Technical report / Version 1
cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A
OPAQUE Systems
Abstract
The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.
What this report contributes
A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.
Evidence and limits
- Software experiments were rerun on September 27, 2026 against ca2a 0.3.1: correctness counts matched the July 2026 draft, and chain verification cost about 216 rather than 195 microseconds per hop.
- Cross-operator attestation was exercised only with synthetic evidence. Recorded hardware runs cover one-directional appraisal across clouds and a same-operator diagnostic, not mutual attestation between independent operators.
- The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records.
The source package preserves the recorded inputs and results. The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Rishabh Poddar; Aaron Fulkerson; Imran Siddique. cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026ca2a,
title = {cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A},
author = {Rishabh Poddar and Aaron Fulkerson and Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23022872},
url = {https://agentrust-io.com/research/ca2a/v1/}
}
Version history
Version 1, September 27, 2026: Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.
Revises a draft dated July 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.