Skip to content

Release 3.0.0: A2A 1.0 agent cards, UCP 2026-08-25 profiles, MPP payment offers - #141

Merged
vvillait88 merged 2 commits into
mainfrom
spec-currency-a2a-ucp-mpp
Oct 3, 2026
Merged

vvillait88 merged 2 commits into
mainfrom
spec-currency-a2a-ucp-mpp

Conversation

@vvillait88

@vvillait88 vvillait88 commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Brings the discovery documents in line with the current upstream specifications. Requested by Varun after a report that our A2A cards were out of date; a sweep of every hand-written format found two more.

  • A2A agent card. The card declared protocol 1.0 but carried the 0.3 shape. A2A 1.0 (specification/a2a.proto at v1.0.1) moved the endpoint, binding and protocol version into the required supportedInterfaces[], moved the extended-card flag into capabilities.extendedAgentCard, dropped stateTransitionHistory, and renamed security to securityRequirements (on skills too). buildA2AAgentCard keeps its inputs (url, preferredTransport, additionalInterfaces, security) and now emits the 1.0 shape. The UCP extension URI moves to 2026-08-25.
  • UCP profile. UCP 2026-08-25 removed signing_keys and made keys (a JWK Set) the one canonical field. The profile now publishes keys and version 2026-08-25. buildUCPProfile takes keys and still accepts signing_keys as an input alias. supported_versions is no longer published: it named the current profile under an older version, which the spec reserves for complete older-version profiles.
  • MPP payment discovery. MPP's draft-payment-discovery and x402scan both define x-payment-info, with different shapes. The block now carries MPP's offers[] (amount as an integer string in the rail's smallest unit, null when dynamic) beside the x402scan price and protocols, so both readers find their own keys.
  • Dependency sweep, in the same release. mppx 0.12.0 to 0.13.1 (dev, exact pin, coupled with pay). The Tempo proof EIP-712 domain stays at version 3 in both tarballs. 0.13.0 requires a shared atomic replay store on stripe.create() (the Stripe-backed Tempo method); our createMppxStripe wraps stripe.charge (SPT), which is unchanged, and no storefront calls stripe.create(). @types/node 26.6.4. Everything else is latest except the org-wide eslint 9 and typescript 6 holds; the axios and esbuild overrides still do work (removing axios resolves 1.16.0); OSV over bun.lock (896 packages) is clean.
  • The guard that should have caught this. a2a_canonical_type.test.ts was a type assignment that never compiled: vitest does not typecheck and tsc covers src only. It is now a round-trip through @a2a-js/sdk's own AgentCard codec, which drops any field the spec does not define, plus a test proving a 0.3-shaped card fails it.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

  • A2AAgentCard loses url, preferredTransport, protocolVersion, additionalInterfaces, supportsAuthenticatedExtendedCard and security; gains supportedInterfaces and securityRequirements. Skills in the card carry securityRequirements instead of security.
  • buildA2AAgentCard: stateTransitionHistory and supportsAuthenticatedExtendedCard options removed; extendedAgentCard added. All other options unchanged.
  • UCPProfile.signing_keys becomes keys. buildUCPProfile({ keys }); signing_keys still accepted as input.
  • wellKnownUcpUrl on buildSignedUcpResponse and mountUcpRoutes* becomes optional and is ignored.
  • XPaymentInfoBlock gains optional offers; new exports offersFrom, toSecurityRequirements, A2ASupportedInterface, A2ASecurityRequirement, A2AAgentCardSkill.
  • Version 3.0.0. Consumers reading the card JSON for url must read supportedInterfaces[0].url.

Test plan

  • Updated the A2A, UCP and signing tests for the new shapes, plus a test that none of the removed 0.3 fields appear.
  • New: MPP offers per rail (tempo and solana in 6-decimal base units, stripe in cents, x402 excluded, dynamic as null).
  • New: the codec guard, and its negative case on a stale card.
  • bun run lint, bun run typecheck (src and examples), bun run build, bun run test (1849 passed).
  • Read the live documents on all five storefronts before the change: every A2A card carried the 0.3 shape, three UCP profiles published signing_keys at 2026-04-08, and no /openapi.json carried offers.

What this deliberately does not do: release the package or move the storefronts. The release is a tag push after review, and each storefront takes 3.0.0 in its own PR. The live all-rails settle the mppx bump owes runs once a storefront is deployed on 3.0.0 with pay on the same mppx.

