This is not an A2A extension. It has not been proposed to the A2A project, has no maintainer sponsorship, and is not official, experimental or recognised in any A2A process. See A2A Extension and Protocol Binding Governance for what those terms mean.
The specification is not written. The extension URIs below are proposals, not allocations. One of them sits in a namespace cheqd does not own (see Open questions).
Do not implement against this. Nothing here is agreed, reviewed or stable. This is an early exploration, not a cheqd product.
An exploration of how an A2A agent might prove, at the request boundary, that it is a known agent acting within granted authority, with its identity anchored on cheqd.
Two independently activatable extensions. Both URIs are provisional.
| Extension | Proposed URI | Would own |
|---|---|---|
| Request/response proof | https://kya-os.org/a2a/ext/proof/v1 |
Binding the org.kya-os/proof.v1 holder-of-key profile to A2A's message envelope |
| cheqd identity resolution | https://cheqd.io/a2a/ext/identity/v1 |
did:cheqd resolution, reciprocal alsoKnownAs linkage, DID-Linked Resource policy, credential status |
They would compose, but neither would require the other.
The two have different owners, which matters for how this repository is used. The proof binding is generic: the wire format is a DIF TAAWG specification and it works against did:web alone, with no cheqd involvement. Only the second extension is cheqd-specific.
- The proof URI namespace is not cheqd's.
org.kya-os/proof.v1is a DIF TAAWG specification andkya-os.orgis their namespace. Minting a binding URI there requires agreement with that working group. The alternative is a cheqd-owned URI, at the price of splitting the wire format and its identifier across two namespaces. - Whether to propose this to the A2A project at all, and if so, when relative to interoperability testing.
The implementation would live in cheqd/agent-toolkit and ship to npm. This repository holds only a specification and a reference sample, so it could be contributed to the A2A project without carrying cheqd's AP2 work or build tooling. That is the same shape as experimental-ext-oid4vp-auth, whose sample consumes its implementation from npm.
Licensed Apache 2.0 from the first commit, because official A2A extensions must be Apache 2.0 and relicensing later would need every contributor's agreement.
This project uses a Developer Certificate of Origin. Sign off your commits with git commit -s — see CONTRIBUTING.md.