Repository navigation
Release 3.0.0: A2A 1.0 agent cards, UCP 2026-08-25 profiles, MPP payment offers - #141
Merged
Merged
Conversation
…ent offers The agent card declared A2A 1.0 but carried the 0.3 shape: the endpoint now sits in supportedInterfaces, the extended-card flag in capabilities, and security as securityRequirements. The UCP profile publishes its signing keys as keys and moves to 2026-08-25, which removed signing_keys; supported_versions is no longer published, since it named the current profile as an older version's. x-payment-info now also carries MPP's offers, priced in each rail's smallest unit, alongside the x402scan fields. The A2A canonical-type guard never ran (vitest does not typecheck and tsc covered src alone). It is now a round-trip through @a2a-js/sdk's own codec, which drops any field the spec does not define.
5 of 8 tasks
vvillait88
added a commit
to agentscore/python-commerce
that referenced
this pull request
Oct 3, 2026
…ent offers (#148) ## Summary Mirrors node-commerce 3.0.0 (agentscore/node-commerce#141). Requested by Varun after a report that our A2A cards were out of date; a sweep of every hand-written format found two more. - **A2A agent card.** The card declared protocol 1.0 but carried the 0.3 shape. `to_dict()` now emits A2A 1.0 (`specification/a2a.proto` at v1.0.1): the required `supportedInterfaces[]` (url, protocolBinding, protocolVersion), the extended-card flag in `capabilities.extendedAgentCard`, and `securityRequirements` in place of `security` on the card and on skills. `build_a2a_agent_card` keeps `url`, `preferred_transport`, `additional_interfaces` and `security` as inputs. The UCP extension URI moves to 2026-08-25. - **UCP profile.** UCP 2026-08-25 removed `signing_keys` and made `keys` (a JWK Set) the one canonical field. The profile publishes `keys` at version 2026-08-25; `build_ucp_profile(keys=...)`, with `signing_keys` still accepted. `supported_versions` is no longer published. - **MPP payment discovery.** `x-payment-info` now also carries MPP's `offers[]` (integer amount in the rail's smallest unit, `None` when dynamic) beside the x402scan `price` and `protocols`. New `offers_from`. - **Dependency sweep, in the same release.** Relocked (`markupsafe` 3.0.4, `tzdata` 2026.5) and the uv CLI workflow input moves to 0.12.23. The capped requirements (`x402`, `pympp`, `redis`, `cdp-sdk`, `joserfc`, `httpx`, `stripe`) all lock at PyPI latest, no prerelease is locked, and OSV over `uv.lock` (157 packages) is clean. - **A real guard.** `tests/test_a2a_canonical.py` parses the built card as the official A2A `AgentCard` protobuf from `a2a-sdk` (added as a dev dependency only), which refuses any field the spec does not define, plus the negative case on a 0.3-shaped card. ## Type of change - [ ] Bug fix (no breaking change) - [ ] New feature (no breaking change) - [x] Breaking change (existing callers must update) - [ ] Docs, tests, or internal maintenance only ## Public API - Card JSON: `url`, `preferredTransport`, `protocolVersion`, `additionalInterfaces`, `supportsAuthenticatedExtendedCard`, `security` removed; `supportedInterfaces`, `securityRequirements` added. - `build_a2a_agent_card`: `state_transition_history` and `supports_authenticated_extended_card` removed; `extended_agent_card` added. `A2AAgentCardCapabilities` follows the same rename. - `UCPProfile.signing_keys` becomes `keys`; `build_ucp_profile(keys=...)`, `signing_keys` still accepted. - `well_known_ucp_url` on `build_signed_ucp_response` and the `mount_ucp_routes_*` methods becomes optional and is ignored. - New exports: `offers_from`, `to_security_requirements`. Version 3.0.0. ## Test plan - Updated the A2A and UCP tests for the new shapes, including a test that none of the removed 0.3 fields appear. - New: MPP offers per rail through `x_payment_info_from_checkout`, and the protobuf guard with its negative case. - `uv run ruff check .`, `uv run ruff format --check .`, `uv run ty check agentscore_commerce/`, `uv run vulture . --min-confidence 80 --exclude .venv`, `uv run pytest tests` (1891 passed, coverage 95.41% against the 95% gate). What this deliberately does not do: release the package or move core's store, which takes 3.0.0 separately. ## Checklist - [x] Tests cover the new behavior, and the suite passes locally - [x] Lint, format, and type checks pass - [x] Docs and README examples updated if the public surface changed - [x] No secrets, credentials, or personal data in the diff or the tests
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Brings the discovery documents in line with the current upstream specifications. Requested by Varun after a report that our A2A cards were out of date; a sweep of every hand-written format found two more.
