1 file was added to this release more than 14 days after its initial publication. Inspect the release files before installing.
vouch-a2a
Bind A2A (Agent2Agent) Agent Cards to a Vouch identity, so two agents can establish trust before they collaborate.
A2A standardized how agents discover and talk to each other through Agent Cards.
It does not, by itself, prove who stands behind an agent. vouch-a2a attaches a
W3C Verifiable Credential (eddsa-jcs-2022 Data Integrity proof) to the card,
optionally with a delegation chain back to the human or org that operates the
agent. A verifier can then refuse an unsigned or impostor peer.
Install
pip install vouch-a2a
Sign an Agent Card
from vouch import Signer
from vouch_a2a import sign_agent_card
signer = Signer(private_key=PRIV_JWK, did="did:web:agents.acme.com")
card = {
"name": "BillingAgent",
"url": "https://agents.acme.com/billing",
"version": "1.0.0",
"capabilities": {"streaming": True},
"skills": [{"id": "invoice", "name": "Create invoice"}],
}
signed_card = sign_agent_card(signer, card) # adds a 'vouchCredential' field
# Optionally bind to an org principal:
# signed_card = sign_agent_card(signer, card, parent_credential=org_principal_cred)
Verify a peer's card
from vouch_a2a import verify_agent_card
ok, passport = verify_agent_card(peer_card, public_key=peer_pubkey)
if not ok:
raise PermissionError("Refusing to collaborate with an unverified agent")
The credential binds to the card's url (the stable agent identity). The input
card is never mutated; sign_agent_card returns a copy.
License
Apache-2.0.
Metadata
Release files for vouch-a2a 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
File added late
1 file was uploaded more than 14 days after the first file in this release.
While project maintainers occasionally add legitimate files to an existing release, late additions can also indicate a security compromise.
We recommend inspecting the release files before installing.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vouch_a2a-0.1.0.tar.gz | 3.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vouch_a2a-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 5.8 kB
Release files / vouch_a2a-0.1.0.tar.gz
File added late
This file was uploaded more than 14 days after the first file in this release.
While project maintainers occasionally add legitimate files to an existing release, late additions can also indicate a security compromise.
We recommend inspecting the release file before installing.
| Download URL | vouch_a2a-0.1.0.tar.gz |
|---|---|
| Size | 3.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f0e1806d392187156b9bb9908f32fbcc6c1bb7909c74a166ed6045752287eb0e
|
|
BLAKE2b-256 checksum How to use checksums |
0d2238dd1eb20431cde9d86f55689bb0eafaec38e23cd6b941ade6b07f46c669
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 5, 2026.
Transparency logRelease files / vouch_a2a-0.1.0-py3-none-any.whl
| Download URL | vouch_a2a-0.1.0-py3-none-any.whl |
|---|---|
| Size | 2.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4399eb5bf765264aa90d6b37a046a3c1c59c4b563c2cfd62e7cda4d7a5e7850c
|
|
BLAKE2b-256 checksum How to use checksums |
11d3aa9ea6f416adb81e51dbed8b54eca081512210cc67cfa282f9d6832e9c06
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.9
|