This page is the specification for the A2A extension https://inamprotocol.org/ext/a2a/v1. It lets an agent name its INAM ID on its Agent Card, so a client can look up a reputation built only from work receipts both parties signed. Normative source: INAM SPEC.md §11.3.
It is a data-only extension: it adds information to the card and changes no request or response. An agent MUST NOT mark it required. The agent adds one entry to capabilities.extensions:
{
"uri": "https://inamprotocol.org/ext/a2a/v1",
"description": "This agent's INAM ID.",
"required": false,
"params": { "did": "did:key:z6Mk..." }
}
and, once, links its service endpoint to that ID in the INAM registry. That request is signed by the ID's own key:
POST /v1/agents/{did}/link
{ "protocol": "a2a_endpoint", "value": "https://agent.example/a2a" }
A client that relies on the extension:
params.did and fetches that agent and its reputation from a registry the client trusts. The card does not choose the registry.supportedInterfaces[].url in A2A 1.0, or url / additionalInterfaces[].url in 0.3) MUST equal the agent's linked.a2a_endpoint, ignoring a trailing slash. Otherwise the client MUST treat the card as naming no INAM ID. The card names the ID and the ID, under its own signature, names the endpoint, so a card can't borrow a reputable agent's ID and an ID can't adopt someone else's endpoint.evidenceLevel, evidence and trustScore. These are the registry's hint. A client that wants a finding re-derives them from the signed receipts and log inclusion proofs (SPEC.md §5.4).With the TypeScript SDK (npm i inamprotocol, 0.15.0 or later):
import { verifyA2ACard } from "inamprotocol";
const decision = await verifyA2ACard(card, inamClient, { minEvidence: "countersigned" });
if (!decision.allow) console.log(decision.reason);
It does not authenticate the transport: use the card's own security schemes and, where available, A2A card signatures. It does not move money; for paid calls see the x402 check in SPEC.md §11.2. An endpoint link is an assertion signed by the ID, not a proof that the ID operates the server. It stops borrowing in both directions, but an operator who controls both can still link them.
A breaking change gets a new URI (/v2), as A2A's extension guidance requires. Questions and proposals: GitHub issues.