Checklist

  • Tests cover the new behavior, and the suite passes locally
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed
  • No secrets, credentials, or personal data in the diff or the tests

…ent offers

The agent card declared A2A 1.0 but carried the 0.3 shape: the endpoint now sits
in supportedInterfaces, the extended-card flag in capabilities, and security as
securityRequirements. The UCP profile publishes its signing keys as keys and
moves to 2026-08-25, which removed signing_keys; supported_versions is no longer
published, since it named the current profile as an older version's. x-payment-info
now also carries MPP's offers, priced in each rail's smallest unit, alongside the
x402scan fields.

The A2A canonical-type guard never ran (vitest does not typecheck and tsc covered
src alone). It is now a round-trip through @a2a-js/sdk's own codec, which drops any
field the spec does not define.
@vvillait88
vvillait88 merged commit 8633a6d into main Oct 3, 2026
6 checks passed
@vvillait88
vvillait88 deleted the spec-currency-a2a-ucp-mpp branch October 3, 2026 20:33
vvillait88 added a commit to agentscore/python-commerce that referenced this pull request Oct 3, 2026
…ent offers (#148)

## Summary

Mirrors node-commerce 3.0.0 (agentscore/node-commerce#141). Requested by
Varun after a report that our A2A cards were out of date; a sweep of
every hand-written format found two more.

- **A2A agent card.** The card declared protocol 1.0 but carried the 0.3
shape. `to_dict()` now emits A2A 1.0 (`specification/a2a.proto` at
v1.0.1): the required `supportedInterfaces[]` (url, protocolBinding,
protocolVersion), the extended-card flag in
`capabilities.extendedAgentCard`, and `securityRequirements` in place of
`security` on the card and on skills. `build_a2a_agent_card` keeps
`url`, `preferred_transport`, `additional_interfaces` and `security` as
inputs. The UCP extension URI moves to 2026-08-25.
- **UCP profile.** UCP 2026-08-25 removed `signing_keys` and made `keys`
(a JWK Set) the one canonical field. The profile publishes `keys` at
version 2026-08-25; `build_ucp_profile(keys=...)`, with `signing_keys`
still accepted. `supported_versions` is no longer published.
- **MPP payment discovery.** `x-payment-info` now also carries MPP's
`offers[]` (integer amount in the rail's smallest unit, `None` when
dynamic) beside the x402scan `price` and `protocols`. New `offers_from`.
- **Dependency sweep, in the same release.** Relocked (`markupsafe`
3.0.4, `tzdata` 2026.5) and the uv CLI workflow input moves to 0.12.23.
The capped requirements (`x402`, `pympp`, `redis`, `cdp-sdk`, `joserfc`,
`httpx`, `stripe`) all lock at PyPI latest, no prerelease is locked, and
OSV over `uv.lock` (157 packages) is clean.
- **A real guard.** `tests/test_a2a_canonical.py` parses the built card
as the official A2A `AgentCard` protobuf from `a2a-sdk` (added as a dev
dependency only), which refuses any field the spec does not define, plus
the negative case on a 0.3-shaped card.

## Type of change

- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [x] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only

## Public API

- Card JSON: `url`, `preferredTransport`, `protocolVersion`,
`additionalInterfaces`, `supportsAuthenticatedExtendedCard`, `security`
removed; `supportedInterfaces`, `securityRequirements` added.
- `build_a2a_agent_card`: `state_transition_history` and
`supports_authenticated_extended_card` removed; `extended_agent_card`
added. `A2AAgentCardCapabilities` follows the same rename.
- `UCPProfile.signing_keys` becomes `keys`;
`build_ucp_profile(keys=...)`, `signing_keys` still accepted.
- `well_known_ucp_url` on `build_signed_ucp_response` and the
`mount_ucp_routes_*` methods becomes optional and is ignored.
- New exports: `offers_from`, `to_security_requirements`. Version 3.0.0.

## Test plan

- Updated the A2A and UCP tests for the new shapes, including a test
that none of the removed 0.3 fields appear.
- New: MPP offers per rail through `x_payment_info_from_checkout`, and
the protobuf guard with its negative case.
- `uv run ruff check .`, `uv run ruff format --check .`, `uv run ty
check agentscore_commerce/`, `uv run vulture . --min-confidence 80
--exclude .venv`, `uv run pytest tests` (1891 passed, coverage 95.41%
against the 95% gate).

What this deliberately does not do: release the package or move core's
store, which takes 3.0.0 separately.

## Checklist

- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant