{"slug":"an-ietf-draft-wants-one-way-to-find-and-call-any-agent","citations":[{"url":"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/01/","committed_hash":"sha256:04204fe40aa5c027373a840dc1c2063eac2c3dac423067992367ade5cfa6d8ec","committed_hash_short":"sha256:04204fe4…cfa6d8ec","mime_type":"text/html","committed_at":"2026-09-15T21:00:23.574539+00:00","content_snapshot":"\n<!DOCTYPE html>\n\n\n\n\n\n\n<html data-bs-theme=\"auto\" lang=\"en\" prefix=\"og: http://ogp.me/ns# article: http://ogp.me/ns/article#\">\n    <head>\n        \n        <meta charset=\"utf-8\">\n        <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n        <title>\n            \n    \n        draft-cui-ai-agent-discovery-invocation-01 - AI Agent Discovery and Invocation Protocol\n    \n\n        </title>\n        <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n        <meta name=\"traceparent\" content=\"\">\n        <link href=\"https://static.ietf.org/fonts/inter/import.css\" rel=\"stylesheet\">\n        <link href=\"https://static.ietf.org/fonts/noto-sans-mono/import.css\" rel=\"stylesheet\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.75.0/ietf/css/ietf.css\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.75.0/ietf/css/select2.css\">\n        \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/theme.js\"></script>\n        <style>\n            .inline { display: inline; }\n        </style>\n        \n        \n    \n\n\n\n\n<meta property=\"og:title\" content=\"AI Agent Discovery and Invocation Protocol\">\n<meta property=\"og:url\" content=\"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/01/\">\n\n\n<link rel=\"canonical\" href=\"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/01/\">\n\n<meta property=\"og:site_name\" content=\"IETF Datatracker\">\n<meta property=\"og:description\" content=\"This document proposes a standardized protocol for discovery and invocation of AI agents. It defines a common metadata format for describing AI agents (including capabilities, I/O specifications, supported languages, tags, authentication methods, etc.), a capability-based discovery mechanism, and a unified RESTful invocation interface. This revision additionally specifies an optional extension that enables intent-based agent selection prior to discovery and invocation, without changing existing discovery or invocation semantics. The goal is to enable cross-platform interoperability among AI agents by providing a discover-and-match mechanism and a unified invocation entry point. Security considerations, including authentication and trust measures, are also discussed. This specification aims to facilitate the formation of multi-agent systems by making it easy to find the right agent for a task and invoke it in a consistent manner across different vendors and platforms.\">\n<meta property=\"og:type\" content=\"article\">\n\n<meta property=\"article:section\" content=\"Individual Internet-Draft\">\n\n<meta property=\"article:author\" content=\"Yong Cui\">\n<meta property=\"article:author\" content=\"Yihan Chao\">\n<meta property=\"article:author\" content=\"Chenguang Du\">\n\n\n\n    <link rel=\"alternate\"\n          type=\"application/atom+xml\"\n          title=\"Document changes\"\n          href=\"/feed/document-changes/draft-cui-ai-agent-discovery-invocation/\">\n    <meta name=\"description\"\n          content=\"AI Agent Discovery and Invocation Protocol \">\n\n        <script type=\"module\" crossorigin=\"\" src=\"https://static.ietf.org/dt/12.75.0/assets/embedded-881b2388.js\"></script>\n<link href=\"https://static.ietf.org/dt/12.75.0/assets/create-pinia-singleton-d62960d6.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n<link href=\"https://static.ietf.org/dt/12.75.0/assets/Scrollbar-8c74800b.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n        \n\n<link rel=\"apple-touch-icon\"\n      sizes=\"180x180\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-180.png\">\n<link rel=\"icon\"\n      sizes=\"32x32\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-32.png\">\n<link rel=\"icon\"\n      sizes=\"16x16\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-16.png\">\n<link rel=\"manifest\" href=\"/site.webmanifest\">\n<link rel=\"mask-icon\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-mask.svg\"\n      color=\"#ffffff\">\n<meta name=\"msapplication-TileColor\"\n      content=\"#ffffff\">\n<meta name=\"theme-color\"\n      content=\"#ffffff\">\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/ietf.js\"></script>\n        \n    </head>\n    <body  class=\"navbar-offset position-relative\"\n          data-group-menu-data-url=\"/group/groupmenu.json\">\n        \n        <noscript><iframe class=\"status\" title=\"Site status\" src=\"/status/latest\"></iframe></noscript>\n<div class=\"vue-embed\" data-component=\"Status\"></div>\n        <a class=\"visually-hidden visually-hidden-focusable\" href=\"#content\">Skip to main content</a>\n        <nav class=\"navbar navbar-expand-lg fixed-top bg-secondary-subtle\">\n            <div class=\"container-fluid\">\n                <a class=\"navbar-brand\" href=\"/\">\n                    \n\n\n\n<img alt=\"IETF Logo\"\n     class=\"d-lm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-white.svg\"\n        \n     \n     >\n\n<img alt=\"IETF Logo\"\n     class=\"d-dm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor.svg\"\n        \n     \n     >\n                    Datatracker\n                    \n                </a>\n                <div class=\"collapse navbar-collapse\" id=\"navbar-collapse\">\n                    <ul class=\"nav navbar-nav flex-nowrap\">\n                        \n\n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Groups\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li class=\"dropdown-header\">By area/parent</li>\n    \n\n\n\n    \n    <li class=\"dropend group-menu group-parent-2010\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#ART\">\n            Apps &amp; Realtime\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1008\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#GEN\">\n            General\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1052\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#INT\">\n            Internet\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1193\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#OPS\">\n            Ops &amp; Management\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1249\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#RTG\">\n            Routing\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1260\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#SEC\">\n            Security\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2412\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#WIT\">\n            Web and Internet Transport\n        </a>\n    </li>\n\n    \n        <li><a class=\"dropdown-item\" href=\"/group/iesg/about/\">IESG</a></li>\n    \n    <li class=\"dropend group-menu group-parent-7\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/program/\">\n            IAB\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-3\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rg/\">\n            IRTF\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2309\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/adm/\">\n            IETF LLC\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1876\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rfcedtyp/\">\n            RFC Editor\n        </a>\n    </li>\n\n\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/group/\">\n            Other\n        </a>\n        \n\n\n<ul class=\"dropdown-menu ms-n1\">\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/ag/\">Active AGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/area/\">Active Areas</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/dir/\">Active Directorates</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/iabworkshop/\">Active IAB Workshops</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/program/\">Active Programs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/rag/\">Active RAGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/team/\">Active Teams</a>\n        </li>\n    \n    \n</ul>\n\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">New work</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/chartering/\">\n            Chartering groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/wg/bofs/\">\n            BOFs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bof-requests\">\n            BOF Requests\n        </a>\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">Other groups</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/concluded/\">\n            Concluded groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/list/nonwg\">\n            Non-WG lists\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Documents\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/search\">\n            Search\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/recent\">\n            Recent I-Ds\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/submit/\">\n            Submit an Internet-Draft\n        </a>\n    </li>\n    \n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        RFC streams\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/iab/\">\n            IAB\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/irtf/\">\n            IRTF\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/ise/\">\n            ISE\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/editorial/\">\n            Editorial\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        Subseries\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/std\">\n            STD\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bcp\">\n            BCP\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/fyi\">\n            FYI\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Meetings\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/agenda\">\n            Agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/materials\">\n            Materials\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/floor-plan\">\n            Floor plan\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/register/\">\n            Registration\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/important-dates/\">\n            Important dates\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/session/request/\">\n            Request a session\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/requests\">\n            Session requests\n        </a>\n    </li>\n    \n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Upcoming meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/upcoming\">\n            Upcoming meetings\n        </a>\n    </li>\n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Past meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/past\">\n            Past meetings\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/past/\">\n            Meeting proceedings\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Other\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/ipr/\">\n            IPR disclosures\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/liaison/\">\n            Liaison statements\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/iesg/agenda/\">\n            IESG agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/nomcom/\">\n            NomComs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/downref\">\n            Downref registry\n        </a>\n    </li>\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n            Statistics\n        </a>\n        <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/document/\">\n                    I-Ds/RFCs\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/meeting/\">\n                    Meetings\n                </a>\n            </li>\n            \n            \n        </ul>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/api/\">\n            API Help\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/release/\">\n            Release notes\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           target=\"_blank\" href=\"https://status.ietf.org\">\n            System status\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item text-danger \"\n           target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n            <i class=\"bi bi-bug\">\n            </i>\n            Report a bug\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n\n    \n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            \n                User\n            \n        </a>\n        <ul class=\"dropdown-menu  mt-n1 \">\n        \n    \n    \n        \n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/login/?next=/doc/draft-cui-ai-agent-discovery-invocation/01/\">\n                    Sign in\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/reset/\">\n                    Password reset\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   href=\"/accounts/settings/\"\n                   rel=\"nofollow\">\n                    Preferences\n                </a>\n            </li>\n        \n    \n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/accounts/create/\">\n                New account\n            </a>\n        </li>\n    \n    <li class=\"dropend\">\n      <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n        List subscriptions\n      </a>\n      <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.ietf.org/mailman3/lists/\">\n                    IETF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.irtf.org/mailman3/lists/\">\n                IRTF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.iab.org/mailman3/lists/\">\n                    IAB Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.rfc-editor.org/mailman3/lists/\">\n                    RFC-Editor Lists\n                </a>\n            </li>\n        </ul>\n    </li>\n    \n    \n    \n    \n    \n    </ul></li>\n\n\n                    </ul>\n                </div>\n                <div class=\"d-flex align-items-center\">\n                    <a class=\"nav-link text-danger d-none d-xl-inline me-xl-4\"\n                       target=\"_blank\"\n                       href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n                        Report a bug\n                        <i class=\"bi bi-bug\"></i>\n                    </a>\n\n                    \n                        <a class=\"btn me-1  btn-warning  d-none d-sm-block\"\n                           rel=\"nofollow\"\n                           href=\"/accounts/login/?next=/doc/draft-cui-ai-agent-discovery-invocation/01/\">\n                            Sign in\n                        </a>\n                    \n\n                    <div class=\"d-none d-md-block dropdown\" id=\"navbar-doc-search-wrapper\">\n                        <input class=\"form-control\"\n                               id=\"navbar-doc-search\"\n                               type=\"text\"\n                               placeholder=\"Document search\"\n                               autocomplete=\"off\"\n                               data-ajax-url=\"/doc/select2search/document/all/\"\n                               aria-label=\"Document search\">\n                        <ul class=\"dropdown-menu\" id=\"navbar-doc-search-results\">\n                        </ul>\n                    </div>\n                </div>\n                <button class=\"navbar-toggler\"\n                        type=\"button\"\n                        data-bs-toggle=\"collapse\"\n                        data-bs-target=\"#navbar-collapse\"\n                        aria-controls=\"navbar-collapse\"\n                        aria-expanded=\"false\"\n                        aria-label=\"Toggle navigation\">\n                    <i class=\"navbar-toggler-icon\"></i>\n                </button>\n            </div>\n        </nav>\n        \n        <main class=\"pt-3 container-fluid\" id=\"main\">\n            <div class=\"row\">\n                \n                <div class=\"col mx-lg-3 ietf-auto-nav\" id=\"content\">\n                    <noscript data-nosnippet>\n                        <div class=\"alert alert-danger alert-ignore my-3\">\n                            <b>Javascript disabled?</b> Like other modern websites, the IETF Datatracker relies on Javascript.\n                            Please enable Javascript for full functionality.\n                        </div>\n                    </noscript>\n                    \n                    \n    \n    \n\n\n\n<h1>\n    AI Agent Discovery and Invocation Protocol\n    <br>\n    <small class=\"text-body-secondary\">draft-cui-ai-agent-discovery-invocation-01</small>\n</h1>\n<ul class=\"nav nav-tabs my-3\">\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link active\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/\">\n                Status\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/email/\">\n                Email expansions\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/history/\">\n                History\n            </a>\n        </li>\n    \n</ul>\n\n    \n\n\n\n    <label class=\"my-1 fw-bold\">Versions:</label>\n    <nav class=\"mb-3\">\n\n    <ul class=\"revision-list pagination pagination-sm text-center flex-wrap\">\n        \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/00/\"\n                        >\n                            00\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item active\">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/01/\"\n                        rel=\"nofollow\">\n                            01\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/02/\"\n                        >\n                            02\n                        </a>\n                    </li>\n                \n            \n            \n        \n    </ul>\n\n    </nav>\n\n    \n\n\n\n\n    <div class=\"alert alert-warning \" role=\"alert\">\n        This document is an Internet-Draft (I-D).\n        Anyone may submit an I-D to the IETF.\n        This I-D is <strong>not endorsed by the IETF</strong> and has <strong>no formal standing</strong> in the\n        <a href=\"/doc/rfc2026/\">IETF standards process</a>.\n    </div>\n\n\n    <div id=\"doc-timeline\"></div>\n    \n        <div class=\"alert alert-warning my-3\">The information below is for an old version of the document.