Summary
Implement TraceClaimSigner: takes a TrustRecord dict, produces a compact EdDSA JWT signed over the JCS-canonical payload with the configured key.
Scope
New file: agent-governance-python/agent-mesh/src/agentmesh/governance/trace_signing.py
Key management:
- Load Ed25519 private key from
TRACE_PRIVATE_KEY_PEM env var at startup
- If absent, generate an ephemeral key and emit a startup warning
- Expose
public_key_jwk() -> dict for embedding in cnf.jwk
Signing:
- Canonicalize payload with RFC 8785 JCS (
json_canonicalize or equivalent)
- Sign with EdDSA (
PyJWT + cryptography, algorithm "EdDSA")
- JWT headers:
{"alg": "EdDSA", "typ": "JWT"}
- Inject
cnf: {"jwk": public_key_jwk()} into payload before signing
Dependencies: PyJWT>=2.8.0, cryptography>=42.0.0, json-canonicalize
Acceptance criteria
References
Summary
Implement
TraceClaimSigner: takes aTrustRecorddict, produces a compact EdDSA JWT signed over the JCS-canonical payload with the configured key.Scope
New file:
agent-governance-python/agent-mesh/src/agentmesh/governance/trace_signing.pyKey management:
TRACE_PRIVATE_KEY_PEMenv var at startuppublic_key_jwk() -> dictfor embedding incnf.jwkSigning:
json_canonicalizeor equivalent)PyJWT+cryptography, algorithm"EdDSA"){"alg": "EdDSA", "typ": "JWT"}cnf: {"jwk": public_key_jwk()}into payload before signingDependencies:
PyJWT>=2.8.0,cryptography>=42.0.0,json-canonicalizeAcceptance criteria
TraceClaimSignerclass withsign(record: dict) -> strreturning compact JWTpublic_key_jwk()returns valid JWK dict (kty: "OKP",crv: "Ed25519")cnf.jwkReferences