Glossary · Identity and trust

Attestation (agents)

Signed evidence a system produces about its own state, such as the software it runs, appraised by a verifier so a relying party can decide what to trust.

Attestation is the process in which a system produces signed evidence about its own state, such as the software and configuration it is running, and a verifier appraises that evidence so another party can decide how far to trust the system.

The IETF model. RFC 9334, the Remote ATtestation procedureS (RATS) architecture, names the roles:

Role What it does
Attester Produces Evidence: claims about itself, such as measurements, configuration or telemetry
Verifier Appraises the Evidence against reference values and policy, and produces Attestation Results
Relying Party Uses the Attestation Results to decide what to allow

The RFC’s use cases include provisioning applications into a Trusted Execution Environment. RFC 9711 defines the Entity Attestation Token (EAT), a JWT or CBOR Web Token carrying attestation claims that a relying party uses to decide how much to trust an entity.

What it could add for agents. Authentication shows that a party holds a key. Attestation can add facts about the thing holding it: for example, that an agent’s signing key lives in protected hardware, or that a known build of an agent is running in a trusted execution environment. AP2’s agent authorization model mentions a hardware-attested key as one possible way for a verifier to trust a user’s approval of a mandate.

What it does not cover. Attestation describes a system’s state. It does not say who operates the agent, whom it acts for, or whether its principal approved a request, so it complements identity and authorization checks and replaces none of them.

Where the standards stop. A2A does not define attestation. A signed Agent Card proves which key published the card and says nothing about the code that answers requests at the endpoint. Anything beyond card signatures and TLS would come from an A2A extension or from general standards such as RATS and EAT. The word is also used loosely for any signed statement about an agent; this entry uses the RATS sense.

Neighbouring terms. Agent identity is the broader set of facts attestation can support. A verifiable credential is a related format for signed claims, usually about a person, organization or thing.

Sources

  1. RFC 9334: Remote ATtestation procedureS (RATS) Architecture (accessed )
  2. RFC 9711: The Entity Attestation Token (EAT) (accessed )
  3. AP2 documentation: Agent Authorization (accessed )
  4. A2A Protocol Specification, section 8.4: Agent Card Signing (accessed )