VAGP 0.3 open protocol
Public specification, schemas, vectors and baseline crypto profile.
VALIDATION / PROTOCOL · MCP · MULTICLOUD
Verimand publishes validation status separately from product roadmap claims. This page records what is validated today and which identity integrations remain limited.
VAGP 0.3 is public, conformance-tested and independently implemented from its public artifacts.
Public specification, schemas, vectors and baseline crypto profile.
81/81 required black-box conformance checks.
Clean-room Core implementation validates implementability from public artifacts.
The Verimand MCP Authority Server is publicly available for authority resolution and inspection. Tool availability does not itself grant authority.
npx -y @verimand/mcp-authority-server@0.1.0dev.verimand/mcp-authority-server
Gateway validation demonstrates fail-closed protected execution, replay blocking and signed outcome evidence in the validated profiles.
Gateway enforcement path validated in controlled pilot and multicloud scenarios.
Denied requests do not reach the protected resource.
Replay attempts are blocked before repeat downstream execution.
Outcome evidence is signed and carries Evidence Certainty.
A2A delegates tasks. VAGP governs delegated authority. A2A-01 validates the boundary with the official A2A protocol without adding A2A-specific authority semantics to VAGP.
This supports a narrow interoperability claim: A2A task and Agent Card metadata can carry work intent and discovery information, but they do not bypass trusted identity binding, Agent DNA, VAGP mandates, attenuation, revocation or replay controls. It does not claim a public Verimand A2A package, production A2A Gateway or A2A certification.
MC-02 validates real Azure and Google Cloud authority enforcement in a narrow controlled test scope. This is not a production SaaS availability claim.
Sanitized MC-02 evidence supports bidirectional Azure/GCP validation, Google WIF, GCP → Azure replay/revocation enforcement and real SPIFFE/SPIRE SVID issuance. It does not validate all clouds, all identity providers or production operation.
Identity establishes who the agent is. Verimand governs what it is authorized to do. Provider-neutral authority semantics are architecturally validated while real provider coverage is still expanding.
Validated through the provider-neutral trusted identity seam.
Gateway verifier integration is not yet fully validated.
Blocked on the blueprint credential/token path.
Used as the deterministic baseline for authority semantics.
Bring your identity. Keep one authority model. Provider identity must not itself grant authority.