Skip to main content
The A2A AgentCard export is a public-discovery surface that projects a Mnemom-composed canonical alignment card into the A2A AgentCard v1.x envelope. The endpoint is unauthenticated: any consumer can fetch it; per-agent opt-in keeps the surface explicit. The export is one-way. Mnemom doesn’t accept inbound A2A registration in v1; that’s deferred to a future phase. The export pattern is the standard “publish for discovery” half of A2A.

Endpoint

What the projection includes

The extensions[].uri values above are namespace identifiers, not fetchable endpoints — aap.mnemom.ai does not resolve to a live host. A2A’s extension mechanism uses uri the way XML uses a namespace URI: a stable string that names the extension, not a URL you GET. To actually fetch the JWKS or the attestation body, use the jwks_uri and token fields inside the extension’s body, or the documented endpoints linked above.

What the projection deliberately excludes

The public-discovery surface filters operator-internal fields:
  • card_id (smolt-internal)
  • _composition.source_card_id / _composition.source_policy_id
  • field_provenance (caller-aware redaction is server-side; A2A consumers don’t get a redacted view, they get no view)
  • Internal connector grants beyond the bare tool name surface
If you’d benefit from the full composed view including provenance, use GET /v1/agents/{id}/state under an authenticated principal.

Opt-in

Agents default to opted out (agents.a2a_export_enabled defaults to false) so no agent’s alignment posture is exposed on the public surface without an explicit decision. There is currently no self-serve API or dashboard toggle for this flag — if you want an agent’s AgentCard published for A2A discovery, contact Mnemom support to have it enabled. Once enabled, the AgentCard is live immediately (the per-request flag check happens on every fetch), and disabling it again returns the endpoint to 404 immediately.

Verifying the embedded attestation

Any A2A consumer can extract the extensions[aap/attestation].body.token and verify it offline against the published JWKS. The mnemom verify-card CLI does this for you in one command:
For programmatic verification, the wire format is documented; any JOSE/JWT library that supports EdDSA can verify.

See also