Urgent.News

What's breaking now, across thousands of outlets.

Tech

Agents are starting to call each other. Nobody gave them receipts.

Agents are starting to call each other. Nobody gave them receipts. Every agent framework is racing toward the same future: agents that call other agents. MCP servers, agent marketplaces, "agent-to-agent" protocols — the demos all show Agent A politely asking Agent B to do something and it just... working. Here's the part nobody demos: Agent B has no idea who called it, what they were allowed to…

Agents are beginning to communicate with one another. The issue lies in the lack of proper documentation.

Each framework for agents is working towards a common goal: agents that can communicate with other agents. Various demonstrations showcase Agent A requesting a task from Agent B, which successfully executes. However, there's a crucial piece missing from these demonstrations: Agent B has no knowledge of who initiated the request, what permissions were granted, or how to prove the results.

Presently, agent-to-agent calls are unsigned HTTP strings, which amounts to a handshake deal rather than a robust protocol. The missing element comprises three crucial components, and the author is actively developing it.

The three challenges are:

1. Identity: When Agent A initiates a call to Agent B, how can we verify Agent A's identity? Instead of relying on usernames, a verifiable key is necessary. Without caller identification, any agent could potentially impersonate another, leading to issues with rate limits, billing, and trust.

2. Authorization: In the request "summarize this document," did Agent A grant permission to Agent B to read the document or also to email the summary to Agent A's entire contact list? The call must have a clearly defined scope, not just assumptions.

3. Audit: After the call, what actually transpired? If Agent B claims to have completed the task, but Agent A disputes this, there's no neutral party to resolve the discrepancy. Both parties require a signed receipt of the actual action performed.

A solution lies in the creation of an agent manifest. Each agent would publish a machine-readable, signed manifest detailing what it can perform, the associated costs (credits), actions requiring explicit approval from the owner, and the public key used to sign its receipts. Without a manifest, no calls can be made, akin to robots.txt but with enforceable rules.

The call process would involve the caller's identity, the declared intent, the scope, and a nonce, all signed by the caller's key. The receiver would validate the signature before proceeding with any work, compare the scope against its manifest, and reject any requests falling outside its approved scope.

The final piece is the signed receipt. Upon completion, the receiver writes a record of the action taken - including the action performed, a hash of the inputs, the outcome, and the credits utilized - into a ledger signed by its key. Both parties retain this receipt. In the event of any issues, a verifiable record exists, detailing every action in chronological order, signed by the respective parties.

Currently, the author is working on these components at an agent platform called Double-Oh. While per-agent action ledgers are live, the manifest format and signed inter-agent call envelopes are still in development. The ledger serves as the foundation, while the calling protocol builds upon it. It's essential to address accountability first, as having a call-to-agent functionality without proper verification will never succeed.

These developments are vital for the wider agent economy, which is projected to reach $3–5T by 2030. Agents transacting with one another - for buying, booking, and negotiating - will require these security measures. Without them, the agent economy would be akin to the web without TLS - insecure, unreliable, and untenable. If you're involved in building agent tooling, I'm interested in learning how you're addressing caller identity and action audit.

It seems most of us are creating similar half-solutions, and a shared manifest format could save everyone considerable time.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 30 September →