Technical report / Version 1

cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A

Rishabh Poddar, Aaron Fulkerson, Imran Siddique

OPAQUE Systems

September 27, 2026Not peer reviewedPatent Pending

Abstract

The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.

What this report contributes

A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.

Evidence and limits

The source package preserves the recorded inputs and results. The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026ca2a,
  title = {cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A},
  author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
  institution = {AgenTrust},
  year = {2026},
  type = {Technical report},
  note = {Version 1; not peer reviewed},
  doi = {10.5281/zenodo.23022872},
  url = {https://agentrust-io.com/research/ca2a/v1/}
}

Version history

Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.

Revises a draft dated July 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.