</div>\n    \n    <table class=\"table table-sm table-borderless\">\n        \n\n\n\n\n\n\n\n<tbody class=\"meta align-top  border-top\">\n    <tr>\n        <th scope=\"row\">Document</th>\n        <th scope=\"row\">Type</th>\n        <td class=\"edit\"></td>\n        <td>\n            \n\n\n\n\n\n\n\n    <div>This is an older version of an Internet-Draft whose latest revision state is \"Active\".</div>\n\n            \n            \n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Authors</th>\n        <td class=\"edit\">\n            \n        </td>\n        <td>\n            \n            \n                <span ><a \n           title=\"Datatracker profile of Yong Cui\"\n            href=\"/person/cuiyong@tsinghua.edu.cn\" >Yong Cui</a> <a \n               href=\"mailto:cuiyong%40tsinghua.edu.cn\"\n               aria-label=\"Compose email to cuiyong@tsinghua.edu.cn\"\n               title=\"Compose email to cuiyong@tsinghua.edu.cn\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Yihan Chao\"\n            href=\"/person/chao_yihan@outlook.com\" >Yihan Chao</a> <a \n               href=\"mailto:chao_yihan%40outlook.com\"\n               aria-label=\"Compose email to chao_yihan@outlook.com\"\n               title=\"Compose email to chao_yihan@outlook.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Chenguang Du\"\n            href=\"/person/du_chenguang@outlook.com\" >Chenguang Du</a> <a \n               href=\"mailto:du_chenguang%40outlook.com\"\n               aria-label=\"Compose email to du_chenguang@outlook.com\"\n               title=\"Compose email to du_chenguang@outlook.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>\n            \n            \n        </td>\n    </tr>\n    \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Last updated</th>\n        <td class=\"edit\"></td>\n        <td>\n            2026-02-12\n            \n                <span class=\"text-body-secondary\">(Latest revision 2025-10-15)</span>\n            \n        </td>\n    </tr>\n    \n    \n        \n        \n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            RFC stream\n        </th>\n        <td class=\"edit\">\n            \n        </td>\n        <td class=\"text-body-secondary\">\n            \n                (None)\n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            Formats\n        </th>\n        <td class=\"edit\">\n        </td>\n        <td>\n            \n                \n    <div class=\"buttonlist\">\n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-01.txt\">\n            \n                <i class=\"bi bi-file-text\"></i> txt\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-01.html\">\n            \n                <i class=\"bi bi-file-code\"></i> html\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-01.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> xml\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          \n          href=\"/doc/html/draft-cui-ai-agent-discovery-invocation-01\">\n            \n                <i class=\"bi bi-file-code\"></i> htmlized\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/draft-cui-ai-agent-discovery-invocation/01/bibtex/\">\n            \n                <i class=\"bi bi-file-ruled\"></i> bibtex\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/bibxml3/draft-cui-ai-agent-discovery-invocation-01.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> bibxml\n            \n        </a>\n        \n    \n</div>\n\n            \n        </td>\n    </tr>\n    \n    \n        \n            \n            \n        \n    \n    \n        \n    \n</tbody>\n        <tbody class=\"meta border-top\">\n            <tr>\n                <th scope=\"row\">\n                    Stream\n                </th>\n                \n                    <th scope=\"row\">\n                        Stream state\n                    </th>\n                    <td class=\"edit\">\n                    </td>\n                    <td>\n                        <span class=\"text-body-secondary\">(No stream defined)</span>\n                    </td>\n                \n            </tr>\n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        Consensus boilerplate\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"text-danger\"\n                              title=\"Whether the document is the result of a community consensus process as defined in RFC 5741\">\n                            Unknown\n                        </span>\n                    </td>\n                </tr>\n            \n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        RFC Editor Note\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        \n                            <span class=\"text-body-secondary\">\n                                (None)\n                            </span>\n                        \n                    </td>\n                </tr>\n            \n            \n        </tbody>\n        \n            <tbody class=\"meta border-top\">\n                <tr>\n                    <th scope=\"row\">\n                        IESG\n                    </th>\n                    <th scope=\"row\">\n                        <a href=\"/doc/help/state/draft-iesg/\">\n                            IESG state\n                        </a>\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"\">\n                            \n                                I-D Exists\n                            \n                        </span>\n                    </td>\n                </tr>\n                \n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Telechat date\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                            \n                        </td>\n                    </tr>\n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Responsible AD\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Send notices to\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                </tbody>\n            \n            \n                \n            \n            \n        </table>\n        <div class=\"buttonlist\">\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"mailto:draft-cui-ai-agent-discovery-invocation@ietf.org?subject=Mail%20regarding%20draft-cui-ai-agent-discovery-invocation\">\n                <i class=\"bi bi-envelope\">\n                </i>\n                Email authors\n            </a>\n            \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/ipr/search/?submit=draft&amp;id=draft-cui-ai-agent-discovery-invocation\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-lightning\">\n                </i>\n                IPR\n                \n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/references/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-left\">\n                </i>\n                References\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/referencedby/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-right\">\n                </i>\n                Referenced by\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/api/idnits?url=https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation\">\n                </i>\n                Nits\n            </a>\n             <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/idnits3/results?url=https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation-diamond\">\n                </i>\n                Nits v3\n            </a>           \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://mailarchive.ietf.org/arch/search/?q=%22draft-cui-ai-agent-discovery-invocation%22\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-search\">\n                </i>\n                Search email archive\n            </a>\n            \n            \n            \n            \n        </div>\n        \n            <div class=\"card mt-5\">\n                <div class=\"card-header\">\n                    \n                        draft-cui-ai-agent-discovery-invocation-01\n                    \n                </div>\n                <div class=\"card-body\">\n                    <pre>Network Working Group                                             Y. Cui\nInternet-Draft                                       Tsinghua University\nIntended status: Informational                                   Y. Chao\nExpires: 16 August 2026                                            C. Du\n                                                 Zhongguancun Laboratory\n                                                        12 February 2026\n\n               AI Agent Discovery and Invocation Protocol\n               draft-cui-ai-agent-discovery-invocation-01\n\n<span>Abstract</span>\n\n   This document proposes a standardized protocol for discovery and\n   invocation of AI agents.  It defines a common metadata format for\n   describing AI agents (including capabilities, I/O specifications,\n   supported languages, tags, authentication methods, etc.), a\n   capability-based discovery mechanism, and a unified RESTful\n   invocation interface.\n\n   This revision additionally specifies an optional extension that\n   enables intent-based agent selection prior to discovery and\n   invocation, without changing existing discovery or invocation\n   semantics.\n\n   The goal is to enable cross-platform interoperability among AI agents\n   by providing a discover-and-match mechanism and a unified invocation\n   entry point.  Security considerations, including authentication and\n   trust measures, are also discussed.  This specification aims to\n   facilitate the formation of multi-agent systems by making it easy to\n   find the right agent for a task and invoke it in a consistent manner\n   across different vendors and platforms.\n\nAbout This Document\n\n   This note is to be removed before publishing as an RFC.\n\n   The latest revision of this draft can be found at\n   https://example.com/LATEST.  Status information for this document may\n   be found at https://datatracker.ietf.org/doc/draft-cui-ai-agent-\n   discovery-invocation/.\n\n   Discussion of this document takes place on the WG Working Group\n   mailing list (mailto:WG@example.com), which is archived at\n   https://example.com/WG.\n\n   Source for this draft and an issue tracker can be found at\n   https://github.com/USER/REPO.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 1]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n<span>Status of This Memo</span>\n\n   This Internet-Draft is submitted in full conformance with the\n   provisions of BCP 78 and BCP 79.\n\n   Internet-Drafts are working documents of the Internet Engineering\n   Task Force (IETF).  Note that other groups may also distribute\n   working documents as Internet-Drafts.  The list of current Internet-\n   Drafts is at https://datatracker.ietf.org/drafts/current/.\n\n   Internet-Drafts are draft documents valid for a maximum of six months\n   and may be updated, replaced, or obsoleted by other documents at any\n   time.  It is inappropriate to use Internet-Drafts as reference\n   material or to cite them other than as &quot;work in progress.&quot;\n\n   This Internet-Draft will expire on 16 August 2026.\n\n<span>Copyright Notice</span>\n\n   Copyright (c) 2026 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust&#x27;s Legal\n   Provisions Relating to IETF Documents (https://trustee.ietf.org/\n   license-info) in effect on the date of publication of this document.\n   Please review these documents carefully, as they describe your rights\n   and restrictions with respect to this document.  Code Components\n   extracted from this document must include Revised BSD License text as\n   described in Section 4.e of the Trust Legal Provisions and are\n   provided without warranty as described in the Revised BSD License.\n\n<span>Table of Contents</span>\n\n   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   3\n   2.  Conventions and Definitions . . . . . . . . . . . . . . . . .   4\n   3.  Agent Metadata Specification  . . . . . . . . . . . . . . . .   5\n     3.1.  Core Fields . . . . . . . . . . . . . . . . . . . . . . .   5\n     3.2.  Operations and I/O Schema . . . . . . . . . . . . . . . .   7\n     3.3.  Example Agent Metadata  . . . . . . . . . . . . . . . . .   8\n   4.  Agent Discovery Mechanism . . . . . . . . . . . . . . . . . .   8\n     4.1.  Registry Overview . . . . . . . . . . . . . . . . . . . .   8\n     4.2.  Agent Registration  . . . . . . . . . . . . . . . . . . .   9\n     4.3.  Querying Agents . . . . . . . . . . . . . . . . . . . . .   9\n       4.3.1.  Attribute-Based Query (Filter)  . . . . . . . . . . .  10\n       4.3.2.  Semantic Query (Natural Language Search)  . . . . . .  10\n       4.3.3.  Retrieve Single Agent . . . . . . . . . . . . . . . .  11\n   5.  Agent Invocation  . . . . . . . . . . . . . . . . . . . . . .  11\n     5.1.  Invocation Request  . . . . . . . . . . . . . . . . . . .  11\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 2]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n     5.2.  Invocation Response . . . . . . . . . . . . . . . . . . .  12\n     5.3.  Additional Considerations for Invocation  . . . . . . . .  14\n   6.  Agent Semantic Resolution . . . . . . . . . . . . . . . . . .  15\n     6.1.  Non-Goals . . . . . . . . . . . . . . . . . . . . . . . .  15\n   7.  Semantic Routing Platform . . . . . . . . . . . . . . . . . .  15\n   8.  Backward Compatibility  . . . . . . . . . . . . . . . . . . .  16\n   9.  Security Considerations . . . . . . . . . . . . . . . . . . .  16\n   10. Example Interaction Flow  . . . . . . . . . . . . . . . . . .  16\n   11. IANA Considerations . . . . . . . . . . . . . . . . . . . . .  17\n   12. Normative References  . . . . . . . . . . . . . . . . . . . .  17\n   Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . . .  17\n   Authors&#x27; Addresses  . . . . . . . . . . . . . . . . . . . . . . .  17\n\n1.  Introduction\n\n   As artificial intelligence technologies advance rapidly, AI\n   agents—autonomous software components capable of perceiving their\n   environment, reasoning, and taking actions to achieve goals—have\n   emerged as a powerful paradigm for task execution.  Today, many\n   organizations develop specialized AI agents for various purposes:\n   from text translation and summarization, to code generation, to data\n   analysis and beyond.  These agents are often offered as services,\n   accessible over the network and may be integrated into larger\n   systems.  However, despite the proliferation of AI agents, there is\n   currently no standard protocol for discovering available agents and\n   invoking their capabilities in a uniform way.\n\n   Existing agent frameworks and platforms facilitate building agents\n   but typically operate in isolated ecosystems, making cross-platform\n   or cross-organization agent interoperability difficult.  Each\n   platform tends to define its own APIs for agent description and\n   invocation, which means a client wishing to use agents from multiple\n   sources must adapt to disparate interfaces.  This lack of\n   standardization creates friction, increases integration costs, and\n   hampers the development of multi-agent collaborative systems.\n\n   This document addresses these issues by proposing a standardized AI\n   Agent Discovery and Invocation Protocol.  The protocol provides:\n\n   1.  *Agent Metadata Specification:* A structured JSON Schema for\n       describing an agent&#x27;s identity, capabilities, inputs, outputs,\n       authentication requirements, and other attributes.  This enables\n       agents to publish their specifications in a machine-readable\n       form.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 3]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   2.  *Discovery Mechanism:* A registry-based approach where agents\n       register themselves and clients can search for agents by\n       capability, tags, or semantic queries.  The registry is language\n       and platform agnostic, facilitating cross-platform discovery.\n\n   3.  *Invocation Interface:* A RESTful API that enables a client\n       (which could be a human user application, another agent, or an\n       orchestration system) to invoke an agent&#x27;s capabilities through a\n       standard endpoint and JSON payloads.\n\n   4.  *Security Considerations:* Guidelines for authentication,\n       authorization, encrypted transport (TLS), and trust\n       establishment, ensuring that discovery and invocation happen\n       securely.\n\n   5.  *Interoperability with Existing Standards:* This specification\n       references existing standards such as JSON Schema, OAuth 2.0\n       [RFC6749], and OpenAPI concepts, and leverages established web\n       technologies for broad compatibility.\n\n   The primary audience for this specification includes developers of AI\n   agent platforms, providers of AI agent services, and system\n   architects building AI-enabled applications or multi-agent systems.\n   By adopting this protocol, an AI agent developer can make their agent\n   accessible to a wide ecosystem, and a client application can\n   integrate AI agents from multiple vendors without custom integration\n   for each.\n\n   This revision extends the base protocol with an optional Agent\n   Semantic Resolution layer that enables intent-based agent selection.\n   This extension allows a Host Agent or coordinator to describe a task\n   intent and receive candidate agents without predetermining which\n   agent to invoke.  ASR does not replace discovery; it adds a semantic\n   matching phase that can precede or augment the capability-based\n   search defined in earlier sections.\n\n2.  Conventions and Definitions\n\n   The key words &quot;MUST&quot;, &quot;MUST NOT&quot;, &quot;REQUIRED&quot;, &quot;SHALL&quot;, &quot;SHALL NOT&quot;,\n   &quot;SHOULD&quot;, &quot;SHOULD NOT&quot;, &quot;RECOMMENDED&quot;, &quot;NOT RECOMMENDED&quot;, &quot;MAY&quot;, and\n   &quot;OPTIONAL&quot; in this document are to be interpreted as described in\n   BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all\n   capitals, as shown here.\n\n   *  *AI Agent:* An autonomous software component that can perform\n      tasks using artificial intelligence capabilities.  Agents may wrap\n      language models, specialized ML models, or reasoning engines,\n      exposing their abilities via defined interfaces.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 4]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   *  *Agent Metadata:* A structured description of an agent, including\n      name, description, capabilities, input/output schemas,\n      authentication requirements, and endpoint information.\n\n   *  *Agent Registry (Discovery Service):* A service that maintains a\n      directory of registered agents and supports queries for\n      discovering agents by attributes or semantic search.