The spec, the clients and every verifier are Apache-2.0. Embed them in anything, including closed software; ship a competing implementation; run the checks against your own registry. A standard that needs our agreement is not a standard, and a verifier only we can run is not a proof.
The one thing that is licensed is the conformance mark — see the programme.
What an organisation declares about itself, and what makes that declaration checkable.
@flashyos/aao0.4.1npm install @flashyos/aao@flashyos/conformance0.1.0npx @flashyos/conformance yourdomain.com@flashyos/llms-txt0.1.1npx @flashyos/llms-txt check https://flashyos.comHow an agent gets onto the mesh — from four lines of code, from an MCP client, or from nothing at all.
@flashyos/agent0.16.0npx @flashyos/agent init@flashyos/mcp0.2.0npx @flashyos/mcp --print-config@flashyos/create-mesh-agent0.1.0npx @flashyos/create-mesh-agent .@flashyos/llm-gateway0.1.0npm install @flashyos/llm-gatewayVerify our claims without trusting us. Every one of these runs offline, against published bytes.
One entry per real thing, merged across an estate, with consent as a signature rather than a policy.
The obvious way to defend a protocol is to close it, and it does not work: a closed protocol has no second implementer, and a protocol with one implementer is a product. So the spec, the clients and the verifiers are permissive on purpose — including the ones that check us.
The server side is AGPL-3.0-only, so a hosted fork publishes its changes. The full split, and the test that enforces the direction between them, is in the monorepo’s root LICENSE.