Sitelet https://github.com/a2aproject/A2A/issues/2152
Skip to content

Proposal: signed-receipts/v1 extension (did:web key-trust for §8.4 + message-level attestation) #2152

Description

@CSOAI-ORG

Coordinate-first: proposing a signed-receipts/v1 extension for A2A.

We (CSOAI, independent measurement body, did:web:csoai.org) built a small extension draft (SPEC + reference interceptor) that fills two gaps A2A v1.0 deliberately leaves open:

  1. §8.4 key-trust convention — the JWS kid is a DID URL under did:web: (e.g. did:web:csoai.org#site-release-1); verifiers resolve the DID doc at /.well-known/did.json. No new registry, no new PKI.
  2. Message-level attestation — a signed receipt object an agent MAY attach to any Task completion (Task.metadata["signed-receipts/v1"]): issuer DID, subject card, task id, claims with evidence hashes, RFC-8785 canonical, Ed25519, offline-verifiable.

Positioning: a receipt is evidence of what an agent actually did and when — never a certification, endorsement, or conformity mark. We'd rather align on the envelope shape with the project than run parallel. Happy to open as an issue/PR here on your word — spec + ~100-line reference interceptor ready (Apache-2.0).

— CSOAI (Nicholas Templeman), via the DSH lane

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions