Signed Agent Card
An Agent Card that carries JWS signatures over its RFC 8785 canonical form, so clients can detect tampering and see which key signed it.
A signed Agent Card is an Agent Card that includes one or more JSON Web Signatures (RFC 7515) in its signatures field, so a client can verify that the card has not changed since the holder of the signing key signed it. Signing is optional in A2A v1.0 (specification section 8.4).
What gets signed. The signer takes the card, removes the signatures field, and drops fields that hold default values under the Protocol Buffer field-presence rules in section 5.7. Required fields always stay. Optional fields stay only if they were explicitly set. The result is canonicalized with the JSON Canonicalization Scheme (RFC 8785), which fixes key order and removes insignificant whitespace, and that canonical JSON is the JWS payload.
Signature format. Each entry in signatures is an AgentCardSignature with a base64url protected header, a base64url signature, and an optional unprotected header object. The protected header must include alg, typ and kid, with JOSE as the recommended typ value. It may also carry jku, the URL of a JWK Set that holds the public key. Decoded, a protected header looks like this:
{"alg": "ES256", "typ": "JOSE", "kid": "key-1", "jku": "https://example.com/agent/jwks.json"}
Verification. The client takes a signature from the array, gets the public key through kid and jku or from its own trusted key store, rebuilds the same canonical payload, and checks the signature against it. Clients should verify at least one signature before they trust a card, should fetch keys over HTTPS, and must not use expired or revoked keys. A card may carry several signatures to support key rotation.
What a signature does not settle. A valid signature proves integrity and possession of the private key. It does not prove that the key belongs to the organization named in the card’s provider field. The specification lets clients keep a trusted key store for known providers, but it does not define how a key is bound to an organization. That binding is a separate trust decision for the client, so a signed card is one input to an agent identity check.
Sources
- A2A Protocol Specification, section 8.4: Agent Card Signing (accessed )
- A2A Protocol Specification, section 5.7: Field Presence and Optionality (accessed )
- A2A protocol definition (a2a.proto): AgentCardSignature (accessed )
- RFC 7515: JSON Web Signature (JWS) (accessed )
- RFC 8785: JSON Canonicalization Scheme (JCS) (accessed )