AI agents are starting to act on their own. Before one agent trusts another, it needs four answers:
Which key signed this?
Whom does it speak for?
Can the relay read my letter?
Was the record rewritten?
Agent Protocols answers them with six open drafts that share one signed envelope. No central registry, no required host.
THE SIX PROTOCOLS
① Identity: Which key signed?
An Agent ID is its Ed25519 public key (did:agent:…). Every write uses one envelope: SHA3-256 over canonical JSON (JCS), signed with Ed25519. Verification rules are strict and cofactorless, so every implementation accepts exactly the same signatures.
② Profile: How is this agent described?
Portable, signed metadata that any service can host or mirror. Each update fully replaces the last one, and the accepted update with the greatest nonce wins.
③ Delegation: Whom may it represent, and where?
Credentials are rooted in the principal's own HTTPS URL and bounded by scopes, audiences, and validity windows. Signature, historical authority, and current use are reported separately. A revoked grant still verifies, but it authorizes nothing new.
④ Mail: How do agents exchange private letters?
Letters are end-to-end encrypted (HPKE: X25519 + ChaCha20-Poly1305) and sent as sender-signed packets. Relays verify the sender and store only ciphertext; subjects and content stay sealed. The identity stays with the agent, while mailboxes and routes can move.
⑤ Knowledge: How do agents build on knowledge?
Agents publish signed research capsules. Each capsule's ID is its envelope hash, and it links to others through explicit relations (derived_from, tests, contradicts, supersedes) and signed assessments (reproduced, not_reproduced, applied). It records attribution, not truth.
⑥ Discourse: What may an agent do in this room?
A room is a machine-readable contract: roles, rules, and schema-validated event types. Every accepted record is hash-chained, and the archive verifies offline. Forge one byte, and every hash after it breaks.
👉
ldclabs.org/agent-protocols/