Skip to content
@opena2a-standards

OpenA2A

OpenA2A

Standards


Open specifications for AI agent security: identity, trust credentials, threat models, behavioral governance, and the conformance suites that test them. Vendor-neutral. Apache 2.0 unless noted per repo.

  • Agent Identity Protocol (AIP): open standard for AI agent identity, capabilities, and trust.
  • did:opena2a: registry-mediated DID method for agents and agent infrastructure. Registered in the W3C DID Extensions registry (did-extensions#717, merged 2026-07-04).
  • Agent Trust Protocol (ATP): open standard for verifiable trust assertions about AI agents.
  • ATX: Agent Trust eXtension credential format and protocol architecture.
  • Agent Authorization Protocol (AAP): scoped, attested authorization; credentials never enter the agent's context.
  • Agent Threat Matrix: tactics and techniques for attacks on AI agent systems. 61 techniques across 9 tactics, evidence-graded, mapped to MITRE, ATLAS, and OWASP. MITRE submission in flight.
  • ABGS: Agent Behavioral Governance Specification. What goes in a SOUL.md file.
  • AIIS Signatures: AI Injection Signature Standard. YARA-style signatures for AI agent prompt injections in web content.
  • OTel SemConv for agent identity: OpenTelemetry semantic conventions for AI agent authorization observability.

Conformance suites:

  • ATX Conformance: byte-pinned fixtures and Go + Python reference verifiers for ATX v1.0 and v1.1, with a cross-language JCS byte-agreement gate.
  • ATP Conformance: fixtures and Go + Python reference verifiers for ATP v1.0.0-rc1.
  • AIP Conformance: challenge-response fixtures and Go + Python reference verifiers for AIP.
  • A2A-IDF Conformance: canonical conformance suite for A2A-IDF.
  • opena2a-parity: cross-CLI parity gate for the OpenA2A CLI fleet.

The specifications are documented, with runnable walkthroughs, at specs.opena2a.org.

See GOVERNANCE.md for how decisions are made and how to contribute. The catalog of all OpenA2A organizations and projects lives at opena2a.org/projects.

Pinned Loading

  1. agent-threat-matrix agent-threat-matrix Public

    AI Agent Threat Matrix: A structured framework for classifying, detecting, and defending against attacks on AI agent systems

    Python 5

  2. agent-identity-protocol agent-identity-protocol Public

    Agent Identity Protocol (AIP) — an open standard for AI agent identity, capabilities, and trust

    Python 3

  3. agent-trust-protocol agent-trust-protocol Public

    Agent Trust Protocol (ATP) — an open standard for verifiable trust assertions about AI agents

    Python 2

  4. aiis-signatures aiis-signatures Public

    AI Injection Signature Standard — YARA-style signatures for AI agent prompt injections in web content. Apache 2.0.

    Go 1

  5. atx-spec atx-spec Public

    Agent Trust eXtension (ATX) credential format and Agent Trust Protocol (ATP) architecture specifications. Open standard for AI agent trust credentials.

    Python 1

  6. agent-authorization-protocol agent-authorization-protocol Public

    Agent Authorization Protocol (AAP): scoped, attested authorization for AI agent systems. Token model + broker/resolution layer.

    Python 1

Repositories

Showing 10 of 19 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…