
A2A Passport — one GTIN, one call, everything GSC knows, signed
io.github.greencore-solutionsv1.0.0Updated Oct 5, 2026
The hubs are the records; A2A-Passport.ai issues the passport.
Overview
Issues and verifies signed product or retail-banner passports composed live from the GSC hubs, keyed by GTIN or market/banner.
- What it does
- Exposes three tools: get_passport returns a signed passport for a product GTIN or a retail banner, showing which hub holds its record, where it is cleared, its compliance records, who lists it and where the payment door is; list_passports returns register entries (ids, kinds, markets, versions, issue times) without bodies; verify_passport checks the signature, version chain, stamp age and any unread sections. Passports are read live from the GSC hubs on each call and signed with EdDSA; the passport never infers, and a product no hub holds gets no passport.
- When to use it
- Use it when an assistant needs a signed, verifiable record about a specific product GTIN or a retail banner, or needs to check that such a record is authentic and current. It suits trade-oriented lookups where the source of each field matters.
- Requirements
- A remote streamable-HTTP endpoint; no registration and no token are needed for reads. Verification uses the published EdDSA key. A verified, countersigned copy settles by x402 payment.
Installation
In SourceWeft
- Open A2A Passport — one GTIN, one call, everything GSC knows, signed in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"a2a-passport": {
"type": "http",
"url": "https://mcp.a2a-passport.ai/mcp"
}
}
}README
A2A Passport — one GTIN, one call, everything GSC knows, signed
The hubs are the records; A2A-Passport.ai issues the passport.
The hubs are the records; A2A-Passport.ai issues the passport. A passport is a signed document for a product or a retail banner: where its record lives, where it is cleared, who lists it, where the money door is. Issued live from the GSC hubs, stamped every week. A2A Passport is operated by GreenCore Solutions Corp.: one signed document per product (a Global Trade Item Number, GTIN) or retail banner, composed live from the GSC hubs — A2A Grocery, A2A Cosmetics, A2A Peptides, A2A Retailmedia and the compliance records — and signed (EdDSA). Three tools: get_passport, list_passports, verify_passport. Every field is a hub's answer, word for word, with the door and the time it was read, or it is absent with a note: the passport never infers. A product no hub holds gets no passport. Reads are open; a verified, countersigned copy settles by x402. Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.
A2A Passport is built and run by GreenCore Solutions Corp. (github.com/greencore-solutions). This is the public connect kit, MIT.
The door
streamable-HTTP, stateless, server name a2a-passport, door version 1.0.1, 3 tools (read from the wire)
- Endpoint:
https://mcp.a2a-passport.ai/mcp— any client that speaks streamable-HTTP:{ "url": "https://mcp.a2a-passport.ai/mcp", "transport": "streamable-http" } - Agent Card (signed):
https://a2a-passport.ai/.well-known/agent-card.json - Key:
https://a2a-passport.ai/.well-known/jwks.json(EdDSA, key ida2apass-2026-10) - No registration and no token: every read is open.
The tools
get_passport— The signed passport of a product (a Global Trade Item Number, GTIN) or a retail banner (market/banner, e.g. FR/Carrefour): which hub holds its record, where it is cleared, its compliance records, who lists it, where the payment door is. Read live from the GSC hubs on every call; the first call issues version 1. subject = a GTIN (8 to 14 digits) or market/banner; kind = gtin or banner (optional).list_passports— The passports on the register: ids, kinds, markets, versions and issue times, newest first. No bodies. Filter by kind (gtin or banner), market, or issued since a time; paginated.verify_passport— Check a passport: is the signature valid, is the chain of versions intact, how old is the stamp, was any section not read. Verifies from the published key at /.well-known/jwks.json.
The document
One envelope for both kinds (a product by its GTIN, or a retail banner as market/banner): passport_id, kind, subject, issued_at, version, previous_version_hash, issuer, signature, delta, and the body.
Every field in the body is a hub's answer, word for word, with the door, the tool and the time it was read — or it is absent with a note. The passport never infers.
- Current version:
https://a2a-passport.ai/passport/{id}.json - One version:
https://a2a-passport.ai/passport/{id}/v{n}.json - Passport #1:
https://a2a-passport.ai/passport/gtin-03284230006408.json - The register (live counts):
https://a2a-passport.ai/passports/register.json
A product that no hub holds on its record gets no passport.
Verify a passport yourself
The signature is a detached JSON Web Signature (EdDSA) over the passport without its signature field, keys sorted, compact JSON, UTF-8. examples/verify_passport.py does it with the published key and nothing else.
The countersigned copy
Reading a passport is free. A verified, countersigned copy settles at https://a2a-passport.ai/api (x402, two accept entries). A passport that is not on the register answers HTTP 403 and is not charged.
Examples
examples/generic_mcp_client.py— a stock client: lists the tools, reads passport #1, verifies it on the door.examples/verify_passport.py— fetches a passport and the key over plain HTTP and verifies the signature offline.
Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.
Source: README.md at commit 53f7b1d
Tools
0Version history
1- v1.0.0LatestOct 5, 2026