specification/a2a.protoat v1.0.1) moved the endpoint, binding and protocol version into the requiredsupportedInterfaces[], moved the extended-card flag intocapabilities.extendedAgentCard, droppedstateTransitionHistory, and renamedsecuritytosecurityRequirements(on skills too).buildA2AAgentCardkeeps its inputs (url,preferredTransport,additionalInterfaces,security) and now emits the 1.0 shape. The UCP extension URI moves to 2026-08-25.signing_keysand madekeys(a JWK Set) the one canonical field. The profile now publisheskeysand version 2026-08-25.buildUCPProfiletakeskeysand still acceptssigning_keysas an input alias.supported_versionsis no longer published: it named the current profile under an older version, which the spec reserves for complete older-version profiles.draft-payment-discoveryand x402scan both definex-payment-info, with different shapes. The block now carries MPP'soffers[](amount as an integer string in the rail's smallest unit,nullwhen dynamic) beside the x402scanpriceandprotocols, so both readers find their own keys.mppx0.12.0 to 0.13.1 (dev, exact pin, coupled with pay). The Tempo proof EIP-712 domain stays at version 3 in both tarballs. 0.13.0 requires a shared atomic replay store onstripe.create()(the Stripe-backed Tempo method); ourcreateMppxStripewrapsstripe.charge(SPT), which is unchanged, and no storefront callsstripe.create().@types/node26.6.4. Everything else is latest except the org-wideeslint9 andtypescript6 holds; theaxiosandesbuildoverrides still do work (removingaxiosresolves 1.16.0); OSV overbun.lock(896 packages) is clean.a2a_canonical_type.test.tswas a type assignment that never compiled: vitest does not typecheck andtsccoverssrconly. It is now a round-trip through@a2a-js/sdk's ownAgentCardcodec, which drops any field the spec does not define, plus a test proving a 0.3-shaped card fails it.Type of change
Public API
A2AAgentCardlosesurl,preferredTransport,protocolVersion,additionalInterfaces,supportsAuthenticatedExtendedCardandsecurity; gainssupportedInterfacesandsecurityRequirements. Skills in the card carrysecurityRequirementsinstead ofsecurity.buildA2AAgentCard:stateTransitionHistoryandsupportsAuthenticatedExtendedCardoptions removed;extendedAgentCardadded. All other options unchanged.UCPProfile.signing_keysbecomeskeys.buildUCPProfile({ keys });signing_keysstill accepted as input.wellKnownUcpUrlonbuildSignedUcpResponseandmountUcpRoutes*becomes optional and is ignored.XPaymentInfoBlockgains optionaloffers; new exportsoffersFrom,toSecurityRequirements,A2ASupportedInterface,A2ASecurityRequirement,A2AAgentCardSkill.urlmust readsupportedInterfaces[0].url.Test plan
null).bun run lint,bun run typecheck(src and examples),bun run build,bun run test(1849 passed).signing_keysat 2026-04-08, and no/openapi.jsoncarriedoffers.What this deliberately does not do: release the package or move the storefronts. The release is a tag push after review, and each storefront takes 3.0.0 in its own PR. The live all-rails settle the mppx bump owes runs once a storefront is deployed on 3.0.0 with pay on the same mppx.
Checklist