a2aproject / a2aproject/A2A

Proposal: signed-receipts/v1 extension (did:web key-trust for §8.4 + message-level attestation)

オープン
#2,152 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Shell
スター
25.7k
フォーク
2.6k
平均マージ
3日 6時間
マージ済み PR(30日)
16

説明

Coordinate-first: proposing a `signed-receipts/v1` extension for A2A.

We (CSOAI, independent measurement body, did:web:csoai.org) built a small extension draft (SPEC + reference interceptor) that fills two gaps A2A v1.0 deliberately leaves open:

1. **§8.4 key-trust convention** — the JWS kid is a DID URL under did:web: (e.g. did:web:csoai.org#site-release-1); verifiers resolve the DID doc at /.well-known/did.json. No new registry, no new PKI.
2. **Message-level attestation** — a signed receipt object an agent MAY attach to any Task completion (Task.metadata["signed-receipts/v1"]): issuer DID, subject card, task id, claims with evidence hashes, RFC-8785 canonical, Ed25519, offline-verifiable.

Positioning: a receipt is evidence of what an agent actually did and when — never a certification, endorsement, or conformity mark. We'd rather align on the envelope shape with the project than run parallel. Happy to open as an issue/PR here on your word — spec + ~100-line reference interceptor ready (Apache-2.0).

— CSOAI (Nicholas Templeman), via the DSH lane

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

The issue proposes a new extension for the A2A protocol. Review the A2A specification, focusing on §8.4 and Task metadata. Examine the existing codebase for extension points and interceptor patterns. The work involves designing and integrating a new signed receipts feature, which requires understanding of DIDs, JWS, and the protocol's security model.

索引モデルが issue の本文から書いたものです。

評価

領域
api, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
30/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。