> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# A2A AgentCard Export

> One-way projection of the canonical alignment card into the A2A AgentCard envelope, with the AAP attestation token attached as an A2A extension.

The **A2A AgentCard export** is a public-discovery surface that projects a Mnemom-composed canonical alignment card into the [A2A AgentCard](https://github.com/google/A2A) v1.x envelope. The endpoint is **unauthenticated**: any consumer can fetch it; per-agent opt-in keeps the surface explicit.

The export is **one-way**. Mnemom doesn't accept inbound A2A registration in v1; that's deferred to a future phase. The export pattern is the standard "publish for discovery" half of A2A.

## Endpoint

```
GET /v1/agents/{agent_id}/a2a-agent-card
```

| Property | Value |
| - | - |
| Auth | None — public surface |
| Per-agent gate | `agents.a2a_export_enabled` — when false, the endpoint returns **404 (not 403)** to avoid leaking which agents exist on the platform |
| Caching | `Cache-Control: public, max-age=60, stale-while-revalidate=300` |
| ETag | `"sha256:<canonical content_hash>"` — clients can issue `If-None-Match` for cheap revalidation |
| CORS | `*` — the endpoint is intentionally cross-origin |

## What the projection includes

```json theme={null}
{
  "schemaVersion": "1.0",
  "name": "support-agent",
  "description": "Mnemom-composed alignment card declaring deliberation_before_action, policy_attentiveness, evidence_grounded.",
  "url": "https://api.mnemom.ai/v1/agents/smolt-e2ca60ef",
  "version": "1.17.0",
  "capabilities": { "streaming": false, "pushNotifications": false },
  "skills": [
    { "id": "campfire_create_chart_account", "name": "campfire_create_chart_account" }
  ],
  "extensions": [
    {
      "uri": "https://aap.mnemom.ai/v1/attestation",
      "required": false,
      "body": {
        "token": "<jws-compact>",
        "jwks_uri": "https://api.mnemom.ai/v1/.well-known/jwks.json"
      }
    },
    {
      "uri": "https://aap.mnemom.ai/v1/alignment",
      "required": false,
      "body": { "autonomy_mode": "observe", "values": { "declared": [...] }, "principal": {...} }
    }
  ],
  "metadata": {
    "content_hash": "<sha256-hex>",
    "composed_at": "2026-05-22T12:00:00Z"
  }
}
```

<Note>
  The `extensions[].uri` values above are **namespace identifiers**, not fetchable endpoints — `aap.mnemom.ai` does not resolve to a live host. A2A's extension mechanism uses `uri` the way XML uses a namespace URI: a stable string that names the extension, not a URL you `GET`. To actually fetch the JWKS or the attestation body, use the `jwks_uri` and `token` fields inside the extension's `body`, or the documented endpoints linked above.
</Note>

| Field | Source |
| - | - |
| `name` | `principal.identifier` from the alignment card; falls back to `agent_id` |
| `description` | Care-framed summary of the first six declared values |
| `version` | `1.<canonical version>.0` (semver shape) |
| `skills` | First 50 entries of `autonomy.bounded_actions` |
| `extensions[aap/attestation]` | Present when `AAP_ATTESTATION_SIGNING_ENABLED=true`; soft-omits on signing error |
| `extensions[aap/alignment]` | Public-safe subset of the canonical card |

## What the projection deliberately excludes

The public-discovery surface filters operator-internal fields:

* `card_id` (smolt-internal)
* `_composition.source_card_id` / `_composition.source_policy_id`
* `field_provenance` (caller-aware redaction is server-side; A2A consumers don't get a redacted view, they get no view)
* Internal connector grants beyond the bare tool name surface

If you'd benefit from the full composed view including provenance, use `GET /v1/agents/{id}/state` under an authenticated principal.

## Opt-in

Agents default to **opted out** (`agents.a2a_export_enabled` defaults to `false`) so no agent's alignment posture is exposed on the public surface without an explicit decision. There is currently no self-serve API or dashboard toggle for this flag — if you want an agent's AgentCard published for A2A discovery, contact Mnemom support to have it enabled. Once enabled, the AgentCard is live immediately (the per-request flag check happens on every fetch), and disabling it again returns the endpoint to 404 immediately.

## Verifying the embedded attestation

Any A2A consumer can extract the `extensions[aap/attestation].body.token` and verify it offline against the published JWKS. The [`mnemom verify-card`](/guides/verify-card) CLI does this for you in one command:

```bash theme={null}
mnemom verify-card smolt-e2ca60ef
```

For programmatic verification, the wire format is [documented](/specifications/attestation-token); any JOSE/JWT library that supports EdDSA can verify.

## See also

* [AAP attestation tokens](/concepts/aap-attestation) — the JWS extension
* [Transparency log](/concepts/transparency-log) — durable historic verification
* [`mnemom verify-card`](/guides/verify-card) — offline verification CLI
* [Card lifecycle](/concepts/card-lifecycle) — where the export fits in the lifecycle


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.