Technical report / Version 1
Authenticating the Answer in an Agent Handoff: Single-use, request-bound response authentication and the outcome a caller cannot know
OPAQUE Systems
Abstract
One agent appraises a peer, delegates a task to it, and gets an HTTP response back. Appraising the peer before sending says nothing about who wrote that response. A relay can swap the body, replay an answer from another call, or turn an error into a success. We study the strict response-authentication mode of the cA2A runtime, which binds the appraised peer key, the complete request and a fresh request occurrence into a key that can verify exactly one response, once. It authenticates success and denial bodies, binds the status the caller will act on, and reports an unknown outcome whenever verification or transport fails, instead of guessing. On the pinned source, 57 selected tests pass, including loopback HTTP exchanges, and removing the MAC comparison or the single-use consumption makes 4 and 3 of them fail. In 20 rounds of 16 concurrent verifications, exactly one response is accepted per round. With separate caller, relay and peer processes and the connection cut before dispatch, after execution, mid-body, or with the caller killed, the client submits once, reports unknown, and a restarted caller cannot accept the captured response. A control client that resends once on a transport error makes the peer execute one business operation twice. The authentication is for the live caller: the caller can compute the same MAC, so a stored response is not proof of peer authorship to a third party. All results were rerun on October 1, 2026 from a fresh environment and match the earlier records, and the same harness passes on current cA2A main.
What this report contributes
A strict response-authentication mode that binds the appraised peer key, the complete request and a fresh occurrence into a single-use key, and reports unknown outcomes instead of guessing.
Evidence and limits
- Software-only, on one Windows host over loopback with software peer assurance. Hardware protection of the peer key and key rotation on attested hardware were not tested.
- The authentication is for the live caller: the caller can compute the same MAC, so a stored response does not prove peer authorship to a third party.
- A MAC does not encrypt the response, a compromised peer can authenticate a wrong answer, and the test oracle shares some serializers with the implementation.
The source package preserves the recorded inputs and results. Every experiment was rerun on October 1, 2026 in a fresh environment at the evaluated revision and at current main. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. Authenticating the Answer in an Agent Handoff: Single-use, request-bound response authentication and the outcome a caller cannot know. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026handoffresponseauthentication,
title = {Authenticating the Answer in an Agent Handoff: Single-use, request-bound response authentication and the outcome a caller cannot know},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23091302},
url = {https://agentrust-io.com/research/handoff-response-authentication/v1/}
}
Version history
Version 1, October 1, 2026: First public edition. Evaluates cA2A fc22c64; results were rerun on October 1, 2026 from a fresh environment, and the same harness passes on main 19407fb.
Based on an internal study drafted September 23, 2026 and rerun September 27, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.