a2aproject / a2aproject/A2A

Extension proposal: signed-receipts/v1 — a did:web key-trust convention for §8.4 + signed task-outcome receipts

Ouverte
#2,150 5 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Shell
Étoiles
25.7k
Forks
2.6k
Merge moyen
3 j 6 h
PR mergées (30 j)
16

Description

§8.4 standardises the AgentCard JWS envelope but deliberately leaves the key-trust root unspecified, and attestation of task *outcomes* is unstandardised — two agents can interoperate, but neither can hand a third party durable evidence of what happened.

We've drafted an extension (experimental tier) that adds:
1. a key-trust convention: JWS `kid` as a `did:web` URL, resolved at `/.well-known/did.json` — no new registry or PKI;
2. a signed receipt object (RFC 8785 canonical JSON, Ed25519, offline-verifiable) an agent MAY attach to task completion via `Task.metadata`;
3. a normative register: a receipt is evidence of what was claimed and when — never a certification or endorsement.

Spec + ~100-line reference interceptor (Apache-2.0, roundtrip/tamper-tested): https://github.com/CSOAI-ORG/a2a-signed-receipts

Is the experimental extension path the right venue for this? Happy to adapt to the extension governance process and any naming/shape feedback.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.