Open specifications for AI agent security: identity, trust credentials, threat models, behavioral governance, and the conformance suites that test them. Vendor-neutral. Apache 2.0 unless noted per repo.
- Agent Identity Protocol (AIP): open standard for AI agent identity, capabilities, and trust.
- did:opena2a: registry-mediated DID method for agents and agent infrastructure. Registered in the W3C DID Extensions registry (did-extensions#717, merged 2026-07-04).
- Agent Trust Protocol (ATP): open standard for verifiable trust assertions about AI agents.
- ATX: Agent Trust eXtension credential format and protocol architecture.
- Agent Authorization Protocol (AAP): scoped, attested authorization; credentials never enter the agent's context.
- Agent Threat Matrix: tactics and techniques for attacks on AI agent systems. 61 techniques across 9 tactics, evidence-graded, mapped to MITRE, ATLAS, and OWASP. MITRE submission in flight.
- ABGS: Agent Behavioral Governance Specification. What goes in a SOUL.md file.
- AIIS Signatures: AI Injection Signature Standard. YARA-style signatures for AI agent prompt injections in web content.
- OTel SemConv for agent identity: OpenTelemetry semantic conventions for AI agent authorization observability.
Conformance suites:
- ATX Conformance: byte-pinned fixtures and Go + Python reference verifiers for ATX v1.0 and v1.1, with a cross-language JCS byte-agreement gate.
- ATP Conformance: fixtures and Go + Python reference verifiers for ATP v1.0.0-rc1.
- AIP Conformance: challenge-response fixtures and Go + Python reference verifiers for AIP.
- A2A-IDF Conformance: canonical conformance suite for A2A-IDF.
- opena2a-parity: cross-CLI parity gate for the OpenA2A CLI fleet.
The specifications are documented, with runnable walkthroughs, at specs.opena2a.org.
See GOVERNANCE.md for how decisions are made and how to contribute. The catalog of all OpenA2A organizations and projects lives at opena2a.org/projects.
