A2A Passport — one GTIN, one call, everything GSC knows, signed
Server Details
The hubs are the records; A2A-Passport.ai issues the passport.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- greencore-solutions/a2a-passport
- GitHub Stars
- 0
TDQS
Scored across 3 tools
get_passport (fetch one signed passport), list_passports (enumerate register entries without bodies), and verify_passport (cryptographic/section integrity check) target clearly distinct operations on the same domain object. There is no overlap in intent, so an agent can select correctly without ambiguity.
All three tools follow the same snake_case verb_noun pattern: get_passport, list_passports, verify_passport. The convention is uniform and the verbs accurately reflect the read/list/validate semantics.
Three tools is a tight, well-scoped surface for a read-oriented passport service whose tagline is 'one GTIN, one call.' Each tool earns its place (fetch, enumerate, verify) with no filler tools.
The read lifecycle (get, list with filters/pagination, verify against JWKS) is covered, and version issuance is implicit in the first get, so no explicit create is needed. However, there is no lifecycle-management operation such as revocation, re-issue, or delete, which could be needed if the register allows retraction.
Available Tools
3 toolsget_passportGet PassportAIdempotentInspect
The signed passport of a product (a Global Trade Item Number, GTIN) or a retail banner (market/banner, e.g. FR/Carrefour): which hub holds its record, where it is cleared, its compliance records, who lists it, where the payment door is. Read live from the GSC hubs on every call; the first call issues version 1. subject = a GTIN (8 to 14 digits) or market/banner; kind = gtin or banner (optional).
| Name | Required | Description | Default |
|---|---|---|---|
| kind | No | ||
| subject | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds real context beyond the annotations: it is 'read live ... on every call' and 'the first call issues version 1', which explains why readOnlyHint=false (a write side effect on first call) while idempotentHint=true. It does not discuss auth/permissions or failure behavior, but the annotation-consistent side-effect disclosure is valuable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the return content, then the live-read/versioning behavior, then the parameter meanings. Dense but each clause earns its place; only the parenthetical GTIN explanation is slightly redundant.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present the return shape need not be explained, and annotations cover the safety profile; the description supplies the side-effect/versioning nuance and both parameter meanings. Only default-value and permission details are absent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0%, so the description carries the burden and does document both params: subject is a GTIN of 8-14 digits or a market/banner string, and kind is 'gtin or banner (optional)'. It does not state what kind defaults to when omitted, a small remaining gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('get the signed passport') and enumerates the payload it returns (holding hub, clearance, compliance records, listing, payment door). It is clear what the tool does, but it never names or distinguishes itself from the sibling list_passports or verify_passport.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is only implied: retrieving the passport for a single subject ('a GTIN ... or market/banner'). There is no explicit when-to-use versus verify_passport or list_passports, and no statement of when this tool is not appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_passportsList PassportsARead-onlyIdempotentInspect
The passports on the register: ids, kinds, markets, versions and issue times, newest first. No bodies. Filter by kind (gtin or banner), market, or issued since a time; paginated.
| Name | Required | Description | Default |
|---|---|---|---|
| kind | No | ||
| limit | No | ||
| since | No | ||
| market | No | ||
| offset | No |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this a safe, idempotent, non-destructive read, so the bar is lower. The description adds genuinely useful traits beyond them: fixed ordering ('newest first'), payload shape ('No bodies'), and that the result set is paginated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two compact sentences with no filler; the return shape and ordering come first and the filtering/pagination note follows. Every clause carries information an agent can act on.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be spelled out, and the annotations cover the safety profile. The only real gap is the semantics of limit/offset, which are never explained beyond the word 'paginated'.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must carry the load and it does add meaning for kind (including the gtin/banner values the schema lacks an enum for), market, and since. It leaves limit and offset unexplained apart from the word 'paginated', so the compensation is partial.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (list) and resource (passports on the register) and enumerates exactly what comes back (ids, kinds, markets, versions, issue times). The contrast with siblings is implicit via 'No bodies,' which suggests get_passport returns the body, but no sibling is named outright.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It tells the agent how to narrow results (kind, market, since) and that results are paginated, which implies usage for metadata browsing rather than fetching a single record. However, it never says when to prefer this over get_passport or verify_passport, leaving the agent to infer the routing.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
verify_passportVerify PassportBRead-onlyIdempotentInspect
Check a passport: is the signature valid, is the chain of versions intact, how old is the stamp, was any section not read. Verifies from the published key at /.well-known/jwks.json.
| Name | Required | Description | Default |
|---|---|---|---|
| version | No | ||
| passport_id | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish readOnly, idempotent, non-destructive, closed-world behavior, so the bar is lower; the description still adds meaningful context by disclosing the trust anchor used (the published key at /.well-known/jwks.json) and the four distinct checks performed. It does not state failure modes (e.g., what a broken chain returns), which is a minor gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two dense sentences with the four checks front-loaded and the key-location detail placed last; no filler. The list-style phrasing is efficient, though the compressed 'was any section not read' clause reads slightly awkwardly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need not be explained, and annotations cover the safety profile. However, with 0% parameter coverage and no usage routing to the sibling tools, the definition leaves real gaps for a two-parameter verification tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must carry parameter meaning, and it largely does not. The phrase 'chain of versions intact' loosely gestures at the optional 'version' parameter but never explains that it pins verification to a specific version, and the passport_id format/source is never described.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (verify/check) and resource (passport) and enumerates exactly what is validated: signature validity, version-chain integrity, stamp age, and unread sections. It is clearly distinguishable from get_passport/list_passports in intent, though it never names those siblings explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied — this is the tool you call to validate rather than merely retrieve a passport — but there is no explicit when-to-use, when-not-to-use, or reference to the get_passport/list_passports alternatives. An agent can infer the routing but must do so unaided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- First observed
get_passport - First observed
list_passports - First observed
verify_passport
Related MCP Connectors
Verifiable agent DIDs + capability discovery — the passport & directory of the A2A economy.
Command your AI agents: verifiable passports, credential injection, full audit, revoke in 60s.
Issue Agent Passports and verify agent authority before value moves. Signed verification records.
First A2A registry where AI agents discover & transact with compliance firms - audits, permits.
Related MCP Servers
- AlicenseAqualityCmaintenanceIssues, verifies, and exchanges portable cryptographic compliance passports for AI agents, enabling offline verification of regulatory compliance across 11 frameworks.3MIT
- AlicenseAqualityDmaintenanceTrust intelligence MCP server for AI agents. 19 tools for identity stamps, reputation scoring (0-100), agent registry, forensic audit trails, ERC-8004 bridge, and A2A passports via x402 USDC micropayments.191Apache 2.0
- AlicenseNot gradedqualityDmaintenancePublishes AAIF Agent Cards and bridges A2A and OASF to AAIF, with built-in EU AI Act compliance.MIT
- AlicenseBqualityBmaintenanceEnables AI agents to execute actions under an accountability layer with identity passports, mandates, a permission gate, and a tamper-evident journal, while requiring human confirmation for irreversible operations.737 PyPI4AGPL 3.0
Glama MCP Gateway
Add one secure layer between your agents and this server.