.agt Manifest Specification

Version: 3.0 · Status: In use on the AGT Registry (Polygon mainnet) · Updated: 2026-09-12 · View as Markdown

Abstract

The .agt manifest is a signed JSON document describing an AI agent's identity, capabilities, endpoints, keys, and payments. For names on the AGT Registry it is the v3 manifest: the wallet that owns the name signs it, and the registry holds the on-chain pointer to it. Any client can verify authorship without trusting any intermediary registry, gateway, or directory.

v3 changes where authority comes from. The trust root is the AGT Registry — verification checks that the signer, the manifest's declared owner, and the registry's current owner all agree. The pointer to the manifest lives on-chain; the DNS TXT record is a projection of it. Two earlier formats — v1 (inline DNS TXT) and v2 (signed JSON on IPFS, "agt": "2.0") — remain readable for names that predate the registry (§11).

1. Where the manifest lives

On the AGT Registry the manifest pointer is stored on-chain against the name. The pointer URI is one of:

The DNS TXT agt-manifest=<uri> record is a downstream projection of the on-chain pointer, for DNS-based readers. Resolvers read the pointer from the registry first.

2. Manifest Document

{
  "agt": "3.0",
  "name": "exampleagent.agt",
  "owner": "0x912D39E13b0bDAe2C5Cf5D0E2f9F4B38aE9c7f6a",
  "updated": "2026-09-07T05:00:00Z",
  "description": "Research and source citation agent.",
  "icon": "https://exampleagent.example/icon.png",
  "website": "https://exampleagent.example",
  "keys": [
    { "id": "sig-1", "purpose": "agent-auth", "type": "secp256k1", "publicKey": "0x04...", "revoked": false }
  ],
  "endpoints": [
    { "protocol": "mcp",  "url": "https://exampleagent.example/mcp", "version": "2025-11-05" },
    { "protocol": "a2a",  "url": "https://exampleagent.example/.well-known/agent.json" },
    { "protocol": "http", "url": "https://exampleagent.example/api/v1" }
  ],
  "capabilities": [
    {
      "id": "research",
      "description": "Searches sources and synthesizes a cited summary.",
      "input":  { "type": "object", "properties": { "query": { "type": "string" } }, "required": ["query"] },
      "output": { "type": "object", "properties": { "summary": { "type": "string" }, "sources": { "type": "array" } } }
    },
    { "id": "summarization" }
  ],
  "pricing": {
    "model": "freemium",
    "free_tier": "10 queries/day",
    "paid": { "currency": "USDC", "amount": "0.01", "unit": "per_request", "chain": "polygon" }
  },
  "payments": [ { "rail": "x402", "chain": "polygon", "address": "0x912D...7f6a", "token": "USDC" } ],
  "delegation": { "principal": "0xABC...", "scope": ["read", "quote"], "expires": "2027-01-01T00:00:00Z" },
  "registrations": [ { "standard": "erc-8004", "chainId": 137, "registry": "0x8004...", "agentId": "42" } ],
  "signature": "0x7f3e8d4c..."
}

3. Fields

FieldRequiredDescription
agtyesSpec version. MUST be "3.0".
nameyesThe .agt name. Lowercase.
owneryesOwner address. MUST equal the registry owner of the name at verification time.
updatedyesISO 8601 timestamp. Resolvers prefer the newest pointer from the registry.
description, icon, websitenoHuman-facing identity fields.
keysnoAgent public keys; each has id, purpose, type, publicKey, revoked.
endpointsnoOne per protocol: protocol, url, optional version.
capabilitiesnoCapability ids with optional description and JSON Schema input/output.
pricingnomodel (free/freemium/paid/contact), optional free_tier, paid.
paymentsnoAccepted rails: rail, chain, address, token.
delegationnoprincipal, scope, optional expires.
registrationsnoInterop identities (erc-8004, did, ens).
signatureyesEIP-191 signature over the canonical serialization (§4).

4. Canonical Serialization & Signing

  1. Build the manifest object without the signature field.
  2. Serialize with keys sorted lexicographically at every level, no insignificant whitespace, UTF-8 (JCS-lite; RFC 8785 for full conformance).
  3. Sign per EIP-191 (personal_sign) with the wallet that owns the name. The key never leaves the wallet.
  4. Place the resulting hex signature (65 bytes, r‖s‖v, 0xprefixed) in the signature field.

5. Verification

  1. Remove signature; canonicalize the remainder.
  2. Recover the signer from the signature and the canonical bytes.
  3. The signer MUST equal the manifest's owner.
  4. The owner MUST equal the current owner of the name in the AGT Registry.
  5. When the pointer is ipfs://, the fetched bytes MUST hash to the CID.

On any failure a resolver surfaces verified: false with reasons; clients MUST NOT trust an unverified manifest.

6. Resolution Algorithm

function resolve(name):
  tokenId = tokenIdOf(name)
  owner, active, pointer = AGTRegistry.read(tokenId)   // ownerOf, status, manifest pointer

  if pointer:
    bytes = fetch(pointer)                             // ipfs:// | https:// | data:
    if pointer is ipfs and cidOf(bytes) != cid: REJECT
    m = parse(bytes)
    verified = recover(m.signature) == m.owner == owner
    return { name, owner, active, manifest: m, verified }

  // legacy fallback for names that predate the registry
  txt = dnsTxt(name)
  if txt.has("agt-manifest="): return readV2Json(txt)
  if txt.has("agt-version=1"): return readV1Inline(txt)   // unverified
  return { name, owner, active, manifest: null }

7. Protocol Vocabulary

IDDescription
mcpModel Context Protocol (Anthropic).
a2aAgent-to-Agent Protocol (Google).
httpREST or RPC over HTTP/HTTPS.
wsWebSocket.
grpcgRPC.