\n\n   *  *Gateway:* (Optional) An intermediary service that routes client\n      requests to appropriate agents.  In some deployments, the registry\n      or another service acts as a gateway to simplify client-to-agent\n      connections.\n\n   *  *Invocation Endpoint:* The URL provided by an agent (or gateway)\n      where clients send requests to invoke the agent&#x27;s capabilities.\n\n   *  *Capability:* A high-level function an agent can perform,\n      identified by a string (e.g., &quot;translation&quot;, &quot;summarization&quot;,\n      &quot;image_classification&quot;).\n\n   *  *Operation:* A specific action supported by an agent.  Some agents\n      may have multiple operations; for example, an agent offering both\n      translation and language detection could list these as separate\n      operations, each with its own input/output schema.\n\n3.  Agent Metadata Specification\n\n   The Agent Metadata Specification defines a standard JSON document\n   that describes an agent.  All agents that wish to be discoverable and\n   invocable through this protocol MUST provide a metadata document\n   conforming to the schema below.  This metadata is used for agent\n   registration and returned to clients during discovery.\n\n3.1.  Core Fields\n\n   The following are the core fields of an agent metadata document:\n\n   *  *id (string):* A globally unique identifier for the agent.  This\n      could be a UUID or a similarly unique value, assigned by the\n      registry upon registration or by the agent provider in advance.\n      This ID is used to refer to the agent in all subsequent operations\n      (e.g., retrieval, invocation routing).\n\n   *  *name (string):* A human-readable name for the agent (e.g.,\n      &quot;Chinese-English Translator Agent&quot;).  Names need not be unique but\n      should be descriptive.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 5]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   *  *description (string):* A detailed description of the agent, its\n      purpose, and capabilities in natural language.  This helps both\n      human users and semantic search algorithms understand what the\n      agent does.\n\n   *  *version (string):* The version of the agent or its metadata\n      (e.g., &quot;1.0.0&quot;).  This allows tracking of agent updates over time.\n\n   *  *publisher (string):* The name or identifier of the entity\n      publishing the agent (e.g., an organization name or developer\n      name).\n\n   *  *capabilities (array of strings):* A list of capabilities the\n      agent supports.  Capabilities are high-level descriptors (like\n      tags or categories) that clients can filter by.  Examples:\n      [&quot;translation&quot;, &quot;summarization&quot;, &quot;text_generation&quot;].\n\n   *  *tags (array of strings):* Additional tags for search and\n      categorization (e.g., [&quot;nlp&quot;, &quot;chinese&quot;, &quot;transformer_model&quot;,\n      &quot;cloud&quot;]).  Tags differ from capabilities in that they can include\n      broader or orthogonal categories (like domain, language support,\n      deployment model, etc.).\n\n   *  *endpoint (string):* The URL of the agent&#x27;s invocation endpoint.\n      If the agent is behind a gateway, this could be either the direct\n      endpoint or, if direct access is not allowed, a gateway path\n      (e.g., the gateway might provide a unified endpoint like\n      /agents/{id}/invoke and internally route to the actual agent\n      endpoint).\n\n   *  *supported_languages (array of strings, optional):* A list of\n      languages the agent supports (e.g., [&quot;en&quot;, &quot;zh&quot;, &quot;fr&quot;]).  For\n      agents dealing with natural language tasks, this field indicates\n      which languages are handled.  If omitted, the agent is either\n      language-agnostic or should not be filtered by language.\n\n   *  *authentication (object, optional):* Describes the authentication\n      mechanism required to invoke the agent.  This object may include:\n\n      -  *type (string):* e.g., &quot;api_key&quot;, &quot;oauth2_bearer&quot;, &quot;mtls&quot;\n         (mutual TLS), &quot;none&quot;.\n\n      -  *instructions (string):* Human-readable note or URL for\n         obtaining credentials.\n\n      -  *scopes (array of strings):* If OAuth 2.0 is used, the OAuth\n         scopes required.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 6]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n      If no authentication is required, this field can be omitted or set\n      with type: &quot;none&quot;.\n\n   *  *status (string, optional):* Operational status of the agent\n      (e.g., &quot;active&quot;, &quot;inactive&quot;, &quot;deprecated&quot;).  The registry may use\n      this to filter out agents that are not currently available.\n\n   *  *additional fields:* Additional fields may include metadata about\n      rate limits (e.g., max calls per minute), pricing info (if the\n      agent charges per use), or links to documentation.  These are not\n      standardized here but can be included in agent metadata as needed.\n\n3.2.  Operations and I/O Schema\n\n   Each agent MUST describe its input and output formats.  This is done\n   using the *operations* field:\n\n   *  *operations (array of objects):* A list of operations the agent\n      supports.  Each operation object has:\n\n      -  *name (string):* The operation name/identifier (e.g.,\n         &quot;translateText&quot;, &quot;summarize&quot;).\n\n      -  *description (string):* A description of what the operation\n         does.\n\n      -  *inputs (object):* A JSON Schema describing the expected input.\n         This allows clients to understand what data to send.  The JSON\n         Schema can specify required fields, types, enums, etc.\n\n      -  *outputs (object):* A JSON Schema describing the output format.\n\n      -  *examples (array of objects, optional):* Example input/output\n         pairs.  Each example is an object {&quot;input&quot;: {...}, &quot;output&quot;:\n         {...}} showing a sample invocation.\n\n   If an agent has a single operation, this array will have one element.\n   If it can do multiple distinct tasks, each is listed here.  Some\n   agents may not have structured operations (e.g., a general-purpose\n   language model that just produces text).  In that case, the\n   operations field might include a generic operation like {&quot;name&quot;:\n   &quot;generate&quot;, ...}.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 7]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   If an agent has a single operation, this array will have one element.\n   If it can do multiple distinct tasks, each is listed here.  For\n   simple agents with one primary function, an alternative is to use\n   top-level inputs and outputs fields directly (instead of an\n   operations array).  In that case, the whole agent effectively has one\n   implied operation.  This spec allows both styles, but using\n   operations is recommended for future extensibility.\n\n3.3.  Example Agent Metadata\n\n   Below is an example metadata JSON for a translation agent:\n\n   json { &quot;id&quot;: &quot;agent-12345&quot;, &quot;name&quot;: &quot;Chinese-English Translator&quot;,\n   &quot;description&quot;: &quot;Translates text between Chinese and English with high\n   accuracy using a fine-tuned model.&quot;, &quot;version&quot;: &quot;1.2.0&quot;, &quot;publisher&quot;:\n   &quot;ExampleAI Inc.&quot;, &quot;capabilities&quot;: [&quot;translation&quot;], &quot;tags&quot;: [&quot;nlp&quot;,\n   &quot;chinese&quot;, &quot;english&quot;, &quot;cloud&quot;], &quot;endpoint&quot;:\n   &quot;https://api.example.com/agents/translate&quot;, &quot;supported_languages&quot;:\n   [&quot;en&quot;, &quot;zh&quot;], &quot;authentication&quot;: { &quot;type&quot;: &quot;api_key&quot;, &quot;instructions&quot;:\n   &quot;Include &#x27;X-API-Key&#x27; header with your API key.&quot; }, &quot;status&quot;:\n   &quot;active&quot;, &quot;operations&quot;: [ { &quot;name&quot;: &quot;translateText&quot;, &quot;description&quot;:\n   &quot;Translates text from source language to target language.&quot;, &quot;inputs&quot;:\n   { &quot;type&quot;: &quot;object&quot;, &quot;properties&quot;: { &quot;text&quot;: {&quot;type&quot;: &quot;string&quot;},\n   &quot;source_language&quot;: {&quot;type&quot;: &quot;string&quot;, &quot;enum&quot;: [&quot;en&quot;, &quot;zh&quot;]},\n   &quot;target_language&quot;: {&quot;type&quot;: &quot;string&quot;, &quot;enum&quot;: [&quot;en&quot;, &quot;zh&quot;]} },\n   &quot;required&quot;: [&quot;text&quot;, &quot;source_language&quot;, &quot;target_language&quot;] },\n   &quot;outputs&quot;: { &quot;type&quot;: &quot;object&quot;, &quot;properties&quot;: { &quot;translated_text&quot;:\n   {&quot;type&quot;: &quot;string&quot;} } }, &quot;examples&quot;: [ { &quot;input&quot;: {&quot;text&quot;: &quot;你好世界&quot;,\n   &quot;source_language&quot;: &quot;zh&quot;, &quot;target_language&quot;: &quot;en&quot;}, &quot;output&quot;:\n   {&quot;translated_text&quot;: &quot;Hello World&quot;} } ] } ] }\n\n   This metadata tells us the agent is an active translation agent for\n   Chinese and English, requires an API key for authentication, and has\n   one operation translateText with a clear input/output schema.\n\n4.  Agent Discovery Mechanism\n\n   The discovery mechanism allows clients to find agents that meet\n   certain criteria.  Discovery is provided by an Agent Registry (or\n   Discovery Service) that aggregates metadata from multiple agents.\n\n4.1.  Registry Overview\n\n   The Agent Registry is a network-accessible service that:\n\n   1.  Allows agents (or their administrators) to register metadata\n       about the agent.\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 8]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   2.  Stores and indexes these metadata entries for efficient search.\n\n   3.  Provides endpoints for clients to query and retrieve agent\n       information.\n\n   A registry may be operated by an organization for its internal\n   agents, or by a third party acting as a directory of agents across\n   multiple providers.  Multiple registries can coexist;\n   interoperability between registries is facilitated by consistent\n   metadata formats, though formal registry federation is out of scope\n   for this draft.\n\n4.2.  Agent Registration\n\n   An agent (or its administrator) registers with the registry by\n   sending its metadata to a registration endpoint:\n\n   *  *Endpoint:* POST /agents\n\n   *  *Request Body:* The agent metadata JSON document.\n\n   *  *Response:* On success, the registry returns *201 Created* (if a\n      new agent was added) or *200 OK* (if an existing agent was\n      updated), with the stored agent metadata (including the assigned\n      id if the agent did not provide one).  If validation fails (e.g.,\n      missing required fields), the registry returns a *400 Bad Request*\n      with error details.\n\n   The registry MUST validate the metadata against the schema.\n   Registration may require authentication (for example, the registry\n   only allows verified publishers to register agents).\n\n   Updates to an agent&#x27;s metadata (e.g., a new version, changed\n   endpoint, etc.) can be done via a PUT request to the agent&#x27;s entry:\n\n   *  *Endpoint:* PUT /agents/{id}\n\n   *  *Request Body:* Updated metadata.\n\n   *  *Response:* *200 OK* on success; *404 Not Found* if no agent with\n      that ID exists; *403 Forbidden* if the requester is not authorized\n      to update that agent.\n\n4.3.  Querying Agents\n\n   Clients query the registry using the search endpoint.  The protocol\n   supports two types of queries:\n\n<span>Cui, et al.              Expires 16 August 2026                 [Page 9]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n4.3.1.  Attribute-Based Query (Filter)\n\n   Clients can specify criteria to filter agents by capabilities, tags,\n   supported languages, etc.\n\n   *  *Endpoint:* GET /agents?capabilities=X&amp;tags=Y&amp;language=Z\n\n   *  or a structured query via *POST /agents/search* with a JSON body.\n\n   For simplicity, *POST /agents/search* is recommended for more complex\n   queries.  The body might look like:\n\n   json { &quot;filters&quot;: { &quot;capabilities&quot;: [&quot;translation&quot;],\n   &quot;supported_languages&quot;: [&quot;en&quot;, &quot;zh&quot;], &quot;tags&quot;: [&quot;nlp&quot;] }, &quot;top&quot;: 10 }\n\n   This returns up to 10 agents that match all the specified filters.\n   Filters are combined with AND logic (the agent must satisfy all\n   conditions).  Capabilities and tags are matched by set intersection\n   (the agent must have at least the ones listed).\n\n   The response is a JSON array of agent summary objects:\n\n   json [ { &quot;id&quot;: &quot;agent-12345&quot;, &quot;name&quot;: &quot;Chinese-English Translator&quot;,\n   &quot;description&quot;: &quot;...&quot;, &quot;endpoint&quot;: &quot;https://api.example.com/agents/\n   translate&quot;, &quot;capabilities&quot;: [&quot;translation&quot;] }, ... ]\n\n   Summary objects include essential fields to help the client decide\n   which agent to use, without returning the full detailed metadata.  A\n   client can retrieve full metadata via the single-agent endpoint.\n\n4.3.2.  Semantic Query (Natural Language Search)\n\n   In addition to attribute-based search, the registry MAY support\n   semantic search where the client describes a need in natural\n   language, and the registry uses AI techniques (embeddings, LLM-based\n   matching) to find relevant agents.  This is an optional feature for\n   registries.\n\n   *  *Endpoint:* POST /agents/search\n\n   *  *Request Body:* json { &quot;query&quot;: &quot;I need an agent that can\n      summarize long legal documents in Chinese.&quot;, &quot;top&quot;: 5 }\n\n   The registry returns a ranked list of agents whose descriptions match\n   the query semantically, possibly including a match score.  For\n   example:\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 10]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   json [ { &quot;id&quot;: &quot;agent-67890&quot;, &quot;name&quot;: &quot;Legal Document Summarizer&quot;,\n   &quot;description&quot;: &quot;...&quot;, &quot;score&quot;: 0.93 }, ... ]\n\n   Semantic search enables flexible discovery beyond exact filter\n   matching, aligning with how users or orchestrating agents might\n   reason about tasks.  Registries not supporting semantic search simply\n   ignore the query text and rely on provided filters.\n\n4.3.3.  Retrieve Single Agent\n\n   *  *Endpoint:* GET /agents/{id}\n\n   *  *Response:* Full metadata JSON for the specified agent, or *404*\n      if not found.\n\n5.  Agent Invocation\n\n   Once a client discovers a suitable agent, it invokes the agent by\n   sending a request to the agent&#x27;s endpoint.  This section defines the\n   interface for invocation.\n\n5.1.  Invocation Request\n\n   To invoke an agent, the client sends an HTTP POST request to the\n   agent&#x27;s invocation endpoint with a JSON body containing the input\n   data for the agent&#x27;s task.\n\n   *  *Method:* POST\n\n   *  *URL:* The endpoint URL from the agent&#x27;s metadata (e.g.,\n      https://api.example.com/agents/translate).  If a gateway is used,\n      the URL might be a gateway-provided path.\n\n   *  *Headers:*\n\n      -  Content-Type: application/json\n\n      -  Authentication header as required (e.g., Authorization: Bearer\n         &lt;token&gt; or X-API-Key: &lt;key&gt;).\n\n   *  *Body:* A JSON object containing input data as per the agent&#x27;s\n      input schema.\n\n   For example, invoking the translation agent:\n\n   json { &quot;text&quot;: &quot;Hello, how are you?&quot;, &quot;source_language&quot;: &quot;en&quot;,\n   &quot;target_language&quot;: &quot;fr&quot; }\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 11]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   This corresponds to the agent&#x27;s expected input fields.  If the agent\n   had multiple operations and a unified endpoint, there might be an\n   additional field to specify which operation or capability to use.\n   For instance, the JSON could include something like &quot;operation&quot;:\n   &quot;translateText&quot; if needed.  Alternatively, different operations could\n   be exposed at different URLs (e.g., /agents/xyz/translate vs\n   /agents/xyz/summarize), in which case the operation is selected by\n   the URL and no extra field is required.\n\n   The protocol does not fix a specific parameter naming; it defers to\n   the agent&#x27;s published schema.  The only requirement is that the\n   client&#x27;s JSON must conform to what the agent expects.  For\n   interoperability, using clear field names and standard data types\n   (strings, numbers, booleans, or structured objects) is encouraged.\n   Binary data (like images for an image-processing agent) should be\n   handled carefully: typically, binary inputs can be provided either as\n   URLs (pointing to where the data is stored), or as base64-encoded\n   strings within the JSON, or by using a multipart request.  This\n   specification suggests that if agents need to receive large binary\n   payloads, they either use URL references or out-of-scope mechanisms\n   (like a separate upload and then an ID in the JSON).  The core\n   invocation remains JSON-based for simplicity and consistency.\n\n   *Headers:* If authentication is required (see Security section), the\n   client must also include the appropriate headers (e.g.,\n   Authorization: Bearer &lt;token&gt; or an API key header) as dictated by\n   the agent&#x27;s metadata.  The invocation request may also include\n   optional headers for correlation or debugging, such as a request ID,\n   but those are not standardized here.\n\n5.2.  Invocation Response\n\n   The agent (or gateway) will process the request and return a\n   response.  The status code and JSON body of the response follow these\n   guidelines:\n\n   *  *Success (2xx status):* If the agent successfully performed its\n      task and produced a result, the status SHOULD be *200 OK* (or *201\n      Created* if a new resource was created as a result, though usually\n      for these actions 200 is fine).  The response body will contain\n      the output data in JSON.  Ideally, the output JSON conforms to the\n      agent&#x27;s advertised output schema.\n\n      For example, for the translation request above, a success response\n      might be:\n\n      json { &quot;translated_text&quot;: &quot;Bonjour, comment êtes-vous?&quot; }\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 12]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n      Here the JSON structure matches what was described in the agent\n      metadata&#x27;s outputs.  