A2A Passport — one GTIN, one call, everything GSC knows, signed

io.github.greencore-solutionsv1.0.0更新於 Oct 5, 2026

The hubs are the records; A2A-Passport.ai issues the passport.

已驗證Streamable HTTP可網頁執行FinanceBusiness & Commerce

概覽

AI 產生的概覽

簽發並驗證由 GSC 各中樞即時彙編、以 GTIN 或市場/橫幅為鍵的簽章商品或零售橫幅護照。

功能
提供三個工具:get_passport 回傳商品 GTIN 或零售橫幅的簽章護照,說明哪個中樞持有其紀錄、在哪裡清關、其合規紀錄、誰將其列入清單,以及付款入口在哪裡;list_passports 回傳登記冊項目(id、類型、市場、版本、簽發時間),不含正文;verify_passport 檢查簽章、版本鏈、時間戳新舊,以及是否有未讀取的部分。每次呼叫都從 GSC 中樞即時讀取,並以 EdDSA 簽章;護照從不推論,任何中樞都不持有的商品不會取得護照。
適用情境
當助理需要關於特定商品 GTIN 或零售橫幅的、可驗證的簽章紀錄,或需要確認這類紀錄真實且最新時使用。適合重視每個欄位來源的貿易類查詢。
執行需求
遠端 streamable-HTTP 端點;讀取無需註冊、無需權杖。驗證使用已發布的 EdDSA 金鑰。經過驗證並會簽的副本透過 x402 結算。
安裝前請注意
讀取是開放的,但經過驗證並會簽的副本透過 x402 結算,涉及付款。此伺服器是代理式資訊來源,不是推薦,README 也提醒人工智慧會出錯。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 A2A Passport — one GTIN, one call, everything GSC knows, signed,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "a2a-passport": {
      "type": "http",
      "url": "https://mcp.a2a-passport.ai/mcp"
    }
  }
}

README

A2A Passport — one GTIN, one call, everything GSC knows, signed

The hubs are the records; A2A-Passport.ai issues the passport.

The hubs are the records; A2A-Passport.ai issues the passport. A passport is a signed document for a product or a retail banner: where its record lives, where it is cleared, who lists it, where the money door is. Issued live from the GSC hubs, stamped every week. A2A Passport is operated by GreenCore Solutions Corp.: one signed document per product (a Global Trade Item Number, GTIN) or retail banner, composed live from the GSC hubs — A2A Grocery, A2A Cosmetics, A2A Peptides, A2A Retailmedia and the compliance records — and signed (EdDSA). Three tools: get_passport, list_passports, verify_passport. Every field is a hub's answer, word for word, with the door and the time it was read, or it is absent with a note: the passport never infers. A product no hub holds gets no passport. Reads are open; a verified, countersigned copy settles by x402. Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.

A2A Passport is built and run by GreenCore Solutions Corp. (github.com/greencore-solutions). This is the public connect kit, MIT.

The door

streamable-HTTP, stateless, server name a2a-passport, door version 1.0.1, 3 tools (read from the wire)

  • Endpoint: https://mcp.a2a-passport.ai/mcp — any client that speaks streamable-HTTP: { "url": "https://mcp.a2a-passport.ai/mcp", "transport": "streamable-http" }
  • Agent Card (signed): https://a2a-passport.ai/.well-known/agent-card.json
  • Key: https://a2a-passport.ai/.well-known/jwks.json (EdDSA, key id a2apass-2026-10)
  • No registration and no token: every read is open.

The tools

  • get_passport — The signed passport of a product (a Global Trade Item Number, GTIN) or a retail banner (market/banner, e.g. FR/Carrefour): which hub holds its record, where it is cleared, its compliance records, who lists it, where the payment door is. Read live from the GSC hubs on every call; the first call issues version 1. subject = a GTIN (8 to 14 digits) or market/banner; kind = gtin or banner (optional).
  • list_passports — The passports on the register: ids, kinds, markets, versions and issue times, newest first. No bodies. Filter by kind (gtin or banner), market, or issued since a time; paginated.
  • verify_passport — Check a passport: is the signature valid, is the chain of versions intact, how old is the stamp, was any section not read. Verifies from the published key at /.well-known/jwks.json.

The document

One envelope for both kinds (a product by its GTIN, or a retail banner as market/banner): passport_id, kind, subject, issued_at, version, previous_version_hash, issuer, signature, delta, and the body. Every field in the body is a hub's answer, word for word, with the door, the tool and the time it was read — or it is absent with a note. The passport never infers.

  • Current version: https://a2a-passport.ai/passport/{id}.json
  • One version: https://a2a-passport.ai/passport/{id}/v{n}.json
  • Passport #1: https://a2a-passport.ai/passport/gtin-03284230006408.json
  • The register (live counts): https://a2a-passport.ai/passports/register.json

A product that no hub holds on its record gets no passport.

Verify a passport yourself

The signature is a detached JSON Web Signature (EdDSA) over the passport without its signature field, keys sorted, compact JSON, UTF-8. examples/verify_passport.py does it with the published key and nothing else.

The countersigned copy

Reading a passport is free. A verified, countersigned copy settles at https://a2a-passport.ai/api (x402, two accept entries). A passport that is not on the register answers HTTP 403 and is not charged.

Examples

  • examples/generic_mcp_client.py — a stock client: lists the tools, reads passport #1, verifies it on the door.
  • examples/verify_passport.py — fetches a passport and the key over plain HTTP and verifies the signature offline.

Artificial intelligence makes mistakes. A2A Passport is an agentic information source, not a recommendation. No ads, ever. No rank for sale. Trade only.

來源:README.md,提交 53f7b1d

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 5, 2026