a2aproject / a2aproject/A2A

Proposal: signed-receipts/v1 extension (did:web key-trust for §8.4 + message-level attestation)

未关闭
#2,152 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Shell
星标
25.7k
派生
2.6k
平均合并
3 天 6 小时
30 天内合并 PR
16

描述

Coordinate-first: proposing a `signed-receipts/v1` extension for A2A.

We (CSOAI, independent measurement body, did:web:csoai.org) built a small extension draft (SPEC + reference interceptor) that fills two gaps A2A v1.0 deliberately leaves open:

1. **§8.4 key-trust convention** — the JWS kid is a DID URL under did:web: (e.g. did:web:csoai.org#site-release-1); verifiers resolve the DID doc at /.well-known/did.json. No new registry, no new PKI.
2. **Message-level attestation** — a signed receipt object an agent MAY attach to any Task completion (Task.metadata["signed-receipts/v1"]): issuer DID, subject card, task id, claims with evidence hashes, RFC-8785 canonical, Ed25519, offline-verifiable.

Positioning: a receipt is evidence of what an agent actually did and when — never a certification, endorsement, or conformity mark. We'd rather align on the envelope shape with the project than run parallel. Happy to open as an issue/PR here on your word — spec + ~100-line reference interceptor ready (Apache-2.0).

— CSOAI (Nicholas Templeman), via the DSH lane

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。