If the output is complex (e.g., multiple\n      fields or nested objects), those should appear accordingly.  The\n      response can include other informational fields if necessary (for\n      example, some agents might return usage metrics, like tokens used\n      or time taken, or a trace id for debugging, but these are optional\n      and out of scope of the core spec).\n\n   *  *Client Error (4xx status):* If the request was malformed or\n      invalid, the agent returns a *4xx* status code.  The most common\n      would be *400 Bad Request* for a JSON that doesn&#x27;t conform to the\n      expected schema or missing required fields.  For example, if the\n      client omitted a required field target_language, the agent might\n      respond with 400.  The response body SHOULD include an error\n      object explaining what went wrong.  We define a simple standard\n      for error objects:\n\n      json { &quot;error&quot;: { &quot;code&quot;: &quot;InvalidInput&quot;, &quot;message&quot;: &quot;Required\n      field &#x27;target_language&#x27; is missing.&quot; } }\n\n      Here, &quot;code&quot; is a short string identifier for the error type\n      (e.g., InvalidInput, Unauthorized, NotFound), and &quot;message&quot; is a\n      human-readable description.  The agent can include additional\n      details if available (e.g., a field name that is wrong, etc.).  If\n      the error is due to unauthorized access, *401 Unauthorized* or\n      *403 Forbidden* should be used (with an appropriate error message\n      indicating credentials are missing or insufficient).  If the agent\n      ID is not found (perhaps the client used an outdated reference),\n      *404 Not Found* is appropriate.\n\n   *  *Server/Agent Error (5xx status):* If something goes wrong on the\n      agent&#x27;s side during processing (an exception, a timeout while\n      executing the task, etc.), the agent (or gateway) returns a *5xx*\n      status (most likely *500 Internal Server Error* or *502/504* if\n      there are upstream issues).  The response should again include an\n      error object.  For example:\n\n      json { &quot;error&quot;: { &quot;code&quot;: &quot;AgentError&quot;, &quot;message&quot;: &quot;The agent\n      encountered an unexpected error while processing the request.&quot; } }\n\n      The agent might log the detailed error internally, but only convey\n      a generic message to the client for security.  A *503 Service\n      Unavailable* might be returned if the agent is temporarily\n      overloaded or offline, indicating the client could retry later.\n\n   *  *Status Codes Summary:* In short, this protocol expects the use of\n      standard status codes to reflect outcome (200 for success, 4xx for\n      client-side issues, 5xx for server-side issues).  Agents should\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 13]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n      avoid using 2xx if the operation did not semantically succeed\n      (even if technically a response was generated).  For example, if\n      an agent is a composite that calls other services and one of those\n      calls fails, it should propagate an error rather than returning\n      200 with an error in the data.\n\n5.3.  Additional Considerations for Invocation\n\n   *  *Streaming Responses:* Some agents (especially those wrapping\n      large language models) may produce results that are streamed (for\n      example, token-by-token outputs).  While this base protocol\n      assumes a request-response pattern with the full result delivered\n      at once, it can be extended to support streaming by using chunked\n      responses or WebSockets.  For instance, an agent might accept a\n      parameter like stream: true and then send partial outputs as they\n      become available.  This is an advanced use case and not elaborated\n      in this draft, but implementers should consider compatibility with\n      streaming if real-time responsiveness is needed.\n\n   *  *Batch Requests:* If a client wants to send multiple independent\n      requests to an agent in one go (for efficiency), the protocol can\n      support that by allowing an array of input objects in the POST\n      body instead of a single object.  The response would then be an\n      array of output results.  This is optional and depends on agent\n      support.\n\n   *  *Idempotency and Retries:* Most agent invocations are not strictly\n      idempotent (since an agent might perform an action or have side\n      effects), but many are pure functions (e.g., translate text).\n      Clients and gateways should design with retry logic carefully — if\n      a network failure happens, a retry might re-run an operation.\n      It&#x27;s best to ensure that agents&#x27; operations are either idempotent\n      or have safeguards (for example, an operation that sends an email\n      might have an idempotency key).\n\n   *  *Operation Metadata:* In cases where the agent defines multiple\n      operations in its metadata, the invocation interface might allow a\n      generic endpoint that accepts an operation name.  Alternatively,\n      each operation could be a sub-resource.  This draft leaves the\n      exact mechanism flexible: an implementation could choose one of\n      these approaches.  The key is that the invocation uses POST and a\n      JSON body following the agent&#x27;s schema.\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 14]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n6.  Agent Semantic Resolution\n\n   Agent Semantic Resolution (ASR) is an optional extension to the\n   discovery mechanism defined in this document.  ASR enables a client\n   to resolve a task intent into one or more candidate agents prior to\n   invoking any specific agent.\n\n   ASR operates on the following conceptual model:\n\n   (Intent, Context, Policy) → (Agent Endpoint(s), Invocation Metadata)\n\n   The intent represents the task to be performed, while context and\n   policy may include domain constraints, trust requirements, or\n   performance considerations.\n\n6.1.  Non-Goals\n\n   ASR explicitly does not provide:\n\n   *  Name-to-address resolution\n\n   *  Global or persistent agent identifiers\n\n   *  Replacement for DNS, ANS, or URI-based registries\n\n   ASR answers the question &quot;Which agent(s) should handle this task\n   now?&quot; rather than &quot;Where is agent X located?&quot;.\n\n7.  Semantic Routing Platform\n\n   A Semantic Routing Platform (SRP) is a control-plane service that\n   implements ASR.  An SRP assists a Host Agent in selecting appropriate\n   agents before standard discovery and invocation procedures are used.\n\n   An SRP MAY perform semantic matching, ranking, and policy-based\n   filtering of candidate agents.  The SRP does not participate in task\n   execution and does not alter the invocation semantics defined in this\n   document.\n\n   Interaction with an SRP is OPTIONAL.  Clients that do not support ASR\n   continue to operate using the discovery and invocation mechanisms\n   defined in earlier sections.\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 15]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n8.  Backward Compatibility\n\n   All discovery and invocation mechanisms defined in previous revisions\n   of this document remain valid and unchanged.\n\n   Agent Semantic Resolution is an optional extension.  Implementations\n   MAY support ASR incrementally, and registries MAY provide semantic\n   resolution capabilities without affecting existing clients.\n\n9.  Security Considerations\n\n   Security is a critical aspect of this protocol.  All discovery and\n   invocation traffic MUST be protected with TLS [RFC8446], and\n   authentication mechanisms such as OAuth 2.0 [RFC6749] bearer tokens,\n   API keys, or mutual TLS are required except for public discovery\n   endpoints.  Registries MUST enforce per-client entitlements, ensuring\n   that both search results and invocation access respect permissions\n   and scopes.  Gateways forwarding requests should authenticate\n   themselves to agents, and agents should maintain stable identifiers\n   and use signed responses when integrity is essential.  All\n   communication MUST be encrypted, and agents are encouraged to\n   disclose data-retention or logging practices, while sensitive data is\n   best handled by on-premises or certified agents.  To mitigate abuse,\n   registries and agents MUST implement rate limiting and quotas,\n   particularly in semantic search scenarios.  Trust mechanisms such as\n   certification, test harnesses, or reputation systems may be used to\n   validate agent claims, and metadata fields like &quot;certification&quot; or\n   &quot;quality_score&quot; can inform client trust decisions.  Systems SHOULD\n   also provide audit and logging with privacy-aware retention, while\n   clients must treat agent outputs as untrusted until verified, using\n   sandboxing and validation before executing code or commands.\n\n   When Agent Semantic Resolution is used, security considerations\n   extend to the pre-invocation phase.  Resolution services SHOULD\n   validate agent capability claims, apply policy constraints, and\n   exclude agents that do not meet trust or reputation requirements.\n   Agents deemed unsafe SHOULD NOT be returned as resolution candidates.\n\n10.  Example Interaction Flow\n\n   1.  *Search:* Client POST /agents/search with {&quot;query&quot;:&quot;summarize an\n       English document&quot;,&quot;filters&quot;:{&quot;capabilities&quot;:[&quot;summarization&quot;],&quot;su\n       pported_language&quot;:&quot;en&quot;},&quot;top&quot;:3}.\n\n   2.  *Select:* Registry returns candidate agents with id, name,\n       description, and score.  Client retrieves full metadata via GET\n       /agents/{id} if needed.\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 16]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   3.  *Invoke:* Client POST to the agent&#x27;s endpoint (or gateway path)\n       with inputs conforming to agent schema and required auth header.\n\n   4.  *Handle Response:* Client processes success or error response;\n       may log usage and optionally rate/feedback the agent.\n\n11.  IANA Considerations\n\n   This document has no IANA actions.\n\n12.  Normative References\n\n   [RFC2119]  Bradner, S., &quot;Key words for use in RFCs to Indicate\n              Requirement Levels&quot;, BCP 14, RFC 2119,\n              DOI 10.17487/RFC2119, March 1997,\n              &lt;https://www.rfc-editor.org/rfc/rfc2119&gt;.\n\n   [RFC6749]  Hardt, D., Ed., &quot;The OAuth 2.0 Authorization Framework&quot;,\n              RFC 6749, DOI 10.17487/RFC6749, October 2012,\n              &lt;https://www.rfc-editor.org/rfc/rfc6749&gt;.\n\n   [RFC8174]  Leiba, B., &quot;Ambiguity of Uppercase vs Lowercase in RFC\n              2119 Key Words&quot;, BCP 14, RFC 8174, DOI 10.17487/RFC8174,\n              May 2017, &lt;https://www.rfc-editor.org/rfc/rfc8174&gt;.\n\n   [RFC8259]  Bray, T., Ed., &quot;The JavaScript Object Notation (JSON) Data\n              Interchange Format&quot;, STD 90, RFC 8259,\n              DOI 10.17487/RFC8259, December 2017,\n              &lt;https://www.rfc-editor.org/rfc/rfc8259&gt;.\n\n   [RFC8446]  Rescorla, E., &quot;The Transport Layer Security (TLS) Protocol\n              Version 1.3&quot;, RFC 8446, DOI 10.17487/RFC8446, August 2018,\n              &lt;https://www.rfc-editor.org/rfc/rfc8446&gt;.\n\n   [RFC9110]  Fielding, R., Ed., Nottingham, M., Ed., and J. Reschke,\n              Ed., &quot;HTTP Semantics&quot;, STD 97, RFC 9110,\n              DOI 10.17487/RFC9110, June 2022,\n              &lt;https://www.rfc-editor.org/rfc/rfc9110&gt;.\n\n<span>Acknowledgments</span>\n\n   TODO acknowledge.\n\n<span>Authors&#x27; Addresses</span>\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 17]</span>\n<span>Internet-Draft                    AIDIP                    February 2026</span>\n\n   Yong Cui\n   Tsinghua University\n   Beijing, 100084\n   China\n   Email: cuiyong@tsinghua.edu.cn\n   URI:   http://www.cuiyong.net/\n\n   Yihan Chao\n   Zhongguancun Laboratory\n   Beijing, 100094\n   China\n   Email: chaoyh@zgclab.edu.cn\n\n   Chenguang Du\n   Zhongguancun Laboratory\n   Beijing, 100094\n   China\n   Email: ducg@zgclab.edu.cn\n\n<span>Cui, et al.              Expires 16 August 2026                [Page 18]</span>\n</pre>\n                </div>\n            </div>\n            \n        \n    \n                    \n                </div>\n            </div>\n        </main>\n        \n            <footer class=\"col-md-12 col-sm-12 border-top mt-5 py-5 bg-light-subtle text-center position-sticky\">\n                <a href=\"https://www.ietf.org/\" class=\"p-3\">IETF</a>\n                <a href=\"https://www.ietf.org/iesg/\" class=\"p-3\">IESG</a>\n                <a href=\"https://www.iab.org/\" class=\"p-3\">IAB</a>\n                <a href=\"https://www.irtf.org/\" class=\"p-3\">IRTF</a>\n                <a href=\"https://www.ietf.org/llc/\" class=\"p-3 text-nowrap\">IETF LLC</a>\n                <a href=\"https://trustee.ietf.org/\" class=\"p-3 text-nowrap\">IETF Trust</a>\n                <a href=\"https://www.rfc-editor.org/\" class=\"p-3 text-nowrap\">RFC Editor</a>\n                <a href=\"https://www.iana.org/\" class=\"p-3\">IANA</a>\n                <a href=\"https://www.ietf.org/privacy-statement/\" class=\"p-3 text-nowrap\">Privacy Statement</a>\n                <div class=\"small text-body-secondary py-3\">\n                    \n                        <a class=\"mx-2\" href=\"/release/about\">About IETF Datatracker</a>\n                        <span class=\"mx-2\">\n                            \n                                <a href=\"https://github.com/ietf-tools/datatracker/releases/tag/12.75.0\">\n                            \n                            Version 12.75.0\n                            (release - a9042bf)\n                            \n                                </a>\n                            \n                        </span>\n                    \n                    <a class=\"mx-2\" href=\"https://status.ietf.org\" target=\"_blank\">System Status</a>\n                    <span class=\"mx-2 text-danger\">\n                        <i class=\"bi bi-bug\"></i>\n                        Report a bug:\n                        <a class=\"text-reset\" target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">GitHub</a>\n                        \n                            <a class=\"text-reset\" href=\"mailto:tools-help@ietf.org\">Email</a>\n                        \n                    </span>\n                    \n                </div>\n            </footer>\n        \n        \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/d3.js\">\n        </script>\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/document_timeline.js\">\n        </script>\n    \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/select2.js\"></script>\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/navbar-doc-search.js\"></script>\n      \n<script>\n  var _paq = window._paq || [];\n  \n  _paq.push(['disableCookies']);\n  _paq.push(['trackPageView']);\n  _paq.push(['enableLinkTracking']);\n  (function() {\n    var u=\"//analytics.ietf.org/\";\n    _paq.push(['setTrackerUrl', u+'matomo.php']);\n    _paq.push(['setSiteId', 7]);\n    var d=document, g=d.createElement('script'), s=d.getElementsByTagName('script')[0];\n    g.type='text/javascript'; g.async=true; g.defer=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);\n  })();\n</script>\n<noscript><p><img src=\"//analytics.ietf.org/matomo.php?idsite=7\" style=\"border:0;\" alt=\"\" /></p></noscript>\n\n    <script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a3ba8f2be9c467bf',t:'MTc4OTUwNjAwOA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\n</html>\n","snapshot_chars":80949,"live_check":"changed"},{"url":"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-01.html","committed_hash":"sha256:f9fa37d956b8faa7173f47f63dbbae0e0cd9e1e3a92b218420fd7ae50925cde9","committed_hash_short":"sha256:f9fa37d9…0925cde9","mime_type":"text/html","committed_at":"2026-09-15T21:00:23.735012+00:00","content_snapshot":"<!DOCTYPE html>\n<html lang=\"en\" class=\"Internet-Draft\">\n<head>\n<meta charset=\"utf-8\">\n<meta content=\"Common,Han,Latin\" name=\"scripts\">\n<meta content=\"initial-scale=1.0\" name=\"viewport\">\n<title>AI Agent Discovery and Invocation Protocol</title>\n<meta content=\"Yong Cui\" name=\"author\">\n<meta content=\"Yihan Chao\" name=\"author\">\n<meta content=\"Chenguang Du\" name=\"author\">\n<meta content=\"\n       This document proposes a standardized protocol for discovery and invocation of AI agents. It defines a common metadata format for describing AI agents (including capabilities, I/O specifications, supported languages, tags, authentication methods, etc.), a capability-based discovery mechanism, and a unified RESTful invocation interface. \n       This revision additionally specifies an optional extension that enables intent-based agent selection prior to discovery and invocation, without changing existing discovery or invocation semantics. \n       The goal is to enable cross-platform interoperability among AI agents by providing a discover-and-match mechanism and a unified invocation entry point. Security considerations, including authentication and trust measures, are also discussed. This specification aims to facilitate the formation of multi-agent systems by making it easy to find the right agent for a task and invoke it in a consistent manner across different vendors and platforms. \n    \" name=\"description\">\n<meta content=\"xml2rfc 3.31.0\" name=\"generator\">\n<meta content=\"AI Agent\" name=\"keyword\">\n<meta content=\"Service Discovery\" name=\"keyword\">\n<meta content=\"draft-cui-ai-agent-discovery-invocation-01\" name=\"ietf.draft\">\n<!-- Generator version information:\n  xml2rfc 3.31.0\n    Python 3.12.12\n    ConfigArgParse 1.7.1\n    google-i18n-address 3.1.1\n    intervaltree 3.2.1\n    Jinja2 3.1.6\n    lxml 6.0.2\n    platformdirs 4.5.1\n    pycountry 24.6.1\n    PyYAML 6.0.3\n    requests 2.32.5\n    wcwidth 0.5.3\n    weasyprint 68.0\n-->\n<link href=\"draft-cui-ai-agent-discovery-invocation-01.xml\" rel=\"alternate\" type=\"application/rfc+xml\">\n<link href=\"#copyright\" rel=\"license\">\n<style type=\"text/css\">/*\n\n  NOTE: Changes at the bottom of this file overrides some earlier settings.