Summary
Add the trace: config block to AGT configuration schema. Fail fast at startup if trace.emit: true but required fields are absent.
Scope
Extend the existing config schema (find the canonical config dataclass or schema file).
New trace: block:
trace:
emit: false # default off
output_path: "" # directory for .jwt files; optional
endpoint: "" # POST endpoint; optional
model:
provider: ""
model_id: ""
version: ""
weights_digest: "" # sha256: or sha384: prefixed
build_provenance:
slsa_level: 0
builder: ""
digest: ""
appraisal_verifier: "" # URI of the verifier; optional
Note: No agent_svid field. TRACE v0.2 accepts did: URIs natively -- subject is derived from session.agent_did at session close. Key material via TRACE_PRIVATE_KEY_PEM env var only.
Startup validation (when emit: true):
model.provider and model.model_id must be present
build_provenance.slsa_level must be 0, 1, 2, or 3
- At least one of
output_path or endpoint must be set (or warn that output goes to stdout)
Acceptance criteria
References
Summary
Add the
trace:config block to AGT configuration schema. Fail fast at startup iftrace.emit: truebut required fields are absent.Scope
Extend the existing config schema (find the canonical config dataclass or schema file).
New
trace:block:Note: No
agent_svidfield. TRACE v0.2 acceptsdid:URIs natively --subjectis derived fromsession.agent_didat session close. Key material viaTRACE_PRIVATE_KEY_PEMenv var only.Startup validation (when
emit: true):model.providerandmodel.model_idmust be presentbuild_provenance.slsa_levelmust be 0, 1, 2, or 3output_pathorendpointmust be set (or warn that output goes to stdout)Acceptance criteria
trace:block (noagent_svid)ConfigurationErrorwith a clear message for each missing required fieldsession_to_trust_recordmodel.providerraises, invalidslsa_levelraisesReferences