Extension proposal: signed-receipts/v1 — a did:web key-trust convention for §8.4 + signed task-outcome receipts
- Langage dominant
- Shell
- Étoiles
- 25.7k
- Forks
- 2.6k
- Merge moyen
- 3 j 6 h
- PR mergées (30 j)
- 16
Description
§8.4 standardises the AgentCard JWS envelope but deliberately leaves the key-trust root unspecified, and attestation of task *outcomes* is unstandardised — two agents can interoperate, but neither can hand a third party durable evidence of what happened.
We've drafted an extension (experimental tier) that adds:
1. a key-trust convention: JWS `kid` as a `did:web` URL, resolved at `/.well-known/did.json` — no new registry or PKI;
2. a signed receipt object (RFC 8785 canonical JSON, Ed25519, offline-verifiable) an agent MAY attach to task completion via `Task.metadata`;
3. a normative register: a receipt is evidence of what was claimed and when — never a certification or endorsement.
Spec + ~100-line reference interceptor (Apache-2.0, roundtrip/tamper-tested): https://github.com/CSOAI-ORG/a2a-signed-receipts
Is the experimental extension path the right venue for this? Happy to adapt to the extension governance process and any naming/shape feedback.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.