\n\n  Once the style has stabilized and has been adopted as an official RFC style,\n  this can be consolidated so that style settings occur only in one place, but\n  for now the contents of this file consists first of the initial CSS work as\n  provided to the RFC Formatter (xml2rfc) work, followed by itemized and\n  commented changes found necessary during the development of the v3\n  formatters.\n\n*/\n\n/* fonts */\n@import url('https://static.ietf.org/fonts/noto-sans/import.css'); /* Sans-serif */\n@import url('https://static.ietf.org/fonts/noto-serif/import.css'); /* Serif (print) */\n@import url('https://static.ietf.org/fonts/roboto-mono/import.css'); /* Monospace */\n\n:root {\n  --font-sans: 'Noto Sans', Arial, Helvetica, sans-serif;\n  --font-serif: 'Noto Serif', 'Times', 'Times New Roman', serif;\n  --font-mono: 'Roboto Mono', Courier, 'Courier New', monospace;\n}\n\n@viewport {\n  zoom: 1.0;\n}\n@-ms-viewport {\n  width: extend-to-zoom;\n  zoom: 1.0;\n}\n/* general and mobile first */\nhtml {\n}\nbody {\n  max-width: 90%;\n  margin: 1.5em auto;\n  color: #222;\n  background-color: #fff;\n  font-size: 14px;\n  font-family: var(--font-sans);\n  line-height: 1.6;\n  scroll-behavior: smooth;\n  overflow-wrap: break-word;\n}\n.ears {\n  display: none;\n}\n\n/* headings */\n#title, h1, h2, h3, h4, h5, h6 {\n  margin: 1em 0 0.5em;\n  font-weight: bold;\n  line-height: 1.3;\n}\n#title {\n  clear: both;\n  border-bottom: 1px solid #ddd;\n  margin: 0 0 0.5em 0;\n  padding: 1em 0 0.5em;\n}\n.author {\n  padding-bottom: 4px;\n}\nh1 {\n  font-size: 26px;\n  margin: 1em 0;\n}\nh2 {\n  font-size: 22px;\n  margin-top: -20px;  /* provide offset for in-page anchors */\n  padding-top: 33px;\n}\nh3 {\n  font-size: 18px;\n  margin-top: -36px;  /* provide offset for in-page anchors */\n  padding-top: 42px;\n}\nh4 {\n  font-size: 16px;\n  margin-top: -36px;  /* provide offset for in-page anchors */\n  padding-top: 42px;\n}\nh5, h6 {\n  font-size: 14px;\n}\n#n-copyright-notice {\n  border-bottom: 1px solid #ddd;\n  padding-bottom: 1em;\n  margin-bottom: 1em;\n}\n/* general structure */\np {\n  padding: 0;\n  margin: 0 0 1em 0;\n  text-align: left;\n}\ndiv, span {\n  position: relative;\n}\ndiv {\n  margin: 0;\n}\n.alignRight.art-text {\n  background-color: #f9f9f9;\n  border: 1px solid #eee;\n  border-radius: 3px;\n  padding: 1em 1em 0;\n  margin-bottom: 1.5em;\n}\n.alignRight.art-text pre {\n  padding: 0;\n}\n.alignRight {\n  margin: 1em 0;\n}\n.alignRight > *:first-child {\n  border: none;\n  margin: 0;\n  float: right;\n  clear: both;\n}\n.alignRight > *:nth-child(2) {\n  clear: both;\n  display: block;\n  border: none;\n}\nsvg {\n  display: block;\n}\n@media print {\n  svg {\n    max-height: 850px;\n    max-width: 660px;\n  }\n}\nsvg[font-family~=\"serif\" i], svg [font-family~=\"serif\" i] {\n  font-family: var(--font-serif);\n}\nsvg[font-family~=\"sans-serif\" i], svg [font-family~=\"sans-serif\" i] {\n  font-family: var(--font-sans);\n}\nsvg[font-family~=\"monospace\" i], svg [font-family~=\"monospace\" i] {\n  font-family: var(--font-mono);\n}\n.alignCenter.art-text {\n  background-color: #f9f9f9;\n  border: 1px solid #eee;\n  border-radius: 3px;\n  padding: 1em 1em 0;\n  margin-bottom: 1.5em;\n}\n.alignCenter.art-text pre {\n  padding: 0;\n}\n.alignCenter {\n  margin: 1em 0;\n}\n.alignCenter > *:first-child {\n  display: table;\n  border: none;\n  margin: 0 auto;\n}\n\n/* lists */\nol, ul {\n  padding: 0;\n  margin: 0 0 1em 2em;\n}\nol ol, ul ul, ol ul, ul ol {\n  margin-left: 1em;\n}\nli {\n  margin: 0 0 0.25em 0;\n}\n.ulCompact li {\n  margin: 0;\n}\nul.empty, .ulEmpty {\n  list-style-type: none;\n}\nul.empty li, .ulEmpty li {\n  margin-top: 0.5em;\n}\nul.ulBare, li.ulBare {\n  margin-left: 0em !important;\n}\nul.compact, .ulCompact,\nol.compact, .olCompact {\n  line-height: 100%;\n  margin: 0 0 0 2em;\n}\n\n/* definition lists */\ndl {\n}\ndl > dt {\n  float: left;\n  margin-right: 1em;\n}\n/* \ndl.nohang > dt {\n  float: none;\n}\n*/\ndl > dd {\n  margin-bottom: .8em;\n  min-height: 1.3em;\n}\ndl.compact > dd, .dlCompact > dd {\n  margin-bottom: 0em;\n}\ndl > dd > dl {\n  margin-top: 0.5em;\n  margin-bottom: 0em;\n}\n\n/* links */\na {\n  text-decoration: none;\n}\na[href] {\n  color: #22e; /* Arlen: WCAG 2019 */\n}\na[href]:hover {\n  background-color: #f2f2f2;\n}\nfigcaption a[href],\na[href].selfRef {\n  color: #222;\n}\n/* XXX probably not this:\na.selfRef:hover {\n  background-color: transparent;\n  cursor: default;\n} */\n\n/* Figures */\ntt, code, pre {\n  background-color: #f9f9f9;\n  font-family: var(--font-mono);\n}\npre {\n  border: 1px solid #eee;\n  margin: 0;\n  padding: 1em;\n}\nimg {\n  max-width: 100%;\n}\nfigure {\n  margin: 0;\n}\nfigure blockquote {\n  margin: 0.8em 0.4em 0.4em;\n}\nfigcaption {\n  font-style: italic;\n  margin: 0 0 1em 0;\n}\n@media screen {\n  pre {\n    overflow-x: auto;\n    max-width: 100%;\n    max-width: calc(100% - 22px);\n  }\n}\n\n/* aside, blockquote */\naside, blockquote {\n  margin-left: 0;\n  padding: 1.2em 2em;\n}\nblockquote {\n  background-color: #f9f9f9;\n  color: #111; /* Arlen: WCAG 2019 */\n  border: 1px solid #ddd;\n  border-radius: 3px;\n  margin: 1em 0;\n}\nblockquote > *:last-child {\n  margin-bottom: 0;\n}\ncite {\n  display: block;\n  text-align: right;\n  font-style: italic;\n}\n.xref {\n  overflow-wrap: normal;\n}\n\n/* tables */\ntable {\n  width: 100%;\n  margin: 0 0 1em;\n  border-collapse: collapse;\n  border: 1px solid #eee;\n}\nth, td {\n  text-align: left;\n  vertical-align: top;\n  padding: 0.5em 0.75em;\n}\nth {\n  text-align: left;\n  background-color: #e9e9e9;\n}\ntr:nth-child(2n+1) > td {\n  background-color: #f5f5f5;\n}\ntable caption {\n  font-style: italic;\n  margin: 0;\n  padding: 0;\n  text-align: left;\n}\ntable p {\n  /* XXX to avoid bottom margin on table row signifiers. If paragraphs should\n     be allowed within tables more generally, it would be far better to select on a class. */\n  margin: 0;\n}\n\n/* pilcrow */\na.pilcrow {\n  color: #666; /* Arlen: AHDJ 2019 */\n  text-decoration: none;\n  visibility: hidden;\n  user-select: none;\n  -ms-user-select: none;\n  -o-user-select:none;\n  -moz-user-select: none;\n  -khtml-user-select: none;\n  -webkit-user-select: none;\n  -webkit-touch-callout: none;\n}\n@media screen {\n  aside:hover > a.pilcrow,\n  p:hover > a.pilcrow,\n  blockquote:hover > a.pilcrow,\n  div:hover > a.pilcrow,\n  li:hover > a.pilcrow,\n  pre:hover > a.pilcrow {\n    visibility: visible;\n  }\n  a.pilcrow:hover {\n    background-color: transparent;\n  }\n}\n\n/* misc */\nhr {\n  border: 0;\n  border-top: 1px solid #eee;\n}\n.bcp14 {\n  font-variant: small-caps;\n}\n\n.role {\n  font-variant: all-small-caps;\n}\n\n/* info block */\n#identifiers {\n  margin: 0;\n  font-size: 0.9em;\n}\n#identifiers dt {\n  width: 3em;\n  clear: left;\n}\n#identifiers dd {\n  float: left;\n  margin-bottom: 0;\n}\n/* Fix PDF info block run off issue */\n@media print {\n  #identifiers dd {\n    max-width: 100%;\n  }\n}\n#identifiers .authors .author {\n  display: inline-block;\n  margin-right: 1.5em;\n}\n#identifiers .authors .org {\n  font-style: italic;\n}\n\n/* The prepared/rendered info at the very bottom of the page */\n.docInfo {\n  color: #666; /* Arlen: WCAG 2019 */\n  font-size: 0.9em;\n  font-style: italic;\n  margin-top: 2em;\n}\n.docInfo .prepared {\n  float: left;\n}\n.docInfo .prepared {\n  float: right;\n}\n\n/* table of contents */\n#toc  {\n  padding: 0.75em 0 2em 0;\n  margin-bottom: 1em;\n}\nnav.toc ul {\n  margin: 0 0.5em 0 0;\n  padding: 0;\n  list-style: none;\n}\nnav.toc li {\n  line-height: 1.3em;\n  margin: 0.75em 0;\n  padding-left: 1.2em;\n  text-indent: -1.2em;\n}\n/* references */\n.references dt {\n  text-align: right;\n  font-weight: bold;\n  min-width: 7em;\n}\n.references dd {\n  margin-left: 8em;\n  overflow: auto;\n}\n\n.refInstance {\n  margin-bottom: 1.25em;\n}\n\n.refSubseries {\n  margin-bottom: 1.25em;\n}\n\n.references .ascii {\n  margin-bottom: 0.25em;\n}\n\n/* index */\n.index ul {\n  margin: 0 0 0 1em;\n  padding: 0;\n  list-style: none;\n}\n.index ul ul {\n  margin: 0;\n}\n.index li {\n  margin: 0;\n  text-indent: -2em;\n  padding-left: 2em;\n  padding-bottom: 5px;\n}\n.indexIndex {\n  margin: 0.5em 0 1em;\n}\n.index a {\n  font-weight: 700;\n}\n/* make the index two-column on all but the smallest screens */\n@media (min-width: 600px) {\n  .index ul {\n    -moz-column-count: 2;\n    -moz-column-gap: 20px;\n  }\n  .index ul ul {\n    -moz-column-count: 1;\n    -moz-column-gap: 0;\n  }\n}\n\n/* authors */\naddress.vcard {\n  font-style: normal;\n  margin: 1em 0;\n}\n\naddress.vcard .nameRole {\n  font-weight: 700;\n  margin-left: 0;\n}\naddress.vcard .label {\n  font-family: var(--font-sans);\n  margin: 0.5em 0;\n}\naddress.vcard .type {\n  display: none;\n}\n.alternative-contact {\n  margin: 1.5em 0 1em;\n}\nhr.addr {\n  border-top: 1px dashed;\n  margin: 0;\n  color: #ddd;\n  max-width: calc(100% - 16px);\n}\n\n/* temporary notes */\n.rfcEditorRemove::before {\n  position: absolute;\n  top: 0.2em;\n  right: 0.2em;\n  padding: 0.2em;\n  content: \"The RFC Editor will remove this note\";\n  color: #9e2a00; /* Arlen: WCAG 2019 */\n  background-color: #ffd; /* Arlen: WCAG 2019 */\n}\n.rfcEditorRemove {\n  position: relative;\n  padding-top: 1.8em;\n  background-color: #ffd; /* Arlen: WCAG 2019 */\n  border-radius: 3px;\n}\n.cref {\n  background-color: #ffd; /* Arlen: WCAG 2019 */\n  padding: 2px 4px;\n}\n.crefSource {\n  font-style: italic;\n}\n/* alternative layout for smaller screens */\n@media screen and (max-width: 1023px) {\n  body {\n    padding-top: 2em;\n  }\n  #title {\n    padding: 1em 0;\n  }\n  h1 {\n    font-size: 24px;\n  }\n  h2 {\n    font-size: 20px;\n    margin-top: -18px;  /* provide offset for in-page anchors */\n    padding-top: 38px;\n  }\n  #identifiers dd {\n    max-width: 60%;\n  }\n  #toc {\n    position: fixed;\n    z-index: 2;\n    top: 0;\n    right: 0;\n    padding: 0;\n    margin: 0;\n    background-color: inherit;\n    border-bottom: 1px solid #ccc;\n  }\n  #toc h2 {\n    margin: -1px 0 0 0;\n    padding: 4px 0 4px 6px;\n    padding-right: 1em;\n    min-width: 190px;\n    font-size: 1.1em;\n    text-align: right;\n    background-color: #444;\n    color: white;\n    cursor: pointer;\n  }\n  #toc h2::before { /* css hamburger */\n    float: right;\n    position: relative;\n    width: 1em;\n    height: 1px;\n    left: -164px;\n    margin: 6px 0 0 0;\n    background: white none repeat scroll 0 0;\n    box-shadow: 0 4px 0 0 white, 0 8px 0 0 white;\n    content: \"\";\n  }\n  #toc nav {\n    display: none;\n    padding: 0.5em 1em 1em;\n    overflow: auto;\n    height: calc(100vh - 48px);\n    border-left: 1px solid #ddd;\n  }\n}\n\n/* alternative layout for wide screens */\n@media screen and (min-width: 1024px) {\n  body {\n    max-width: 724px;\n    margin: 42px auto;\n    padding-left: 1.5em;\n    padding-right: 29em;\n  }\n  #toc {\n    position: fixed;\n    top: 42px;\n    right: 42px;\n    width: 25%;\n    margin: 0;\n    padding: 0 1em;\n    z-index: 1;\n  }\n  #toc h2 {\n    border-top: none;\n    border-bottom: 1px solid #ddd;\n    font-size: 1em;\n    font-weight: normal;\n    margin: 0;\n    padding: 0.25em 1em 1em 0;\n  }\n  #toc nav {\n    display: block;\n    height: calc(90vh - 84px);\n    bottom: 0;\n    padding: 0.5em 0 0;\n    overflow: auto;\n  }\n  img { /* future proofing */\n    max-width: 100%;\n    height: auto;\n  }\n}\n\n/* pagination */\n@media print {\n  body {\n    width: 100%;\n  }\n  p {\n    orphans: 3;\n    widows: 3;\n  }\n  #n-copyright-notice {\n    border-bottom: none;\n  }\n  #toc, #n-introduction {\n    page-break-before: always;\n  }\n  #toc {\n    border-top: none;\n    padding-top: 0;\n  }\n  figure, pre {\n    page-break-inside: avoid;\n  }\n  figure {\n    overflow: scroll;\n  }\n  .breakable pre {\n    break-inside: auto;\n  }\n  h1, h2, h3, h4, h5, h6 {\n    page-break-after: avoid;\n  }\n  h2+*, h3+*, h4+*, h5+*, h6+* {\n    page-break-before: avoid;\n  }\n  pre {\n    white-space: pre-wrap;\n    word-wrap: break-word;\n    font-size: 10pt;\n  }\n  table {\n    border: 1px solid #ddd;\n  }\n  td {\n    border-top: 1px solid #ddd;\n  }\n}\n\n/* This is commented out here, as the string-set: doesn't\n   pass W3C validation currently */\n/*\n.ears thead .left {\n  string-set: ears-top-left content();\n}\n\n.ears thead .center {\n  string-set: ears-top-center content();\n}\n\n.ears thead .right {\n  string-set: ears-top-right content();\n}\n\n.ears tfoot .left {\n  string-set: ears-bottom-left content();\n}\n\n.ears tfoot .center {\n  string-set: ears-bottom-center content();\n}\n\n.ears tfoot .right {\n  string-set: ears-bottom-right content();\n}\n*/\n\n@page :first {\n  padding-top: 0;\n  @top-left {\n    content: normal;\n    border: none;\n  }\n  @top-center {\n    content: normal;\n    border: none;\n  }\n  @top-right {\n    content: normal;\n    border: none;\n  }\n}\n\n@page {\n  size: A4;\n  margin-bottom: 45mm;\n  padding-top: 20px;\n  /* The following is commented out here, but set appropriately by in code, as\n     the content depends on the document */\n  /*\n  @top-left {\n    content: 'Internet-Draft';\n    vertical-align: bottom;\n    border-bottom: solid 1px #ccc;\n  }\n  @top-left {\n    content: string(ears-top-left);\n    vertical-align: bottom;\n    border-bottom: solid 1px #ccc;\n  }\n  @top-center {\n    content: string(ears-top-center);\n    vertical-align: bottom;\n    border-bottom: solid 1px #ccc;\n  }\n  @top-right {\n    content: string(ears-top-right);\n    vertical-align: bottom;\n    border-bottom: solid 1px #ccc;\n  }\n  @bottom-left {\n    content: string(ears-bottom-left);\n    vertical-align: top;\n    border-top: solid 1px #ccc;\n  }\n  @bottom-center {\n    content: string(ears-bottom-center);\n    vertical-align: top;\n    border-top: solid 1px #ccc;\n  }\n  @bottom-right {\n      content: '[Page ' counter(page) ']';\n      vertical-align: top;\n      border-top: solid 1px #ccc;\n  }\n  */\n\n}\n\n/* Changes introduced to fix issues found during implementation */\n/* Make sure links are clickable even if overlapped by following H* */\na {\n  z-index: 2;\n}\n/* Separate body from document info even without intervening H1 */\nsection {\n  clear: both;\n}\n\n\n/* Top align author divs, to avoid names without organization dropping level with org names */\n.author {\n  vertical-align: top;\n}\n\n/* Leave room in document info to show Internet-Draft on one line */\n#identifiers dt {\n  width: 8em;\n}\n\n/* Don't waste quite as much whitespace between label and value in doc info */\n#identifiers dd {\n  margin-left: 1em;\n}\n\n/* Give floating toc a background color (needed when it's a div inside section */\n#toc {\n  background-color: white;\n}\n\n/* Make the collapsed ToC header render white on gray also when it's a link */\n@media screen and (max-width: 1023px) {\n  #toc h2 a,\n  #toc h2 a:link,\n  #toc h2 a:focus,\n  #toc h2 a:hover,\n  #toc a.toplink,\n  #toc a.toplink:hover {\n    color: white;\n    background-color: #444;\n    text-decoration: none;\n  }\n}\n\n/* Give the bottom of the ToC some whitespace */\n@media screen and (min-width: 1024px) {\n  #toc {\n    padding: 0 0 1em 1em;\n  }\n}\n\n/* Style section numbers with more space between number and title */\n.section-number {\n  padding-right: 0.5em;\n}\n\n/* prevent monospace from becoming overly large */\ntt, code, pre {\n  font-size: 95%;\n}\n\n/* Fix the height/width aspect for ascii art*/\n.sourcecode pre,\n.art-text pre {\n  line-height: 1.12;\n}\n\n\n/* Add styling for a link in the ToC that points to the top of the document */\na.toplink {\n  float: right;\n  margin-right: 0.5em;\n}\n\n/* Fix the dl styling to match the RFC 7992 attributes */\ndl > dt,\ndl.dlParallel > dt {\n  float: left;\n  margin-right: 1em;\n}\ndl.dlNewline > dt {\n  float: none;\n}\n\n/* Provide styling for table cell text alignment */\ntable td.text-left,\ntable th.text-left {\n  text-align: left;\n}\ntable td.text-center,\ntable th.text-center {\n  text-align: center;\n}\ntable td.text-right,\ntable th.text-right {\n  text-align: right;\n}\n\n/* Make the alternative author contact information look less like just another\n   author, and group it closer with the primary author contact information */\n.alternative-contact {\n  margin: 0.5em 0 0.25em 0;\n}\naddress .non-ascii {\n  margin: 0 0 0 2em;\n}\n\n/* With it being possible to set tables with alignment\n  left, center, and right, { width: 100%; } does not make sense */\ntable {\n  width: auto;\n}\n\n/* Avoid reference text that sits in a block with very wide left margin,\n   because of a long floating dt label.*/\n.references dd {\n  overflow: visible;\n}\n\n/* Control caption placement */\ncaption {\n  caption-side: bottom;\n}\n\n/* Limit the width of the author address vcard, so names in right-to-left\n   script don't end up on the other side of the page. */\n\naddress.vcard {\n  max-width: 30em;\n  margin-right: auto;\n}\n\n/* For address alignment dependent on LTR or RTL scripts */\naddress div.left {\n  text-align: left;\n}\naddress div.right {\n  text-align: right;\n}\n\n/* Provide table alignment support.  