
A2A Passport — one GTIN, one call, everything GSC knows, signed
io.github.greencore-solutionsv1.0.0更新于 Oct 5, 2026
The hubs are the records; A2A-Passport.ai issues the passport.
概览
签发并验证由 GSC 各枢纽实时汇编的、以 GTIN 或市场/横幅为键的签名商品或零售横幅护照。
- 功能
- 提供三个工具:get_passport 返回商品 GTIN 或零售横幅的签名护照,说明哪个枢纽持有其记录、在哪里清关、其合规记录、谁将其列入清单以及付款入口在哪里;list_passports 返回登记册条目(id、类型、市场、版本、签发时间),不含正文;verify_passport 检查签名、版本链、时间戳新旧以及是否有未读取的部分。每次调用都从 GSC 枢纽实时读取,并使用 EdDSA 签名;护照从不推断,任何枢纽都不持有的商品不会获得护照。
- 适用场景
- 当助手需要关于特定商品 GTIN 或零售横幅的、可验证的签名记录,或需要确认此类记录真实且最新时使用。适合重视每个字段来源的贸易类查询。
- 运行要求
- 远程 streamable-HTTP 端点;读取无需注册、无需令牌。验证使用已发布的 EdDSA 密钥。经过验证并会签的副本通过 x402 结算。
安装
在 SourceWeft 中
- 打开 控制台中的 A2A Passport — one GTIN, one call, everything GSC knows, signed,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"a2a-passport": {
"type": "http",
"url": "https://mcp.a2a-passport.ai/mcp"
}
}
}README
A2A Passport — one GTIN, one call, everything GSC knows, signed
The hubs are the records; A2A-Passport.ai issues the passport.
The hubs are the records; A2A-Passport.ai issues the passport. A passport is a signed document for a product or a retail banner: where its record lives, where it is cleared, who lists it, where the money door is. Issued live from the GSC hubs, stamped every week. A2A Passport is operated by GreenCore Solutions Corp.: one signed document per product (a Global Trade Item Number, GTIN) or retail banner, composed live from the GSC hubs — A2A Grocery, A2A Cosmetics, A2A Peptides, A2A Retailmedia and the compliance records — and signed (EdDSA). Three tools: get_passport, list_passports, verify_passport. Every field is a hub's answer, word for word, with the door and the time it was read, or it is absent with a note: the passport never infers. A product no hub holds gets no passport. Reads are open; a verified, countersigned copy settles by x402. Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.
A2A Passport is built and run by GreenCore Solutions Corp. (github.com/greencore-solutions). This is the public connect kit, MIT.
The door
streamable-HTTP, stateless, server name a2a-passport, door version 1.0.1, 3 tools (read from the wire)
- Endpoint:
https://mcp.a2a-passport.ai/mcp— any client that speaks streamable-HTTP:{ "url": "https://mcp.a2a-passport.ai/mcp", "transport": "streamable-http" } - Agent Card (signed):
https://a2a-passport.ai/.well-known/agent-card.json - Key:
https://a2a-passport.ai/.well-known/jwks.json(EdDSA, key ida2apass-2026-10) - No registration and no token: every read is open.
The tools
get_passport— The signed passport of a product (a Global Trade Item Number, GTIN) or a retail banner (market/banner, e.g. FR/Carrefour): which hub holds its record, where it is cleared, its compliance records, who lists it, where the payment door is. Read live from the GSC hubs on every call; the first call issues version 1. subject = a GTIN (8 to 14 digits) or market/banner; kind = gtin or banner (optional).list_passports— The passports on the register: ids, kinds, markets, versions and issue times, newest first. No bodies. Filter by kind (gtin or banner), market, or issued since a time; paginated.verify_passport— Check a passport: is the signature valid, is the chain of versions intact, how old is the stamp, was any section not read. Verifies from the published key at /.well-known/jwks.json.
The document
One envelope for both kinds (a product by its GTIN, or a retail banner as market/banner): passport_id, kind, subject, issued_at, version, previous_version_hash, issuer, signature, delta, and the body.
Every field in the body is a hub's answer, word for word, with the door, the tool and the time it was read — or it is absent with a note. The passport never infers.
- Current version:
https://a2a-passport.ai/passport/{id}.json - One version:
https://a2a-passport.ai/passport/{id}/v{n}.json - Passport #1:
https://a2a-passport.ai/passport/gtin-03284230006408.json - The register (live counts):
https://a2a-passport.ai/passports/register.json
A product that no hub holds on its record gets no passport.
Verify a passport yourself
The signature is a detached JSON Web Signature (EdDSA) over the passport without its signature field, keys sorted, compact JSON, UTF-8. examples/verify_passport.py does it with the published key and nothing else.
The countersigned copy
Reading a passport is free. A verified, countersigned copy settles at https://a2a-passport.ai/api (x402, two accept entries). A passport that is not on the register answers HTTP 403 and is not charged.
Examples
examples/generic_mcp_client.py— a stock client: lists the tools, reads passport #1, verifies it on the door.examples/verify_passport.py— fetches a passport and the key over plain HTTP and verifies the signature offline.
Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.
来源:README.md,提交 53f7b1d
工具
0版本历史
1- v1.0.0最新Oct 5, 2026

