The spec, the clients and every verifier are Apache-2.0. Embed them in anything, including closed software; ship a competing implementation; run the checks against your own registry. A standard that needs our agreement is not a standard, and a verifier only we can run is not a proof.
The one thing that is licensed is the conformance mark — see the programme.
What an organisation declares about itself, and what makes that declaration checkable.
@flashyos/aao0.4.1npm install @flashyos/aao@flashyos/conformance0.2.3npx @flashyos/conformance yourdomain.com@flashyos/llms-txt0.1.1npx @flashyos/llms-txt check https://flashyos.comHow an agent gets onto the mesh — from four lines of code, from an MCP client, or from nothing at all.
@flashyos/agent0.16.1npx @flashyos/agent init@flashyos/mcp0.2.1npx @flashyos/mcp --print-config@flashyos/create-mesh-agent0.1.1npx @flashyos/create-mesh-agent .@flashyos/create-mesh-node0.1.0npm create @flashyos/mesh-node -- yourdomain.com --email you@org.com@flashyos/page0.1.0npm install @flashyos/page@flashyos/eslint-config0.1.0npm install -D @flashyos/eslint-config@flashyos/llm-gateway0.1.1npm install @flashyos/llm-gatewayVerify our claims without trusting us. Every one of these runs offline, against published bytes.
@flashyos/bolt0.1.0npm install @flashyos/bolt@flashyos/verify0.3.0npx @flashyos/verify@flashyos/countersign0.1.0npx @flashyos/countersignOne entry per real thing, merged across an estate, with consent as a signature rather than a policy.
@flashyos/canon0.1.0npm i @flashyos/canon@flashyos/directory0.2.0npm install @flashyos/directory@flashyos/backlog0.1.0npm install @flashyos/backlog@flashyos/shiplog0.1.0npm install @flashyos/shiplog@flashyos/checkpoint0.2.0npm install @flashyos/checkpoint@flashyos/assetmesh0.1.0npm install @flashyos/assetmesh@flashyos/delivery0.1.0npm install @flashyos/delivery@flashyos/playbook0.1.0npm install @flashyos/playbook@flashyos/mesh0.1.0npx @flashyos/mesh status@flashyos/holding0.1.0npm install @flashyos/holding@flashyos/frontdoor0.1.0npx @flashyos/frontdoorThe obvious way to defend a protocol is to close it, and it does not work: a closed protocol has no second implementer, and a protocol with one implementer is a product. So the spec, the clients and the verifiers are permissive on purpose — including the ones that check us.
The server side is AGPL-3.0-only, so a hosted fork publishes its changes. The full split, and the test that enforces the direction between them, is in the monorepo’s root LICENSE.