AbsoluteJS

@absolutejs/agent-exchange-provider-conformance

@absolutejs/agent-exchange-provider-conformancev0.3.1betaAI

OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.

#Installation

BASH
bun add @absolutejs/agent-exchange-provider-conformance

#Capabilities

Overview

Shared capability checks, cryptographic DPoP verification, and black-box A2A security tests for Agent Exchange providers. Provider adapters publish facts; this package decides whether those facts meet the phishing-resistant OAuth profile. A2A servers are exercised over their public protocol boundary without depending on their implementation.

Unknown or unavailable features are failures, not optimistic defaults.

A2A prepared-profile conformance

evaluateAgentExchangeA2aConformance() performs eight active checks:

Agent Card discovery and same-origin A2A 1.0 JSON-RPC routing;

extension parameters, skill media types, and declared authentication;

Show 10 more

authentication before parsing malformed A2A and preparation requests;

distinct preparation and A2A credentials;

A2A-Extensions negotiation;

protected preparation followed by exact-reference execution;

raw, hexadecimal, base64, and base64url leakage detection in tasks and

receipts; and

safe replay rejection or convergence on the original task.

The suite executes the supplied request. It requires the literal acknowledgeExecution: "sandbox-only" and must never be aimed at production or an endpoint that can submit a real credential:

createRequest() receives a purpose identifier and must return a fresh exchange each time. The sandbox must use separate audience-bound credentials for the preparation and A2A URLs. Put any simulated protected value that is not already part of the request—such as a sandbox six-digit code—in additionalSensitiveMarkers.

The report demonstrates observable protocol behavior for that sandbox run. It is not a cryptographic audit, production authorization, penetration test, or claim that an email/SMS bearer code is phishing-resistant.

OAuth provider conformance

evaluateOAuthProviderConformance() evaluates declared authorization-code, issuer-identification, PAR, S256 PKCE, RAR, resource-indicator, and sender-constraint capabilities. verifyDpopProof() independently validates the ES256 proof, public key, method, normalized target URI, timestamp, nonce, and access-token hash. JWT segments must use canonical unpadded base64url encoding; alternate strings that decode to the same bytes are rejected so proof identity cannot be aliased through unused padding bits.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-provider-conformance through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-provider-conformance version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-provider-conformance example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#A2A prepared-profile conformance

Partial snippet

evaluateAgentExchangeA2aConformance() performs eight active checks:

TS
import {
  assertAgentExchangeA2aConformance,
  type AgentExchangeA2aConformanceTarget,
} from "@absolutejs/agent-exchange-provider-conformance";

const target: AgentExchangeA2aConformanceTarget = {
  acknowledgeExecution: "sandbox-only",
  additionalSensitiveMarkers: [sandboxVerificationCode],
  a2aHeaders: ({ url }) => a2aTokenFor(url),
  createRequest: (purpose) => sandboxRequest(purpose),
  origin: "https://sandbox-recipient.example",
  preparationHeaders: ({ url }) => preparationTokenFor(url),
};

const report = await assertAgentExchangeA2aConformance(target);

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-provider-conformancePackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange --external '@absolutejs/agent-exchange/*' && tsc --project tsconfig.build.json && prettier --write --ignore-path /dev/null 'dist/*.d.ts'
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

18 symbols
OAuthFeatureStatustypePermalinkSource
TS
type OAuthFeatureStatus = "supported" | "unknown" | "unsupported";
Exported from @absolutejs/agent-exchange-provider-conformance