We can't use the alignX classes above\n   since they do unwanted things with caption and other styling. */\ntable.right {\n margin-left: auto;\n margin-right: 0;\n}\ntable.center {\n margin-left: auto;\n margin-right: auto;\n}\ntable.left {\n margin-left: 0;\n margin-right: auto;\n}\n\n/* Give the table caption label the same styling as the figcaption */\ncaption a[href] {\n  color: #222;\n}\n\n@media print {\n  .toplink {\n    display: none;\n  }\n\n  /* avoid overwriting the top border line with the ToC header */\n  #toc {\n    padding-top: 1px;\n  }\n\n  /* Avoid page breaks inside dl and author address entries */\n  .vcard {\n    page-break-inside: avoid;\n  }\n\n}\n/* Tweak the bcp14 keyword presentation */\n.bcp14 {\n  font-variant: small-caps;\n  font-weight: bold;\n  font-size: 0.9em;\n}\n/* Tweak the invisible space above H* in order not to overlay links in text above */\n h2 {\n  margin-top: -18px;  /* provide offset for in-page anchors */\n  padding-top: 31px;\n }\n h3 {\n  margin-top: -18px;  /* provide offset for in-page anchors */\n  padding-top: 24px;\n }\n h4 {\n  margin-top: -18px;  /* provide offset for in-page anchors */\n  padding-top: 24px;\n }\n/* Float artwork pilcrow to the right */\n@media screen {\n  .artwork a.pilcrow {\n    display: block;\n    line-height: 0.7;\n    margin-top: 0.15em;\n  }\n}\n/* Make pilcrows on dd visible */\n@media screen {\n  dd:hover > a.pilcrow {\n    visibility: visible;\n  }\n}\n/* Make the placement of figcaption match that of a table's caption\n   by removing the figure's added bottom margin */\n.alignLeft.art-text,\n.alignCenter.art-text,\n.alignRight.art-text {\n   margin-bottom: 0;\n}\n.alignLeft,\n.alignCenter,\n.alignRight {\n  margin: 1em 0 0 0;\n}\n/* In print, the pilcrow won't show on hover, so prevent it from taking up space,\n   possibly even requiring a new line */\n@media print {\n  a.pilcrow {\n    display: none;\n  }\n}\n/* Styling for the external metadata */\ndiv#external-metadata {\n  background-color: #eee;\n  padding: 0.5em;\n  margin-bottom: 0.5em;\n  display: none;\n}\ndiv#internal-metadata {\n  padding: 0.5em;                       /* to match the external-metadata padding */\n}\n/* Styling for title RFC Number */\nh1#rfcnum {\n  clear: both;\n  margin: 0 0 -1em;\n  padding: 1em 0 0 0;\n}\n/* Make .olPercent look the same as <ol><li> */\ndl.olPercent > dd {\n  margin-bottom: 0.25em;\n  min-height: initial;\n}\n/* Give aside some styling to set it apart */\naside {\n  border-left: 1px solid #ddd;\n  margin: 1em 0 1em 2em;\n  padding: 0.2em 2em;\n}\naside > dl,\naside > ol,\naside > ul,\naside > table,\naside > p {\n  margin-bottom: 0.5em;\n}\n/* Additional page break settings */\n@media print {\n  figcaption, table caption {\n    page-break-before: avoid;\n  }\n}\n/* Font size adjustments for print */\n@media print {\n  body  { font-size: 10pt;      line-height: normal; max-width: 96%; }\n  h1    { font-size: 1.72em;    padding-top: 1.5em; } /* 1*1.2*1.2*1.2 */\n  h2    { font-size: 1.44em;    padding-top: 1.5em; } /* 1*1.2*1.2 */\n  h3    { font-size: 1.2em;     padding-top: 1.5em; } /* 1*1.2 */\n  h4    { font-size: 1em;       padding-top: 1.5em; }\n  h5, h6 { font-size: 1em;      margin: initial; padding: 0.5em 0 0.3em; }\n}\n/* Sourcecode margin in print, when there's no pilcrow */\n@media print {\n  .artwork,\n  .artwork > pre,\n  .sourcecode {\n    margin-bottom: 1em;\n  }\n}\n/* Avoid narrow tables forcing too narrow table captions, which may render badly */\ntable {\n  min-width: 20em;\n}\n/* ol type a */\nol.type-a { list-style-type: lower-alpha; }\nol.type-A { list-style-type: upper-alpha; }\nol.type-i { list-style-type: lower-roman; }\nol.type-I { list-style-type: upper-roman; }\n/* Apply the print table and row borders in general, on request from the RPC,\nand increase the contrast between border and odd row background slightly */\ntable {\n  border: 1px solid #ddd;\n}\ntd {\n  border-top: 1px solid #ddd;\n}\ntr {\n  break-inside: avoid;\n}\ntr:nth-child(2n+1) > td {\n  background-color: #f8f8f8;\n}\n/* Use style rules to govern display of the TOC. */\n@media screen and (max-width: 1023px) {\n  #toc nav { display: none; }\n  #toc.active nav { display: block; }\n}\n/* Add support for keepWithNext */\n.keepWithNext {\n  break-after: avoid-page;\n  break-after: avoid-page;\n}\n/* Add support for keepWithPrevious */\n.keepWithPrevious {\n  break-before: avoid-page;\n}\n/* Change the approach to avoiding breaks inside artwork etc. */\nfigure, pre, table, .artwork, .sourcecode  {\n  break-before: auto;\n  break-after: auto;\n}\n/* Avoid breaks between <dt> and <dd> */\ndl {\n  break-before: auto;\n  break-inside: auto;\n}\ndt {\n  break-before: auto;\n  break-after: avoid-page;\n}\ndd {\n  break-before: avoid-page;\n  break-after: auto;\n  orphans: 3;\n  widows: 3\n}\nspan.break, dd.break {\n  margin-bottom: 0;\n  min-height: 0;\n  break-before: auto;\n  break-inside: auto;\n  break-after: auto;\n}\n/* Undo break-before ToC */\n@media print {\n  #toc {\n    break-before: auto;\n  }\n}\n/* Text in compact lists should not get extra bottom margin space,\n   since that would makes the list not compact */\nul.compact p, .ulCompact p,\nol.compact p, .olCompact p {\n margin: 0;\n}\n/* But the list as a whole needs the extra space at the end */\nsection ul.compact,\nsection .ulCompact,\nsection ol.compact,\nsection .olCompact {\n  margin-bottom: 1em;                    /* same as p not within ul.compact etc. */\n}\n/* The tt and code background above interferes with for instance table cell\n   backgrounds.  Changed to something a bit more selective. */\ntt, code {\n  background-color: transparent;\n}\np tt, p code, li tt, li code, dt tt, dt code {\n  background-color: #f8f8f8;\n}\n/* Tweak the pre margin -- 0px doesn't come out well */\npre {\n   margin-top: 0.5px;\n}\n/* Tweak the compact list text */\nul.compact, .ulCompact,\nol.compact, .olCompact,\ndl.compact, .dlCompact {\n  line-height: normal;\n}\n/* Don't add top margin for nested lists */\nli > ul, li > ol, li > dl,\ndd > ul, dd > ol, dd > dl,\ndl > dd > dl {\n  margin-top: initial;\n}\n/* Elements that should not be rendered on the same line as a <dt> */\n/* This should match the element list in writer.text.TextWriter.render_dl() */\ndd > div.artwork:first-child,\ndd > aside:first-child,\ndd > blockquote:first-child,\ndd > figure:first-child,\ndd > ol:first-child,\ndd > div.sourcecode:first-child,\ndd > table:first-child,\ndd > ul:first-child {\n  clear: left;\n}\n/* fix for weird browser behaviour when <dd/> is empty */\ndt+dd:empty::before{\n  content: \"\\00a0\";\n}\n/* Make paragraph spacing inside <li> smaller than in body text, to fit better within the list */\nli > p {\n  margin-bottom: 0.5em\n}\n/* Don't let p margin spill out from inside list items */\nli > p:last-of-type:only-child {\n  margin-bottom: 0;\n}\n</style>\n<link href=\"rfc-local.css\" rel=\"stylesheet\" type=\"text/css\">\n<script type=\"application/javascript\">async function addMetadata(){try{const e=document.styleSheets[0].cssRules;for(let t=0;t<e.length;t++)if(/#identifiers/.exec(e[t].selectorText)){const a=e[t].cssText.replace(\"#identifiers\",\"#external-updates\");document.styleSheets[0].insertRule(a,document.styleSheets[0].cssRules.length)}}catch(e){console.log(e)}const e=document.getElementById(\"external-metadata\");if(e)try{var t,a=\"\",o=function(e){const t=document.getElementsByTagName(\"meta\");for(let a=0;a<t.length;a++)if(t[a].getAttribute(\"name\")===e)return t[a].getAttribute(\"content\");return\"\"}(\"rfc.number\");if(o){t=\"https://www.rfc-editor.org/rfc/rfc\"+o+\".json\";try{const e=await fetch(t);a=await e.json()}catch(e){t=document.URL.indexOf(\"html\")>=0?document.URL.replace(/html$/,\"json\"):document.URL+\".json\";const o=await fetch(t);a=await o.json()}}if(!a)return;e.style.display=\"block\";const s=\"\",d=\"https://datatracker.ietf.org/doc\",n=\"https://datatracker.ietf.org/ipr/search\",c=\"https://www.rfc-editor.org/info\",l=a.doc_id.toLowerCase(),i=a.doc_id.slice(0,3).toLowerCase(),f=a.doc_id.slice(3).replace(/^0+/,\"\"),u={status:\"Status\",obsoletes:\"Obsoletes\",obsoleted_by:\"Obsoleted By\",updates:\"Updates\",updated_by:\"Updated By\",see_also:\"See Also\",errata_url:\"Errata\"};let h=\"<dl style='overflow:hidden' id='external-updates'>\";[\"status\",\"obsoletes\",\"obsoleted_by\",\"updates\",\"updated_by\",\"see_also\",\"errata_url\"].forEach(e=>{if(\"status\"==e){a[e]=a[e].toLowerCase();var t=a[e].split(\" \"),o=t.length,w=\"\",p=1;for(let e=0;e<o;e++)p<o?w=w+r(t[e])+\" \":w+=r(t[e]),p++;a[e]=w}else if(\"obsoletes\"==e||\"obsoleted_by\"==e||\"updates\"==e||\"updated_by\"==e){var g,m=\"\",b=1;g=a[e].length;for(let t=0;t<g;t++)a[e][t]&&(a[e][t]=String(a[e][t]).toLowerCase(),m=b<g?m+\"<a href='\"+s+\"/rfc/\".concat(a[e][t])+\"'>\"+a[e][t].slice(3)+\"</a>, \":m+\"<a href='\"+s+\"/rfc/\".concat(a[e][t])+\"'>\"+a[e][t].slice(3)+\"</a>\",b++);a[e]=m}else if(\"see_also\"==e){var y,L=\"\",C=1;y=a[e].length;for(let t=0;t<y;t++)if(a[e][t]){a[e][t]=String(a[e][t]);var _=a[e][t].slice(0,3),v=a[e][t].slice(3).replace(/^0+/,\"\");L=C<y?\"RFC\"!=_?L+\"<a href='\"+s+\"/info/\"+_.toLowerCase().concat(v.toLowerCase())+\"'>\"+_+\" \"+v+\"</a>, \":L+\"<a href='\"+s+\"/info/\"+_.toLowerCase().concat(v.toLowerCase())+\"'>\"+v+\"</a>, \":\"RFC\"!=_?L+\"<a href='\"+s+\"/info/\"+_.toLowerCase().concat(v.toLowerCase())+\"'>\"+_+\" \"+v+\"</a>\":L+\"<a href='\"+s+\"/info/\"+_.toLowerCase().concat(v.toLowerCase())+\"'>\"+v+\"</a>\",C++}a[e]=L}else if(\"errata_url\"==e){var R=\"\";R=a[e]?R+\"<a href='\"+a[e]+\"'>Errata exist</a> | <a href='\"+d+\"/\"+l+\"'>Datatracker</a>| <a href='\"+n+\"/?\"+i+\"=\"+f+\"&submit=\"+i+\"'>IPR</a> | <a href='\"+c+\"/\"+l+\"'>Info page</a>\":\"<a href='\"+d+\"/\"+l+\"'>Datatracker</a> | <a href='\"+n+\"/?\"+i+\"=\"+f+\"&submit=\"+i+\"'>IPR</a> | <a href='\"+c+\"/\"+l+\"'>Info page</a>\",a[e]=R}\"\"!=a[e]?\"Errata\"==u[e]?h+=`<dt>More info:</dt><dd>${a[e]}</dd>`:h+=`<dt>${u[e]}:</dt><dd>${a[e]}</dd>`:\"Errata\"==u[e]&&(h+=`<dt>More info:</dt><dd>${a[e]}</dd>`)}),h+=\"</dl>\",e.innerHTML=h}catch(e){console.log(e)}else console.log(\"Could not locate metadata <div> element\");function r(e){return e.charAt(0).toUpperCase()+e.slice(1)}}window.removeEventListener(\"load\",addMetadata),window.addEventListener(\"load\",addMetadata);</script>\n</head>\n<body class=\"xml2rfc\">\n<table class=\"ears\">\n<thead><tr>\n<td class=\"left\">Internet-Draft</td>\n<td class=\"center\">AIDIP</td>\n<td class=\"right\">February 2026</td>\n</tr></thead>\n<tfoot><tr>\n<td class=\"left\">Cui, et al.</td>\n<td class=\"center\">Expires 16 August 2026</td>\n<td class=\"right\">[Page]</td>\n</tr></tfoot>\n</table>\n<div id=\"external-metadata\" class=\"document-information\"></div>\n<div id=\"internal-metadata\" class=\"document-information\">\n<dl id=\"identifiers\">\n<dt class=\"label-workgroup\">Workgroup:</dt>\n<dd class=\"workgroup\">Network Working Group</dd>\n<dt class=\"label-internet-draft\">Internet-Draft:</dt>\n<dd class=\"internet-draft\">draft-cui-ai-agent-discovery-invocation-01</dd>\n<dt class=\"label-published\">Published:</dt>\n<dd class=\"published\">\n<time datetime=\"2026-02-12\" class=\"published\">12 February 2026</time>\n    </dd>\n<dt class=\"label-intended-status\">Intended Status:</dt>\n<dd class=\"intended-status\">Informational</dd>\n<dt class=\"label-expires\">Expires:</dt>\n<dd class=\"expires\"><time datetime=\"2026-08-16\">16 August 2026</time></dd>\n<dt class=\"label-authors\">Authors:</dt>\n<dd class=\"authors\">\n<div class=\"author\">\n      <div class=\"author-name\">Y. Cui</div>\n<div class=\"org\">Tsinghua University</div>\n</div>\n<div class=\"author\">\n      <div class=\"author-name\">Y. Chao</div>\n<div class=\"org\">Zhongguancun Laboratory</div>\n</div>\n<div class=\"author\">\n      <div class=\"author-name\">C. Du</div>\n<div class=\"org\">Zhongguancun Laboratory</div>\n</div>\n</dd>\n</dl>\n</div>\n<h1 id=\"title\">AI Agent Discovery and Invocation Protocol</h1>\n<section id=\"section-abstract\">\n      <h2 id=\"abstract\"><a href=\"#abstract\" class=\"selfRef\">Abstract</a></h2>\n<p id=\"section-abstract-1\">This document proposes a standardized protocol for discovery and invocation of AI agents. It defines a common metadata format for describing AI agents (including capabilities, I/O specifications, supported languages, tags, authentication methods, etc.), a capability-based discovery mechanism, and a unified RESTful invocation interface.<a href=\"#section-abstract-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-abstract-2\">This revision additionally specifies an optional extension that enables intent-based agent selection prior to discovery and invocation, without changing existing discovery or invocation semantics.<a href=\"#section-abstract-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-abstract-3\">The goal is to enable cross-platform interoperability among AI agents by providing a discover-and-match mechanism and a unified invocation entry point. Security considerations, including authentication and trust measures, are also discussed. This specification aims to facilitate the formation of multi-agent systems by making it easy to find the right agent for a task and invoke it in a consistent manner across different vendors and platforms.<a href=\"#section-abstract-3\" class=\"pilcrow\">¶</a></p>\n</section>\n<section class=\"note rfcEditorRemove\" id=\"section-note.1\">\n      <h2 id=\"name-about-this-document\">\n<a href=\"#name-about-this-document\" class=\"section-name selfRef\">About This Document</a>\n      </h2>\n<p id=\"section-note.1-1\">This note is to be removed before publishing as an RFC.<a href=\"#section-note.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-note.1-2\">\n        The latest revision of this draft can be found at <span><a href=\"https://example.com/LATEST\">https://example.com/LATEST</a></span>.\n        Status information for this document may be found at <span><a href=\"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/\">https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/</a></span>.<a href=\"#section-note.1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-note.1-3\">\n        Discussion of this document takes place on the\n        WG Working Group mailing list (<span><a href=\"mailto:WG@example.com\">mailto:WG@example.com</a></span>),\n        which is archived at <span><a href=\"https://example.com/WG\">https://example.com/WG</a></span>.<a href=\"#section-note.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-note.1-4\">Source for this draft and an issue tracker can be found at\n        <span><a href=\"https://github.com/USER/REPO\">https://github.com/USER/REPO</a></span>.<a href=\"#section-note.1-4\" class=\"pilcrow\">¶</a></p>\n</section>\n<div id=\"status-of-memo\">\n<section id=\"section-boilerplate.1\">\n        <h2 id=\"name-status-of-this-memo\">\n<a href=\"#name-status-of-this-memo\" class=\"section-name selfRef\">Status of This Memo</a>\n        </h2>\n<p id=\"section-boilerplate.1-1\">\n        This Internet-Draft is submitted in full conformance with the\n        provisions of BCP 78 and BCP 79.<a href=\"#section-boilerplate.1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-2\">\n        Internet-Drafts are working documents of the Internet Engineering Task\n        Force (IETF). Note that other groups may also distribute working\n        documents as Internet-Drafts. The list of current Internet-Drafts is\n        at <span><a href=\"https://datatracker.ietf.org/drafts/current/\">https://datatracker.ietf.org/drafts/current/</a></span>.<a href=\"#section-boilerplate.1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-3\">\n        Internet-Drafts are draft documents valid for a maximum of six months\n        and may be updated, replaced, or obsoleted by other documents at any\n        time. It is inappropriate to use Internet-Drafts as reference\n        material or to cite them other than as \"work in progress.\"<a href=\"#section-boilerplate.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.1-4\">\n        This Internet-Draft will expire on 16 August 2026.<a href=\"#section-boilerplate.1-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"copyright\">\n<section id=\"section-boilerplate.2\">\n        <h2 id=\"name-copyright-notice\">\n<a href=\"#name-copyright-notice\" class=\"section-name selfRef\">Copyright Notice</a>\n        </h2>\n<p id=\"section-boilerplate.2-1\">\n            Copyright (c) 2026 IETF Trust and the persons identified as the\n            document authors. All rights reserved.<a href=\"#section-boilerplate.2-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-boilerplate.2-2\">\n            This document is subject to BCP 78 and the IETF Trust's Legal\n            Provisions Relating to IETF Documents\n            (<span><a href=\"https://trustee.ietf.org/license-info\">https://trustee.ietf.org/license-info</a></span>) in effect on the date of\n            publication of this document. Please review these documents\n            carefully, as they describe your rights and restrictions with\n            respect to this document. Code Components extracted from this\n            document must include Revised BSD License text as described in\n            Section 4.e of the Trust Legal Provisions and are provided without\n            warranty as described in the Revised BSD License.<a href=\"#section-boilerplate.2-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"toc\">\n<section id=\"section-toc.1\">\n        <a href=\"#\" onclick=\"scroll(0,0)\" class=\"toplink\">▲</a><h2 id=\"name-table-of-contents\">\n<a href=\"#name-table-of-contents\" class=\"section-name selfRef\">Table of Contents</a>\n        </h2>\n<nav class=\"toc\"><ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.1\">\n            <p id=\"section-toc.1-1.1.1\" class=\"keepWithNext\"><a href=\"#section-1\" class=\"auto internal xref\">1</a>.  <a href=\"#name-introduction\" class=\"internal xref\">Introduction</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.2\">\n            <p id=\"section-toc.1-1.2.1\" class=\"keepWithNext\"><a href=\"#section-2\" class=\"auto internal xref\">2</a>.  <a href=\"#name-conventions-and-definitions\" class=\"internal xref\">Conventions and Definitions</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.3\">\n            <p id=\"section-toc.1-1.3.1\"><a href=\"#section-3\" class=\"auto internal xref\">3</a>.  <a href=\"#name-agent-metadata-specificatio\" class=\"internal xref\">Agent Metadata Specification</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.3.2.1\">\n                <p id=\"section-toc.1-1.3.2.1.1\" class=\"keepWithNext\"><a href=\"#section-3.1\" class=\"auto internal xref\">3.1</a>.  <a href=\"#name-core-fields\" class=\"internal xref\">Core Fields</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.3.2.2\">\n                <p id=\"section-toc.1-1.3.2.2.1\"><a href=\"#section-3.2\" class=\"auto internal xref\">3.2</a>.  <a href=\"#name-operations-and-i-o-schema\" class=\"internal xref\">Operations and I/O Schema</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.3.2.3\">\n                <p id=\"section-toc.1-1.3.2.3.1\"><a href=\"#section-3.3\" class=\"auto internal xref\">3.3</a>.  <a href=\"#name-example-agent-metadata\" class=\"internal xref\">Example Agent Metadata</a></p>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4\">\n            <p id=\"section-toc.1-1.4.1\"><a href=\"#section-4\" class=\"auto internal xref\">4</a>.  <a href=\"#name-agent-discovery-mechanism\" class=\"internal xref\">Agent Discovery Mechanism</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.1\">\n                <p id=\"section-toc.1-1.4.2.1.1\"><a href=\"#section-4.1\" class=\"auto internal xref\">4.1</a>.  <a href=\"#name-registry-overview\" class=\"internal xref\">Registry Overview</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.2\">\n                <p id=\"section-toc.1-1.4.2.2.1\"><a href=\"#section-4.2\" class=\"auto internal xref\">4.2</a>.  <a href=\"#name-agent-registration\" class=\"internal xref\">Agent Registration</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.3\">\n                <p id=\"section-toc.1-1.4.2.3.1\"><a href=\"#section-4.3\" class=\"auto internal xref\">4.3</a>.  <a href=\"#name-querying-agents\" class=\"internal xref\">Querying Agents</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.3.2.1\">\n                    <p id=\"section-toc.1-1.4.2.3.2.1.1\"><a href=\"#section-4.3.1\" class=\"auto internal xref\">4.3.1</a>.  <a href=\"#name-attribute-based-query-filte\" class=\"internal xref\">Attribute-Based Query (Filter)</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.3.2.2\">\n                    <p id=\"section-toc.1-1.4.2.3.2.2.1\"><a href=\"#section-4.3.2\" class=\"auto internal xref\">4.3.2</a>.  <a href=\"#name-semantic-query-natural-lang\" class=\"internal xref\">Semantic Query (Natural Language Search)</a></p>\n</li>\n                  <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.4.2.3.2.3\">\n                    <p id=\"section-toc.1-1.4.2.3.2.3.1\"><a href=\"#section-4.3.3\" class=\"auto internal xref\">4.3.3</a>.  <a href=\"#name-retrieve-single-agent\" class=\"internal xref\">Retrieve Single Agent</a></p>\n</li>\n                </ul>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.5\">\n            <p id=\"section-toc.1-1.5.1\"><a href=\"#section-5\" class=\"auto internal xref\">5</a>.  <a href=\"#name-agent-invocation\" class=\"internal xref\">Agent Invocation</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.5.2.1\">\n                <p id=\"section-toc.1-1.5.2.1.1\"><a href=\"#section-5.1\" class=\"auto internal xref\">5.1</a>.  <a href=\"#name-invocation-request\" class=\"internal xref\">Invocation Request</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.5.2.2\">\n                <p id=\"section-toc.1-1.5.2.2.1\"><a href=\"#section-5.2\" class=\"auto internal xref\">5.2</a>.  <a href=\"#name-invocation-response\" class=\"internal xref\">Invocation Response</a></p>\n</li>\n              <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.5.2.3\">\n                <p id=\"section-toc.1-1.5.2.3.1\"><a href=\"#section-5.3\" class=\"auto internal xref\">5.3</a>.  <a href=\"#name-additional-considerations-f\" class=\"internal xref\">Additional Considerations for Invocation</a></p>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.6\">\n            <p id=\"section-toc.1-1.6.1\"><a href=\"#section-6\" class=\"auto internal xref\">6</a>.  <a href=\"#name-agent-semantic-resolution\" class=\"internal xref\">Agent Semantic Resolution</a></p>\n<ul class=\"compact toc ulBare ulEmpty\">\n<li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.6.2.1\">\n                <p id=\"section-toc.1-1.6.2.1.1\"><a href=\"#section-6.1\" class=\"auto internal xref\">6.1</a>.  <a href=\"#name-non-goals\" class=\"internal xref\">Non-Goals</a></p>\n</li>\n            </ul>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.7\">\n            <p id=\"section-toc.1-1.7.1\"><a href=\"#section-7\" class=\"auto internal xref\">7</a>.  <a href=\"#name-semantic-routing-platform\" class=\"internal xref\">Semantic Routing Platform</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.8\">\n            <p id=\"section-toc.1-1.8.1\"><a href=\"#section-8\" class=\"auto internal xref\">8</a>.  <a href=\"#name-backward-compatibility\" class=\"internal xref\">Backward Compatibility</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.9\">\n            <p id=\"section-toc.1-1.9.1\"><a href=\"#section-9\" class=\"auto internal xref\">9</a>.  <a href=\"#name-security-considerations\" class=\"internal xref\">Security Considerations</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.10\">\n            <p id=\"section-toc.1-1.10.1\"><a href=\"#section-10\" class=\"auto internal xref\">10</a>. <a href=\"#name-example-interaction-flow\" class=\"internal xref\">Example Interaction Flow</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.11\">\n            <p id=\"section-toc.1-1.11.1\"><a href=\"#section-11\" class=\"auto internal xref\">11</a>. <a href=\"#name-iana-considerations\" class=\"internal xref\">IANA Considerations</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.12\">\n            <p id=\"section-toc.1-1.12.1\"><a href=\"#section-12\" class=\"auto internal xref\">12</a>. <a href=\"#name-normative-references\" class=\"internal xref\">Normative References</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.13\">\n            <p id=\"section-toc.1-1.13.1\"><a href=\"#appendix-A\" class=\"auto internal xref\"></a><a href=\"#name-acknowledgments\" class=\"internal xref\">Acknowledgments</a></p>\n</li>\n          <li class=\"compact toc ulBare ulEmpty\" id=\"section-toc.1-1.14\">\n            <p id=\"section-toc.1-1.14.1\"><a href=\"#appendix-B\" class=\"auto internal xref\"></a><a href=\"#name-authors-addresses\" class=\"internal xref\">Authors' Addresses</a></p>\n</li>\n        </ul>\n</nav>\n</section>\n</div>\n<div id=\"introduction\">\n<section id=\"section-1\">\n      <h2 id=\"name-introduction\">\n<a href=\"#section-1\" class=\"section-number selfRef\">1. </a><a href=\"#name-introduction\" class=\"section-name selfRef\">Introduction</a>\n      </h2>\n<p id=\"section-1-1\">As artificial intelligence technologies advance rapidly, AI agents—autonomous software components capable of perceiving their environment, reasoning, and taking actions to achieve goals—have emerged as a powerful paradigm for task execution. Today, many organizations develop specialized AI agents for various purposes: from text translation and summarization, to code generation, to data analysis and beyond. These agents are often offered as services, accessible over the network and may be integrated into larger systems. However, despite the proliferation of AI agents, there is currently no standard protocol for discovering available agents and invoking their capabilities in a uniform way.<a href=\"#section-1-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-1-2\">Existing agent frameworks and platforms facilitate building agents but typically operate in isolated ecosystems, making cross-platform or cross-organization agent interoperability difficult. Each platform tends to define its own APIs for agent description and invocation, which means a client wishing to use agents from multiple sources must adapt to disparate interfaces. This lack of standardization creates friction, increases integration costs, and hampers the development of multi-agent collaborative systems.<a href=\"#section-1-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-1-3\">This document addresses these issues by proposing a standardized AI Agent Discovery and Invocation Protocol. The protocol provides:<a href=\"#section-1-3\" class=\"pilcrow\">¶</a></p>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-1-4\">\n<li id=\"section-1-4.1\">\n          <p id=\"section-1-4.1.1\"><strong>Agent Metadata Specification:</strong> A structured JSON Schema for describing an agent's identity, capabilities, inputs, outputs, authentication requirements, and other attributes. This enables agents to publish their specifications in a machine-readable form.<a href=\"#section-1-4.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-1-4.2\">\n          <p id=\"section-1-4.2.1\"><strong>Discovery Mechanism:</strong> A registry-based approach where agents register themselves and clients can search for agents by capability, tags, or semantic queries. The registry is language and platform agnostic, facilitating cross-platform discovery.<a href=\"#section-1-4.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-1-4.3\">\n          <p id=\"section-1-4.3.1\"><strong>Invocation Interface:</strong> A RESTful API that enables a client (which could be a human user application, another agent, or an orchestration system) to invoke an agent's capabilities through a standard endpoint and JSON payloads.<a href=\"#section-1-4.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-1-4.4\">\n          <p id=\"section-1-4.4.1\"><strong>Security Considerations:</strong> Guidelines for authentication, authorization, encrypted transport (TLS), and trust establishment, ensuring that discovery and invocation happen securely.<a href=\"#section-1-4.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-1-4.5\">\n          <p id=\"section-1-4.5.1\"><strong>Interoperability with Existing Standards:</strong> This specification references existing standards such as JSON Schema, OAuth 2.0 <span>[<a href=\"#RFC6749\" class=\"cite xref\">RFC6749</a>]</span>, and OpenAPI concepts, and leverages established web technologies for broad compatibility.<a href=\"#section-1-4.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ol>\n<p id=\"section-1-5\">The primary audience for this specification includes developers of AI agent platforms, providers of AI agent services, and system architects building AI-enabled applications or multi-agent systems. By adopting this protocol, an AI agent developer can make their agent accessible to a wide ecosystem, and a client application can integrate AI agents from multiple vendors without custom integration for each.<a href=\"#section-1-5\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-1-6\">This revision extends the base protocol with an optional Agent Semantic Resolution layer that enables intent-based agent selection. This extension allows a Host Agent or coordinator to describe a task intent and receive candidate agents without predetermining which agent to invoke. ASR does not replace discovery; it adds a semantic matching phase that can precede or augment the capability-based search defined in earlier sections.<a href=\"#section-1-6\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"conventions-and-definitions\">\n<section id=\"section-2\">\n      <h2 id=\"name-conventions-and-definitions\">\n<a href=\"#section-2\" class=\"section-number selfRef\">2. </a><a href=\"#name-conventions-and-definitions\" class=\"section-name selfRef\">Conventions and Definitions</a>\n      </h2>\n<p id=\"section-2-1\">The key words \"<span class=\"bcp14\">MUST</span>\", \"<span class=\"bcp14\">MUST NOT</span>\", \"<span class=\"bcp14\">REQUIRED</span>\", \"<span class=\"bcp14\">SHALL</span>\", \"<span class=\"bcp14\">SHALL NOT</span>\", \"<span class=\"bcp14\">SHOULD</span>\", \"<span class=\"bcp14\">SHOULD NOT</span>\", \"<span class=\"bcp14\">RECOMMENDED</span>\", \"<span class=\"bcp14\">NOT RECOMMENDED</span>\",\n\"<span class=\"bcp14\">MAY</span>\", and \"<span class=\"bcp14\">OPTIONAL</span>\" in this document are to be interpreted as\ndescribed in BCP 14 <span>[<a href=\"#RFC2119\" class=\"cite xref\">RFC2119</a>]</span> <span>[<a href=\"#RFC8174\" class=\"cite xref\">RFC8174</a>]</span> when, and only when, they\nappear in all capitals, as shown here.<a href=\"#section-2-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-2-2.1\">\n          <p id=\"section-2-2.1.1\"><strong>AI Agent:</strong> An autonomous software component that can perform tasks using artificial intelligence capabilities. Agents may wrap language models, specialized ML models, or reasoning engines, exposing their abilities via defined interfaces.<a href=\"#section-2-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.2\">\n          <p id=\"section-2-2.2.1\"><strong>Agent Metadata:</strong> A structured description of an agent, including name, description, capabilities, input/output schemas, authentication requirements, and endpoint information.<a href=\"#section-2-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.3\">\n          <p id=\"section-2-2.3.1\"><strong>Agent Registry (Discovery Service):</strong> A service that maintains a directory of registered agents and supports queries for discovering agents by attributes or semantic search.<a href=\"#section-2-2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.4\">\n          <p id=\"section-2-2.4.1\"><strong>Gateway:</strong> (Optional) An intermediary service that routes client requests to appropriate agents. In some deployments, the registry or another service acts as a gateway to simplify client-to-agent connections.<a href=\"#section-2-2.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.5\">\n          <p id=\"section-2-2.5.1\"><strong>Invocation Endpoint:</strong> The URL provided by an agent (or gateway) where clients send requests to invoke the agent's capabilities.<a href=\"#section-2-2.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.6\">\n          <p id=\"section-2-2.6.1\"><strong>Capability:</strong> A high-level function an agent can perform, identified by a string (e.g., \"translation\", \"summarization\", \"image_classification\").<a href=\"#section-2-2.6.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li class=\"normal\" id=\"section-2-2.7\">\n          <p id=\"section-2-2.7.1\"><strong>Operation:</strong> A specific action supported by an agent. Some agents may have multiple operations; for example, an agent offering both translation and language detection could list these as separate operations, each with its own input/output schema.<a href=\"#section-2-2.7.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ul>\n</section>\n</div>\n<div id=\"agent-metadata-specification\">\n<section id=\"section-3\">\n      <h2 id=\"name-agent-metadata-specificatio\">\n<a href=\"#section-3\" class=\"section-number selfRef\">3. </a><a href=\"#name-agent-metadata-specificatio\" class=\"section-name selfRef\">Agent Metadata Specification</a>\n      </h2>\n<p id=\"section-3-1\">The Agent Metadata Specification defines a standard JSON document that describes an agent. All agents that wish to be discoverable and invocable through this protocol <span class=\"bcp14\">MUST</span> provide a metadata document conforming to the schema below. This metadata is used for agent registration and returned to clients during discovery.<a href=\"#section-3-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"core-fields\">\n<section id=\"section-3.1\">\n        <h3 id=\"name-core-fields\">\n<a href=\"#section-3.1\" class=\"section-number selfRef\">3.1. </a><a href=\"#name-core-fields\" class=\"section-name selfRef\">Core Fields</a>\n        </h3>\n<p id=\"section-3.1-1\">The following are the core fields of an agent metadata document:<a href=\"#section-3.1-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-3.1-2.1\">\n            <p id=\"section-3.1-2.1.1\"><strong>id (string):</strong> A globally unique identifier for the agent. This could be a UUID or a similarly unique value, assigned by the registry upon registration or by the agent provider in advance. This ID is used to refer to the agent in all subsequent operations (e.g., retrieval, invocation routing).<a href=\"#section-3.1-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.2\">\n            <p id=\"section-3.1-2.2.1\"><strong>name (string):</strong> A human-readable name for the agent (e.g., \"Chinese-English Translator Agent\"). Names need not be unique but should be descriptive.<a href=\"#section-3.1-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.3\">\n            <p id=\"section-3.1-2.3.1\"><strong>description (string):</strong> A detailed description of the agent, its purpose, and capabilities in natural language. This helps both human users and semantic search algorithms understand what the agent does.<a href=\"#section-3.1-2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.4\">\n            <p id=\"section-3.1-2.4.1\"><strong>version (string):</strong> The version of the agent or its metadata (e.g., \"1.0.0\"). This allows tracking of agent updates over time.<a href=\"#section-3.1-2.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.5\">\n            <p id=\"section-3.1-2.5.1\"><strong>publisher (string):</strong> The name or identifier of the entity publishing the agent (e.g., an organization name or developer name).<a href=\"#section-3.1-2.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.6\">\n            <p id=\"section-3.1-2.6.1\"><strong>capabilities (array of strings):</strong> A list of capabilities the agent supports. Capabilities are high-level descriptors (like tags or categories) that clients can filter by. Examples: <code>[\"translation\", \"summarization\", \"text_generation\"]</code>.<a href=\"#section-3.1-2.6.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.7\">\n            <p id=\"section-3.1-2.7.1\"><strong>tags (array of strings):</strong> Additional tags for search and categorization (e.g., <code>[\"nlp\", \"chinese\", \"transformer_model\", \"cloud\"]</code>). Tags differ from capabilities in that they can include broader or orthogonal categories (like domain, language support, deployment model, etc.).<a href=\"#section-3.1-2.7.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.8\">\n            <p id=\"section-3.1-2.8.1\"><strong>endpoint (string):</strong> The URL of the agent's invocation endpoint. If the agent is behind a gateway, this could be either the direct endpoint or, if direct access is not allowed, a gateway path (e.g., the gateway might provide a unified endpoint like <code>/agents/{id}/invoke</code> and internally route to the actual agent endpoint).<a href=\"#section-3.1-2.8.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.9\">\n            <p id=\"section-3.1-2.9.1\"><strong>supported_languages (array of strings, optional):</strong> A list of languages the agent supports (e.g., <code>[\"en\", \"zh\", \"fr\"]</code>). For agents dealing with natural language tasks, this field indicates which languages are handled. If omitted, the agent is either language-agnostic or should not be filtered by language.<a href=\"#section-3.1-2.9.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.10\">\n            <p id=\"section-3.1-2.10.1\"><strong>authentication (object, optional):</strong> Describes the authentication mechanism required to invoke the agent. This object may include:<a href=\"#section-3.1-2.10.1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-3.1-2.10.2.1\">\n                <p id=\"section-3.1-2.10.2.1.1\"><strong>type (string):</strong> e.g., \"api_key\", \"oauth2_bearer\", \"mtls\" (mutual TLS), \"none\".<a href=\"#section-3.1-2.10.2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.1-2.10.2.2\">\n                <p id=\"section-3.1-2.10.2.2.1\"><strong>instructions (string):</strong> Human-readable note or URL for obtaining credentials.<a href=\"#section-3.1-2.10.2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.1-2.10.2.3\">\n                <p id=\"section-3.1-2.10.2.3.1\"><strong>scopes (array of strings):</strong> If OAuth 2.0 is used, the OAuth scopes required.<a href=\"#section-3.1-2.10.2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            </ul>\n<p id=\"section-3.1-2.10.3\">\nIf no authentication is required, this field can be omitted or set with <code>type: \"none\"</code>.<a href=\"#section-3.1-2.10.3\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.11\">\n            <p id=\"section-3.1-2.11.1\"><strong>status (string, optional):</strong> Operational status of the agent (e.g., <code>\"active\"</code>, <code>\"inactive\"</code>, <code>\"deprecated\"</code>). The registry may use this to filter out agents that are not currently available.