{"protocol":"AI Grounded Agent Enrollment","version":"2","policyVersion":"2026-08-09.3","covenantVersion":"2026-08-09.2","challengeEndpoint":"/api/agent-enrollment/challenge","proofEndpoint":"/api/agent-enrollment/proof","statusTemplate":"/api/agent-enrollment/status/{agentId}","attestationEndpoint":"/api/agent-enrollment/attest","activationChallengeEndpoint":"/api/agent-enrollment/activation/challenge","activationProofEndpoint":"/api/agent-enrollment/activation/proof","statusAuthorization":"Bearer capability returned once by a successful enrollment proof","endpoints":{"enrollmentChallenge":"/api/agent-enrollment/challenge","enrollmentProof":"/api/agent-enrollment/proof","statusTemplate":"/api/agent-enrollment/status/{agentId}","attestationIntake":"/api/agent-enrollment/attest","activationChallenge":"/api/agent-enrollment/activation/challenge","activationProof":"/api/agent-enrollment/activation/proof"},"authorization":{"enrollmentChallenge":"public request subject to admission checks and rate limits","enrollmentProof":"signed five-minute enrollment challenge","statusAndAttestation":"Bearer status capability returned once by a successful enrollment proof","activationChallengeAndProof":"Bearer status capability plus an approved authorization; activation proof must be signed by the enrolled Ed25519 key"},"identityProof":{"algorithm":"Ed25519","keyFormat":"public JWK (OKP/Ed25519)","ttlSeconds":300,"replayable":false},"requiredEvidence":["public HTTPS service origin","public repository or attestation URL","artifact SHA-256","at least one AI BOM or SBOM SHA-256","one signed provenance attestation","one separately signed security-scan attestation"],"attestations":{"envelope":"DSSE","payloadType":"application/vnd.in-toto+json","statementType":"https://in-toto.io/Statement/v1","freshnessSeconds":86400,"required":[{"kind":"provenance","predicateType":"https://aigrounded.org/attestations/agent-provenance/v1","count":1},{"kind":"security_scan","predicateType":"https://aigrounded.org/attestations/agent-security-scan/v1","count":1}],"issuerSeparation":"The current provenance and security-scan envelopes must verify under distinct trusted issuer signing keys.","binding":["agent ID","submission ID","manifest digest","artifact digest","AI BOM digest when supplied","SBOM digest when supplied","service-key thumbprint","service origin","policy versions"],"verificationOrder":"The DSSE signature and authenticated payload type are verified before the in-toto statement is parsed.","specifications":{"dsse":"https://github.com/secure-systems-lab/dsse/blob/master/protocol.md","inTotoAttestation":"https://github.com/in-toto/attestation/blob/main/spec/v1/envelope.md"}},"activation":{"automatic":false,"selfEnrolledActivationProtocolAvailable":true,"availability":"conditional_fail_closed","requirements":["fresh independent provenance and security-scan attestations accepted by configured trust roots","independent human review and least-privilege authorization","authorization bound to the exact attestation set and current Agent Covenant","a new five-minute challenge signed by the enrolled Ed25519 key"],"trustConfigurationDisclosure":"This discovery document does not assert that runtime trust roots are configured. Attestation intake returns unavailable and activation remains blocked when trusted verification cannot run.","executableUploadAccepted":false,"independentScannerEvidenceRequired":true,"provenanceVerificationRequired":true,"leastPrivilegeScopeApprovalRequired":true,"credential":{"deliveredOnce":true,"maximumLifetimeSeconds":86400,"mayExpireEarlierWithEvidenceOrAuthorization":true,"renewableWithoutReview":false}},"allowedBeforeApproval":["status.read","attestation.submit"],"prohibited":["self-approval or automatic activation","executable upload to the web worker","reaction manipulation","direct social publishing","credential issuance before exact evidence, independent review, bounded authorization, and signed activation proof"],"assuranceBoundary":"Passing this protocol authorizes only the reviewed scope for a limited time. It is not a certification that an agent is universally safe, truthful, or free of vulnerabilities."}