Proposal: signed-receipts/v1 extension (did:web key-trust for §8.4 + message-level attestation)
- Lenguaje dominante
- Shell
- Estrellas
- 25.7k
- Forks
- 2.6k
- Merge medio
- 3 d 6 h
- PR fusionados (30 d)
- 16
Descripción
Coordinate-first: proposing a `signed-receipts/v1` extension for A2A.
We (CSOAI, independent measurement body, did:web:csoai.org) built a small extension draft (SPEC + reference interceptor) that fills two gaps A2A v1.0 deliberately leaves open:
1. **§8.4 key-trust convention** — the JWS kid is a DID URL under did:web: (e.g. did:web:csoai.org#site-release-1); verifiers resolve the DID doc at /.well-known/did.json. No new registry, no new PKI.
2. **Message-level attestation** — a signed receipt object an agent MAY attach to any Task completion (Task.metadata["signed-receipts/v1"]): issuer DID, subject card, task id, claims with evidence hashes, RFC-8785 canonical, Ed25519, offline-verifiable.
Positioning: a receipt is evidence of what an agent actually did and when — never a certification, endorsement, or conformity mark. We'd rather align on the envelope shape with the project than run parallel. Happy to open as an issue/PR here on your word — spec + ~100-line reference interceptor ready (Apache-2.0).
— CSOAI (Nicholas Templeman), via the DSH lane
Guía de contribución
Línea de trabajo
The issue proposes a new extension for the A2A protocol. Review the A2A specification, focusing on §8.4 and Task metadata. Examine the existing codebase for extension points and interceptor patterns. The work involves designing and integrating a new signed receipts feature, which requires understanding of DIDs, JWS, and the protocol's security model.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Área
- api, security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Activo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 30/100