Overview
Implement offline-verifiable decision receipts as a first-party AGT capability. Every tool call an agent makes should produce a cryptographic receipt that third parties can verify without access to the original infrastructure.
Background
This feature was previously contributed by an external party but was removed in PR #1498 after the contributor was flagged for credential laundering by AGT's governance tools. The underlying concept has genuine value and should be reimplemented properly.
Requirements
- Receipt format: Per-tool-call Ed25519 signatures over JCS-canonical (RFC 8785) payloads
- Hash chaining: Receipts linked via parent hashes for insertion detection
- Offline verification: CLI tool to verify receipt chains without network access
- Cedar integration: Bind Cedar policy decisions to receipt payloads
- Audit log integration: Two-layer integrity with AGT's existing AuditLog
- SLSA provenance: Optional emission as SLSA provenance metadata
Standards Alignment
- Ed25519 (RFC 8032)
- JSON Canonicalization Scheme (RFC 8785)
- IETF draft-farley-acta-signed-receipts
- SLSA provenance predicates
Deliverables
Labels
enhancement, good first issue
Overview
Implement offline-verifiable decision receipts as a first-party AGT capability. Every tool call an agent makes should produce a cryptographic receipt that third parties can verify without access to the original infrastructure.
Background
This feature was previously contributed by an external party but was removed in PR #1498 after the contributor was flagged for credential laundering by AGT's governance tools. The underlying concept has genuine value and should be reimplemented properly.
Requirements
Standards Alignment
Deliverables
agent-governance-pythonLabels
enhancement, good first issue