Manifest Specification
The .agt manifest is a signed JSON document describing an AI agent's identity, capabilities, endpoints, keys, and payments. For names on the AGT Registry it is the v3 manifest: the owner signs it with their wallet, and the registry holds the on-chain pointer to it. Any client can verify authorship without trusting any intermediary registry, gateway, or directory.
For the canonical specification document, see /spec or spec/agt-manifest-v3-draft.md. This page is the developer-facing summary.
Where the pointer lives
On the AGT Registry, the manifest pointer is stored on-chain — the registry records the manifest URI for the name, and the DNS TXT agt-manifest= record is a downstream projection of it. Resolvers read the pointer from the registry, so there is no DNS round-trip in the trust path. The URI can be ipfs:// (content-addressed), https://, or an inline data: URI.
Manifest Document
{
"agt": "3.0",
"name": "exampleagent.agt",
"owner": "0x912D39E13b0bDAe2C5Cf5D0E2f9F4B38aE9c7f6a",
"updated": "2026-09-07T05:00:00Z",
"description": "Research and source citation agent.",
"icon": "https://exampleagent.example/icon.png",
"website": "https://exampleagent.example",
"keys": [
{ "id": "sig-1", "purpose": "agent-auth", "type": "secp256k1", "publicKey": "0x04...", "revoked": false }
],
"endpoints": [
{ "protocol": "mcp", "url": "https://exampleagent.example/mcp", "version": "2025-11-05" },
{ "protocol": "a2a", "url": "https://exampleagent.example/.well-known/agent.json" },
{ "protocol": "http", "url": "https://exampleagent.example/api/v1" }
],
"capabilities": [
{ "id": "research", "description": "Searches sources and synthesizes a cited summary." },
{ "id": "summarization" }
],
"pricing": { "model": "freemium", "free_tier": "10 queries/day",
"paid": { "currency": "USDC", "amount": "0.01", "unit": "per_request", "chain": "polygon" } },
"payments": [ { "rail": "x402", "chain": "polygon", "address": "0x912D...7f6a", "token": "USDC" } ],
"delegation": { "principal": "0xABC...", "scope": ["read", "quote"], "expires": "2027-01-01T00:00:00Z" },
"registrations": [ { "standard": "erc-8004", "chainId": 137, "registry": "0x8004...", "agentId": "42" } ],
"signature": "0x7f3e8d4c..."
}
Fields
| Field | Required | Description |
|---|
agt | yes | Spec version. "3.0". |
name | yes | The .agt name this manifest describes. Lowercase. |
owner | yes | Owner wallet address. Must equal the registry owner of the name at verification time. |
updated | yes | ISO 8601 timestamp. |
description, icon, website | no | Human-facing identity fields. |
keys | no | Agent public keys. Each has a purpose (agent-auth, encryption, custom), a type, a publicKey, and a revoked flag. Rotate by publishing a new manifest. |
endpoints | no | One entry per protocol: protocol, url, and an optional version. |
capabilities | no | Capability ids (see the vocabulary below), each with an optional description and JSON Schema input/output. |
pricing | no | How the agent charges: model (free/freemium/paid/contact), optional free_tier and paid terms. |
payments | no | Payment rails the agent accepts: rail, chain, address, token. |
delegation | no | "This agent acts for this principal": principal address, scope, and optional expires. |
registrations | no | Interop identities in other standards (erc-8004, did, ens). |
signature | yes | EIP-191 signature over the canonicalized manifest (see below). |
Signing & Verification
Manifests are canonicalized with keys sorted lexicographically at every level and no insignificant whitespace (JCS-lite; RFC 8785 for full conformance). Signing is EIP-191 personal_sign by the wallet that owns the name — the private key never leaves the wallet.
Verification is three-way:
- Signature recovery: the signer recovered from
signature MUST equal the manifest's owner. - On-chain owner check: the manifest's
owner MUST equal the current owner of the name in the AGT Registry. - CID check (when the URI is
ipfs://): the fetched bytes MUST hash to the CID in the pointer. (Defends against gateway tampering.)
On any failure, resolvers surface verified: false with reasons rather than silently dropping the document — but clients MUST NOT trust an unverified manifest.
Resolution Algorithm
- Derive the token ID from the label.
- Read
ownerOf, active/expiry, and the manifest pointer from the AGT Registry. - Fetch the manifest from its URI (
ipfs:// via configurable gateways, https://, or data:), parse, and run the three verification checks. - If the registry has no pointer, fall back to DNS TXT for legacy names (
agt-manifest= for a v2 JSON manifest, agt-version=1 for a v1 inline manifest). - Return
{ name, owner, active, manifest, verified, reasons }.
Protocol Vocabulary
| ID | Description |
|---|
mcp | Model Context Protocol (Anthropic). |
a2a | Agent-to-Agent Protocol (Google). |
http | REST or RPC over HTTP/HTTPS. |
ws | WebSocket. |
grpc | gRPC. |
Custom protocol IDs are permitted. Lowercase, hyphenated.
Payment Rails
| Rail | Description |
|---|
x402 | HTTP 402 pay-per-request settlement. |
evm | Direct EVM token transfer. |
lightning | Bitcoin Lightning. |
Custom rails are permitted.
Capability Vocabulary
70 reference capabilities across 8 categories. Capability inputs and outputs use JSON Schema Draft 2020-12. Custom IDs permitted.