Custom protocol IDs are permitted. Lowercase, hyphenated.

8. Payment Rails

RailDescription
x402HTTP 402 pay-per-request settlement.
evmDirect EVM token transfer.
lightningBitcoin Lightning.

Custom rails are permitted.

9. Capability Vocabulary (Reference)

70 reference capabilities across 8 categories. Custom IDs permitted — this list is non-exhaustive.

Language

IDDescription
researchGathers, synthesizes, and cites information from multiple sources.
summarizationCondenses long-form content into concise summaries.
translationTranslates text between natural languages.
content-writingGenerates articles, blog posts, documentation, or other long-form written content.
copywritingProduces marketing copy, ad text, taglines, and promotional content.
editingProofreads, corrects grammar, and improves style and clarity.
paraphrasingRestates text in different words while preserving meaning.
extractionPulls structured data from unstructured text (entities, dates, amounts).
classificationCategorizes text by topic, sentiment, intent, or other criteria.
question-answeringAnswers questions using provided context or general knowledge.
fact-checkingVerifies claims against authoritative sources.
reasoningPerforms multi-step logical reasoning and problem solving.
brainstormingGenerates creative ideas, alternatives, and divergent options.

Code

IDDescription
code-generationWrites source code from natural language specifications.
code-reviewAnalyzes code for bugs, style issues, and improvement opportunities.
code-explanationExplains what code does in plain language.
debuggingIdentifies and fixes software bugs.
testingWrites or executes tests and reports results.
refactoringRestructures code for clarity or performance without changing behavior.
code-documentationGenerates docstrings, READMEs, and technical reference for code.
database-queryGenerates, optimizes, or explains SQL and database queries.
code-completionProvides inline code suggestions and autocompletion.

Data

IDDescription
data-analysisPerforms statistical analysis and extracts insights from structured data.
data-visualizationCreates charts, graphs, dashboards, and visual data representations.
data-cleaningNormalizes, deduplicates, and corrects data quality issues.
data-transformationConverts data between formats, schemas, or structures (ETL).
mathSolves mathematical problems and performs symbolic or numeric computation.
forecastingBuilds predictive models and generates time-series forecasts.
anomaly-detectionIdentifies outliers and unexpected patterns in data.
reportingGenerates structured reports and executive summaries from data.
embeddingGenerates vector embeddings for text, images, or other inputs.
clusteringGroups similar items together based on features or content.
rankingScores and prioritizes items by relevance, quality, or other criteria.

Search & Retrieval

IDDescription
searchLooks up records, names or resources by query in a specific corpus or registry.
web-searchSearches the public internet for information.
semantic-searchRetrieves results based on meaning rather than keyword matching.
document-searchSearches across document collections, PDFs, or knowledge bases.
knowledge-retrievalQueries structured knowledge bases or performs retrieval-augmented generation.
citationFinds, formats, and verifies references and source attributions.

Media

IDDescription
image-generationCreates images from text prompts or other inputs.
image-editingModifies, enhances, or transforms existing images.
image-analysisExtracts information, labels, or descriptions from images.
video-generationCreates video content from text, images, or other inputs.
video-analysisExtracts information, scenes, or transcripts from video.
audio-transcriptionConverts spoken audio into text.
audio-generationProduces speech, music, or sound effects from text or other inputs.
ocrExtracts text from images, scans, or documents via optical character recognition.
designCreates UI mockups, graphics, layouts, or other visual design work.
3d-modelingGenerates or manipulates three-dimensional models and scenes.

Communication

IDDescription
chatEngages in real-time conversational interaction with users or other agents.
email-draftingComposes, formats, and suggests email messages.
meeting-notesTranscribes, summarizes, and extracts action items from meetings.
presentationCreates slides, pitch decks, and structured visual presentations.
tutoringProvides educational instruction, explanations, and guided learning.
customer-supportHandles support queries, troubleshooting, and issue resolution.
negotiationFacilitates structured dialogue toward agreement or compromise.

Automation

IDDescription
web-scrapingExtracts structured data from web pages.
api-integrationConnects to and orchestrates third-party APIs.
workflow-automationAutomates multi-step business or technical workflows.
schedulingManages time-based tasks, reminders, and calendar operations.
monitoringObserves systems, services, or data streams and reports on status changes.
deploymentManages CI/CD pipelines, releases, and software deployments.
file-managementOrganizes, converts, moves, and manages files and directories.
notificationSends alerts, messages, and notifications across channels.
data-entryFills forms, inputs data, and automates manual entry tasks.

Security

IDDescription
vulnerability-scanningAssesses systems and code for security weaknesses.
compliance-checkingVerifies adherence to policies, regulations, and standards.
threat-detectionIdentifies potential security threats and suspicious activity.
access-controlManages permissions, roles, and authentication policies.
encryptionHandles data encryption, decryption, and key management.

10. Security Considerations

11. Legacy manifests

Names that predate the AGT Registry may carry one of two older formats, both read-only:

Writers MUST NOT generate new v1 or v2 manifests; new names write v3.

12. References