents, enforced in code

How does the group pick one option, and what happens when nothing fits?

Only options acceptable to every participant are candidates. Among them the engine picks the option whose lowest score across participants is highest, and breaks ties by the sum of scores; this is a max-min rule, not a majority vote, so a majority cannot outvote one owner's floor. When no option clears everyone's red lines the result is a deadlock with no decision, and a deadlock forces nothing on anyone. Scores are self-reported too, and there is no resistance yet to an owner misreporting them strategically or to collusion (SECURITY.md).

Guide: Fair multi-agent negotiation for rival owners

What can I check afterwards, and what does the receipt not prove?

You can re-hash the transcript (SHA-256 over its canonical JSON), recompute the max-min winner from the recorded verdicts, and replay your own private sheet against the decision with verify_non_betrayal, all on your own machine and without showing the sheet to anyone. The hash is unsigned, so it catches a later edit only when someone other than the editor kept the hash; verdicts are unsigned unless the run signed them, and a signed verdict is checked against the key carried in the same record, with no trusted owner-to-key roster yet. The participants list is written by the coordinator, scores are public and leak preference ordering, and every limit is self-reported.

Guide: Verify an AI-agent decision without trusting the coordinator

How do I try it, and what does it need?

pip install parley-consensus gives you the core with no third-party dependencies on Python 3.10 or later (tested on 3.11 to 3.14), plus the parley-mcp command, a stdio MCP server you can point Claude or Cursor at. Signed verdicts need the crypto extra, pip install "parley-consensus[crypto]". The examples and scripts, including the receipt verifier, are not in the PyPI wheel; clone the repository, which is Apache-2.0. It is Alpha (v0): do not run it against genuinely adversarial principals in production. The demo on this site replays pre-computed runs of the same engine.

Guide: Parley as an MCP server for multi-party agent decisions


Put your next decisionon the tape.