Skip to content

Architecture


πŸ“± Mobile AppAndroid & iOSKotlin / SwiftUIEd25519 + E2EE☁️ CloudflareZero Trust Tunnelwss:// TLSβš™οΈ Gatewayantimatter-gatewayπŸ” Ed25519 CryptoπŸ›‘ Token AuthπŸ“‘ IPC Router :8765🎯 AG AdapterAntigravity IDETypeScript Β· .vsix🐍 AG2 AdapterAntigravity 2.0Python daemonπŸ€– CC AdapterClaude CodeNode.js Β· SDKE2EEIPC ws://127.0.0.1:8765

Hover over any node to learn what it does.


Instead of baking security, networking, and tunneling logic into every agent integration, Antimatter cleanly separates the system into two independent layers:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Independent Adapters β”‚
β”‚ β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ AG Adapter β”‚ β”‚ AG2 Adapter β”‚ β”‚ CC Adapter β”‚ β”‚
β”‚ β”‚ (TypeScript) β”‚ β”‚ (Python) β”‚ β”‚ (Node.js) β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚ β”‚ β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ IPC ws://127.0.0.1:8765 β”‚
β–Ό β–Ό β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ antimatter-gateway Gateway β”‚
β”‚ β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ Security & Infrastructure Layer β”‚ β”‚
β”‚ β”‚ β”œβ”€ Ed25519 Keypair (OS Keychain) β”‚ β”‚
β”‚ β”‚ β”œβ”€ 256-bit Bearer Token (OS Keychain) β”‚ β”‚
β”‚ β”œβ”€ Daemon Manager (~/.antimatter_daemon/gateway.pid) β”‚ β”‚
β”‚ β”œβ”€ Rotating Logger (~/.antimatter_daemon/gateway.log) β”‚ β”‚
β”‚ β”œβ”€ Cloudflare Tunnel Manager β”‚ β”‚
β”‚ └─ IPC Router (ws://127.0.0.1:8765) β”‚ β”‚
β”‚ └─────────────────────────────────────────────────────── β”˜ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Cloudflare Tunnel (wss://)
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Mobile App (Client) β”‚
β”‚ β”‚
β”‚ Android (Kotlin/Compose) iOS (SwiftUI/Swift) β”‚
β”‚ β”œβ”€ BridgeWebSocket (OkHttp) β”œβ”€ BridgeWebSocket (URLSessionβ”‚
β”‚ β”œβ”€ Ed25519 verify β”œβ”€ Ed25519 verify (CryptoKit) β”‚
β”‚ β”œβ”€ E2EE decrypt β”œβ”€ E2EE decrypt β”‚
β”‚ └─ Feature Screens └─ Feature Screens β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The Gateway is the brain of the operation. It runs as a background process and handles everything complex so adapters don’t have to:

When started with antimatter-gateway start, the process immediately double-forks and detaches from the console. It tracks its process ID at ~/.antimatter_daemon/gateway.pid and safely rotates its standard output/errors to ~/.antimatter_daemon/gateway.log (capped at 5MB).

The Gateway exposes a secure wss:// endpoint through your Cloudflare Zero Trust tunnel β€” no firewall rules, no port forwarding, no static IP required.

On first run, the Gateway generates:

  • A persistent Ed25519 keypair β€” private key stored in OS keychain
  • A 256-bit random bearer token β€” stored in OS keychain

During QR pairing, the public key and token are encoded into the QR code. On every WebSocket connection, the mobile client presents the token and then verifies the Gateway’s identity via an AUTH_CHALLENGE / AUTH_RESPONSE handshake. This prevents Man-in-the-Middle attacks even on compromised networks.

The Gateway hosts a local WebSocket server at ws://127.0.0.1:8765. Adapters connect here and register with a name. When the mobile app sends a message targeting "ag", the Gateway forwards it to the correct adapter connection.


Adapters are lightweight, stateless IPC clients. Because they don’t handle security or tunneling, they can be:

  • Written in any language
  • Contain AI-specific β€œhacks” (e.g., file watching, SDK integration)
  • Easily swapped or added without touching the Gateway

When an adapter boots, it connects to ws://127.0.0.1:8765 and sends:

Adapter registration message
{
"type": "REGISTER_ADAPTER",
"name": "ag"
}

The Gateway registers this connection. Any message from the mobile app targeting "ag" is forwarded to this socket.


The MessageRouter inside the Gateway dispatches each inbound JSON frame:

Message Type Target Action
AUTH_CHALLENGE Gateway Sign nonce β†’ AUTH_RESPONSE
GET_AVAILABLE_AGENTS Gateway Reply with list of connected adapters
GET_FILES, READ_FILE Target Adapter Forward to adapter’s IPC socket
SEND_MESSAGE Target Adapter Inject prompt into the AI agent

| PING | Gateway | Reply PONG to keep tunnel alive |


Built with Kotlin and Jetpack Compose, following a multi-module MVVM architecture:

Layer Technology Purpose
Networking OkHttp + BridgeWebSocket.kt WebSocket client, Ed25519 auth, E2EE
Background BridgeService (Foreground Service) Keeps socket alive when backgrounded
Persistence Room + DataStore Offline trajectory/artifact caching
UI Jetpack Compose + Material 3 Declarative UI, dynamic theming
Markdown Custom MarkdownText composable Syntax-highlighted AI responses

Built with SwiftUI and Swift 6, targeting iOS 16+:

Layer Technology Purpose
Networking URLSession WebSocket + async/await WebSocket client, Ed25519 auth
Crypto CryptoKit Ed25519 verification, E2EE decryption
UI SwiftUI Declarative UI, Dark Mode support
Persistence CoreData / SwiftData Local conversation caching

Beyond TLS (provided by Cloudflare) and token authentication, Antimatter implements true E2EE using a Diffie-Hellman key exchange:

  1. During pairing, phone and Gateway exchange ephemeral DH public keys.
  2. Both sides derive the same 256-bit shared secret.
  3. All WebSocket payloads are AES-GCM encrypted on the sender before leaving the device.
  4. Decryption happens only on the receiving device β€” Cloudflare and any intermediaries only see ciphertext.

This provides zero-knowledge routing β€” even if the Cloudflare tunnel is compromised, the attacker cannot read the plaintext.



Saif Mukhtar

Saif Mukhtar

Creator & Lead Developer of Antimatter Β· Android, iOS & Python engineer