Language
| ID | Description |
|---|
research | Gathers, synthesizes, and cites information from multiple sources. |
summarization | Condenses long-form content into concise summaries. |
translation | Translates text between natural languages. |
content-writing | Generates articles, blog posts, documentation, or other long-form written content. |
copywriting | Produces marketing copy, ad text, taglines, and promotional content. |
editing | Proofreads, corrects grammar, and improves style and clarity. |
paraphrasing | Restates text in different words while preserving meaning. |
extraction | Pulls structured data from unstructured text (entities, dates, amounts). |
classification | Categorizes text by topic, sentiment, intent, or other criteria. |
question-answering | Answers questions using provided context or general knowledge. |
fact-checking | Verifies claims against authoritative sources. |
reasoning | Performs multi-step logical reasoning and problem solving. |
brainstorming | Generates creative ideas, alternatives, and divergent options. |
Code
| ID | Description |
|---|
code-generation | Writes source code from natural language specifications. |
code-review | Analyzes code for bugs, style issues, and improvement opportunities. |
code-explanation | Explains what code does in plain language. |
debugging | Identifies and fixes software bugs. |
testing | Writes or executes tests and reports results. |
refactoring | Restructures code for clarity or performance without changing behavior. |
code-documentation | Generates docstrings, READMEs, and technical reference for code. |
database-query | Generates, optimizes, or explains SQL and database queries. |
code-completion | Provides inline code suggestions and autocompletion. |
Data
| ID | Description |
|---|
data-analysis | Performs statistical analysis and extracts insights from structured data. |
data-visualization | Creates charts, graphs, dashboards, and visual data representations. |
data-cleaning | Normalizes, deduplicates, and corrects data quality issues. |
data-transformation | Converts data between formats, schemas, or structures (ETL). |
math | Solves mathematical problems and performs symbolic or numeric computation. |
forecasting | Builds predictive models and generates time-series forecasts. |
anomaly-detection | Identifies outliers and unexpected patterns in data. |
reporting | Generates structured reports and executive summaries from data. |
embedding | Generates vector embeddings for text, images, or other inputs. |
clustering | Groups similar items together based on features or content. |
ranking | Scores and prioritizes items by relevance, quality, or other criteria. |
Search & Retrieval
| ID | Description |
|---|
search | Looks up records, names or resources by query in a specific corpus or registry. |
web-search | Searches the public internet for information. |
semantic-search | Retrieves results based on meaning rather than keyword matching. |
document-search | Searches across document collections, PDFs, or knowledge bases. |
knowledge-retrieval | Queries structured knowledge bases or performs retrieval-augmented generation. |
citation | Finds, formats, and verifies references and source attributions. |
Media
| ID | Description |
|---|
image-generation | Creates images from text prompts or other inputs. |
image-editing | Modifies, enhances, or transforms existing images. |
image-analysis | Extracts information, labels, or descriptions from images. |
video-generation | Creates video content from text, images, or other inputs. |
video-analysis | Extracts information, scenes, or transcripts from video. |
audio-transcription | Converts spoken audio into text. |
audio-generation | Produces speech, music, or sound effects from text or other inputs. |
ocr | Extracts text from images, scans, or documents via optical character recognition. |
design | Creates UI mockups, graphics, layouts, or other visual design work. |
3d-modeling | Generates or manipulates three-dimensional models and scenes. |
Communication
| ID | Description |
|---|
chat | Engages in real-time conversational interaction with users or other agents. |
email-drafting | Composes, formats, and suggests email messages. |
meeting-notes | Transcribes, summarizes, and extracts action items from meetings. |
presentation | Creates slides, pitch decks, and structured visual presentations. |
tutoring | Provides educational instruction, explanations, and guided learning. |
customer-support | Handles support queries, troubleshooting, and issue resolution. |
negotiation | Facilitates structured dialogue toward agreement or compromise. |
Automation
| ID | Description |
|---|
web-scraping | Extracts structured data from web pages. |
api-integration | Connects to and orchestrates third-party APIs. |
workflow-automation | Automates multi-step business or technical workflows. |
scheduling | Manages time-based tasks, reminders, and calendar operations. |
monitoring | Observes systems, services, or data streams and reports on status changes. |
deployment | Manages CI/CD pipelines, releases, and software deployments. |
file-management | Organizes, converts, moves, and manages files and directories. |
notification | Sends alerts, messages, and notifications across channels. |
data-entry | Fills forms, inputs data, and automates manual entry tasks. |
Security
| ID | Description |
|---|
vulnerability-scanning | Assesses systems and code for security weaknesses. |
compliance-checking | Verifies adherence to policies, regulations, and standards. |
threat-detection | Identifies potential security threats and suspicious activity. |
access-control | Manages permissions, roles, and authentication policies. |
encryption | Handles data encryption, decryption, and key management. |
Security Considerations
- Public gateways are untrusted — resolvers must verify the CID matches the fetched content.
- On-chain ownership is the ground truth. A valid signature proves authorship at signing time; always resolve the current pointer and owner from the registry. Manifests signed by a previous owner become invalid after transfer.
- Manifests are public. Never include secrets, API keys, or private data.
- Key rotation and revocation are done by setting
keys[].revoked and publishing a new signed manifest. - Treat all manifest text as untrusted input in agent prompts (prompt-injection surface).
- Endpoints SHOULD use HTTPS. Clients SHOULD warn before connecting to plain HTTP.
Legacy manifests
Two earlier formats remain readable but are not written for new names: v1 (each field as a separate inline DNS TXT record, no signature) and v2 (a signed JSON document on IPFS with "agt": "2.0"). Resolvers fall back to DNS TXT to read these for names that predate the registry; new registrations and migrated names write v3.
References
- RFC 8785 — JSON Canonicalization Scheme (JCS)
- EIP-191 — Signed Data Standard
- EIP-55 — Mixed-case checksum address encoding
- ENSIP-9 — Multichain address resolution
- ERC-8004 — Agent identity registration
- JSON Schema Draft 2020-12
- IPFS CIDv1 — multibase, multihash, multicodec