<a href=\"#section-3.1-2.11.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-3.1-2.12\">\n            <p id=\"section-3.1-2.12.1\"><strong>additional fields:</strong> Additional fields may include metadata about rate limits (e.g., max calls per minute), pricing info (if the agent charges per use), or links to documentation. These are not standardized here but can be included in agent metadata as needed.<a href=\"#section-3.1-2.12.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n</section>\n</div>\n<div id=\"operations-and-io-schema\">\n<section id=\"section-3.2\">\n        <h3 id=\"name-operations-and-i-o-schema\">\n<a href=\"#section-3.2\" class=\"section-number selfRef\">3.2. </a><a href=\"#name-operations-and-i-o-schema\" class=\"section-name selfRef\">Operations and I/O Schema</a>\n        </h3>\n<p id=\"section-3.2-1\">Each agent <span class=\"bcp14\">MUST</span> describe its input and output formats. This is done using the <strong>operations</strong> field:<a href=\"#section-3.2-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-3.2-2.1\">\n            <p id=\"section-3.2-2.1.1\"><strong>operations (array of objects):</strong> A list of operations the agent supports. Each operation object has:<a href=\"#section-3.2-2.1.1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-3.2-2.1.2.1\">\n                <p id=\"section-3.2-2.1.2.1.1\"><strong>name (string):</strong> The operation name/identifier (e.g., \"translateText\", \"summarize\").<a href=\"#section-3.2-2.1.2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.2-2.1.2.2\">\n                <p id=\"section-3.2-2.1.2.2.1\"><strong>description (string):</strong> A description of what the operation does.<a href=\"#section-3.2-2.1.2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.2-2.1.2.3\">\n                <p id=\"section-3.2-2.1.2.3.1\"><strong>inputs (object):</strong> A JSON Schema describing the expected input. This allows clients to understand what data to send. The JSON Schema can specify required fields, types, enums, etc.<a href=\"#section-3.2-2.1.2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.2-2.1.2.4\">\n                <p id=\"section-3.2-2.1.2.4.1\"><strong>outputs (object):</strong> A JSON Schema describing the output format.<a href=\"#section-3.2-2.1.2.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-3.2-2.1.2.5\">\n                <p id=\"section-3.2-2.1.2.5.1\"><strong>examples (array of objects, optional):</strong> Example input/output pairs. Each example is an object <code>{\"input\": {...}, \"output\": {...}}</code> showing a sample invocation.<a href=\"#section-3.2-2.1.2.5.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            </ul>\n</li>\n        </ul>\n<p id=\"section-3.2-3\">If an agent has a single operation, this array will have one element. If it can do multiple distinct tasks, each is listed here. Some agents may not have structured operations (e.g., a general-purpose language model that just produces text). In that case, the operations field might include a generic operation like <code>{\"name\": \"generate\", ...}</code>.<a href=\"#section-3.2-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-3.2-4\">If an agent has a single operation, this array will have one element. If it can do multiple distinct tasks, each is listed here. For simple agents with one primary function, an alternative is to use top-level <code>inputs</code> and <code>outputs</code> fields directly (instead of an operations array). In that case, the whole agent effectively has one implied operation. This spec allows both styles, but using <code>operations</code> is recommended for future extensibility.<a href=\"#section-3.2-4\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"example-agent-metadata\">\n<section id=\"section-3.3\">\n        <h3 id=\"name-example-agent-metadata\">\n<a href=\"#section-3.3\" class=\"section-number selfRef\">3.3. </a><a href=\"#name-example-agent-metadata\" class=\"section-name selfRef\">Example Agent Metadata</a>\n        </h3>\n<p id=\"section-3.3-1\">Below is an example metadata JSON for a translation agent:<a href=\"#section-3.3-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-3.3-2\"><code>json\n{\n  \"id\": \"agent-12345\",\n  \"name\": \"Chinese-English Translator\",\n  \"description\": \"Translates text between Chinese and English with high accuracy using a fine-tuned model.\",\n  \"version\": \"1.2.0\",\n  \"publisher\": \"ExampleAI Inc.\",\n  \"capabilities\": [\"translation\"],\n  \"tags\": [\"nlp\", \"chinese\", \"english\", \"cloud\"],\n  \"endpoint\": \"https://api.example.com/agents/translate\",\n  \"supported_languages\": [\"en\", \"zh\"],\n  \"authentication\": {\n    \"type\": \"api_key\",\n    \"instructions\": \"Include 'X-API-Key' header with your API key.\"\n  },\n  \"status\": \"active\",\n  \"operations\": [\n    {\n      \"name\": \"translateText\",\n      \"description\": \"Translates text from source language to target language.\",\n      \"inputs\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"text\": {\"type\": \"string\"},\n          \"source_language\": {\"type\": \"string\", \"enum\": [\"en\", \"zh\"]},\n          \"target_language\": {\"type\": \"string\", \"enum\": [\"en\", \"zh\"]}\n        },\n        \"required\": [\"text\", \"source_language\", \"target_language\"]\n      },\n      \"outputs\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"translated_text\": {\"type\": \"string\"}\n        }\n      },\n      \"examples\": [\n        {\n          \"input\": {\"text\": \"你好世界\", \"source_language\": \"zh\", \"target_language\": \"en\"},\n          \"output\": {\"translated_text\": \"Hello World\"}\n        }\n      ]\n    }\n  ]\n}\n</code><a href=\"#section-3.3-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-3.3-3\">This metadata tells us the agent is an active translation agent for Chinese and English, requires an API key for authentication, and has one operation <code>translateText</code> with a clear input/output schema.<a href=\"#section-3.3-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n</section>\n</div>\n<div id=\"agent-discovery-mechanism\">\n<section id=\"section-4\">\n      <h2 id=\"name-agent-discovery-mechanism\">\n<a href=\"#section-4\" class=\"section-number selfRef\">4. </a><a href=\"#name-agent-discovery-mechanism\" class=\"section-name selfRef\">Agent Discovery Mechanism</a>\n      </h2>\n<p id=\"section-4-1\">The discovery mechanism allows clients to find agents that meet certain criteria. Discovery is provided by an Agent Registry (or Discovery Service) that aggregates metadata from multiple agents.<a href=\"#section-4-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"registry-overview\">\n<section id=\"section-4.1\">\n        <h3 id=\"name-registry-overview\">\n<a href=\"#section-4.1\" class=\"section-number selfRef\">4.1. </a><a href=\"#name-registry-overview\" class=\"section-name selfRef\">Registry Overview</a>\n        </h3>\n<p id=\"section-4.1-1\">The Agent Registry is a network-accessible service that:<a href=\"#section-4.1-1\" class=\"pilcrow\">¶</a></p>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-4.1-2\">\n<li id=\"section-4.1-2.1\">\n            <p id=\"section-4.1-2.1.1\">Allows agents (or their administrators) to register metadata about the agent.<a href=\"#section-4.1-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li id=\"section-4.1-2.2\">\n            <p id=\"section-4.1-2.2.1\">Stores and indexes these metadata entries for efficient search.<a href=\"#section-4.1-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li id=\"section-4.1-2.3\">\n            <p id=\"section-4.1-2.3.1\">Provides endpoints for clients to query and retrieve agent information.<a href=\"#section-4.1-2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ol>\n<p id=\"section-4.1-3\">A registry may be operated by an organization for its internal agents, or by a third party acting as a directory of agents across multiple providers. Multiple registries can coexist; interoperability between registries is facilitated by consistent metadata formats, though formal registry federation is out of scope for this draft.<a href=\"#section-4.1-3\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"agent-registration\">\n<section id=\"section-4.2\">\n        <h3 id=\"name-agent-registration\">\n<a href=\"#section-4.2\" class=\"section-number selfRef\">4.2. </a><a href=\"#name-agent-registration\" class=\"section-name selfRef\">Agent Registration</a>\n        </h3>\n<p id=\"section-4.2-1\">An agent (or its administrator) registers with the registry by sending its metadata to a registration endpoint:<a href=\"#section-4.2-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4.2-2.1\">\n            <p id=\"section-4.2-2.1.1\"><strong>Endpoint:</strong> <code>POST /agents</code><a href=\"#section-4.2-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-4.2-2.2\">\n            <p id=\"section-4.2-2.2.1\"><strong>Request Body:</strong> The agent metadata JSON document.<a href=\"#section-4.2-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-4.2-2.3\">\n            <p id=\"section-4.2-2.3.1\"><strong>Response:</strong> On success, the registry returns <strong>201 Created</strong> (if a new agent was added) or <strong>200 OK</strong> (if an existing agent was updated), with the stored agent metadata (including the assigned <code>id</code> if the agent did not provide one). If validation fails (e.g., missing required fields), the registry returns a <strong>400 Bad Request</strong> with error details.<a href=\"#section-4.2-2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n<p id=\"section-4.2-3\">The registry <span class=\"bcp14\">MUST</span> validate the metadata against the schema. Registration may require authentication (for example, the registry only allows verified publishers to register agents).<a href=\"#section-4.2-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.2-4\">Updates to an agent's metadata (e.g., a new version, changed endpoint, etc.) can be done via a PUT request to the agent's entry:<a href=\"#section-4.2-4\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4.2-5.1\">\n            <p id=\"section-4.2-5.1.1\"><strong>Endpoint:</strong> <code>PUT /agents/{id}</code><a href=\"#section-4.2-5.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-4.2-5.2\">\n            <p id=\"section-4.2-5.2.1\"><strong>Request Body:</strong> Updated metadata.<a href=\"#section-4.2-5.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-4.2-5.3\">\n            <p id=\"section-4.2-5.3.1\"><strong>Response:</strong> <strong>200 OK</strong> on success; <strong>404 Not Found</strong> if no agent with that ID exists; <strong>403 Forbidden</strong> if the requester is not authorized to update that agent.<a href=\"#section-4.2-5.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n</section>\n</div>\n<div id=\"querying-agents\">\n<section id=\"section-4.3\">\n        <h3 id=\"name-querying-agents\">\n<a href=\"#section-4.3\" class=\"section-number selfRef\">4.3. </a><a href=\"#name-querying-agents\" class=\"section-name selfRef\">Querying Agents</a>\n        </h3>\n<p id=\"section-4.3-1\">Clients query the registry using the search endpoint. The protocol supports two types of queries:<a href=\"#section-4.3-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"attribute-based-query-filter\">\n<section id=\"section-4.3.1\">\n          <h4 id=\"name-attribute-based-query-filte\">\n<a href=\"#section-4.3.1\" class=\"section-number selfRef\">4.3.1. </a><a href=\"#name-attribute-based-query-filte\" class=\"section-name selfRef\">Attribute-Based Query (Filter)</a>\n          </h4>\n<p id=\"section-4.3.1-1\">Clients can specify criteria to filter agents by capabilities, tags, supported languages, etc.<a href=\"#section-4.3.1-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4.3.1-2.1\">\n              <p id=\"section-4.3.1-2.1.1\"><strong>Endpoint:</strong> <code>GET /agents?capabilities=X&amp;tags=Y&amp;language=Z</code><a href=\"#section-4.3.1-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            <li class=\"normal\" id=\"section-4.3.1-2.2\">\n              <p id=\"section-4.3.1-2.2.1\">or a structured query via <strong>POST /agents/search</strong> with a JSON body.<a href=\"#section-4.3.1-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          </ul>\n<p id=\"section-4.3.1-3\">For simplicity, <strong>POST /agents/search</strong> is recommended for more complex queries. The body might look like:<a href=\"#section-4.3.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.1-4\"><code>json\n{\n  \"filters\": {\n    \"capabilities\": [\"translation\"],\n    \"supported_languages\": [\"en\", \"zh\"],\n    \"tags\": [\"nlp\"]\n  },\n  \"top\": 10\n}\n</code><a href=\"#section-4.3.1-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.1-5\">This returns up to 10 agents that match all the specified filters. Filters are combined with AND logic (the agent must satisfy all conditions). Capabilities and tags are matched by set intersection (the agent must have at least the ones listed).<a href=\"#section-4.3.1-5\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.1-6\">The response is a JSON array of agent summary objects:<a href=\"#section-4.3.1-6\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.1-7\"><code>json\n[\n  {\n    \"id\": \"agent-12345\",\n    \"name\": \"Chinese-English Translator\",\n    \"description\": \"...\",\n    \"endpoint\": \"https://api.example.com/agents/translate\",\n    \"capabilities\": [\"translation\"]\n  },\n  ...\n]\n</code><a href=\"#section-4.3.1-7\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.1-8\">Summary objects include essential fields to help the client decide which agent to use, without returning the full detailed metadata. A client can retrieve full metadata via the single-agent endpoint.<a href=\"#section-4.3.1-8\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"semantic-query-natural-language-search\">\n<section id=\"section-4.3.2\">\n          <h4 id=\"name-semantic-query-natural-lang\">\n<a href=\"#section-4.3.2\" class=\"section-number selfRef\">4.3.2. </a><a href=\"#name-semantic-query-natural-lang\" class=\"section-name selfRef\">Semantic Query (Natural Language Search)</a>\n          </h4>\n<p id=\"section-4.3.2-1\">In addition to attribute-based search, the registry <span class=\"bcp14\">MAY</span> support semantic search where the client describes a need in natural language, and the registry uses AI techniques (embeddings, LLM-based matching) to find relevant agents. This is an optional feature for registries.<a href=\"#section-4.3.2-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4.3.2-2.1\">\n              <p id=\"section-4.3.2-2.1.1\"><strong>Endpoint:</strong> <code>POST /agents/search</code><a href=\"#section-4.3.2-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            <li class=\"normal\" id=\"section-4.3.2-2.2\">\n              <p id=\"section-4.3.2-2.2.1\"><strong>Request Body:</strong>\n                <code>json\n{\n  \"query\": \"I need an agent that can summarize long legal documents in Chinese.\",\n  \"top\": 5\n}\n</code><a href=\"#section-4.3.2-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          </ul>\n<p id=\"section-4.3.2-3\">The registry returns a ranked list of agents whose descriptions match the query semantically, possibly including a match score. For example:<a href=\"#section-4.3.2-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.2-4\"><code>json\n[\n  {\n    \"id\": \"agent-67890\",\n    \"name\": \"Legal Document Summarizer\",\n    \"description\": \"...\",\n    \"score\": 0.93\n  },\n  ...\n]\n</code><a href=\"#section-4.3.2-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-4.3.2-5\">Semantic search enables flexible discovery beyond exact filter matching, aligning with how users or orchestrating agents might reason about tasks. Registries not supporting semantic search simply ignore the <code>query</code> text and rely on provided filters.<a href=\"#section-4.3.2-5\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"retrieve-single-agent\">\n<section id=\"section-4.3.3\">\n          <h4 id=\"name-retrieve-single-agent\">\n<a href=\"#section-4.3.3\" class=\"section-number selfRef\">4.3.3. </a><a href=\"#name-retrieve-single-agent\" class=\"section-name selfRef\">Retrieve Single Agent</a>\n          </h4>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-4.3.3-1.1\">\n              <p id=\"section-4.3.3-1.1.1\"><strong>Endpoint:</strong> <code>GET /agents/{id}</code><a href=\"#section-4.3.3-1.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            <li class=\"normal\" id=\"section-4.3.3-1.2\">\n              <p id=\"section-4.3.3-1.2.1\"><strong>Response:</strong> Full metadata JSON for the specified agent, or <strong>404</strong> if not found.<a href=\"#section-4.3.3-1.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          </ul>\n</section>\n</div>\n</section>\n</div>\n</section>\n</div>\n<div id=\"agent-invocation\">\n<section id=\"section-5\">\n      <h2 id=\"name-agent-invocation\">\n<a href=\"#section-5\" class=\"section-number selfRef\">5. </a><a href=\"#name-agent-invocation\" class=\"section-name selfRef\">Agent Invocation</a>\n      </h2>\n<p id=\"section-5-1\">Once a client discovers a suitable agent, it invokes the agent by sending a request to the agent's endpoint. This section defines the interface for invocation.<a href=\"#section-5-1\" class=\"pilcrow\">¶</a></p>\n<div id=\"invocation-request\">\n<section id=\"section-5.1\">\n        <h3 id=\"name-invocation-request\">\n<a href=\"#section-5.1\" class=\"section-number selfRef\">5.1. </a><a href=\"#name-invocation-request\" class=\"section-name selfRef\">Invocation Request</a>\n        </h3>\n<p id=\"section-5.1-1\">To invoke an agent, the client sends an HTTP POST request to the agent's invocation endpoint with a JSON body containing the input data for the agent's task.<a href=\"#section-5.1-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-5.1-2.1\">\n            <p id=\"section-5.1-2.1.1\"><strong>Method:</strong> POST<a href=\"#section-5.1-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.1-2.2\">\n            <p id=\"section-5.1-2.2.1\"><strong>URL:</strong> The <code>endpoint</code> URL from the agent's metadata (e.g., <code>https://api.example.com/agents/translate</code>). If a gateway is used, the URL might be a gateway-provided path.<a href=\"#section-5.1-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.1-2.3\">\n            <p id=\"section-5.1-2.3.1\"><strong>Headers:</strong><a href=\"#section-5.1-2.3.1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-5.1-2.3.2.1\">\n                <p id=\"section-5.1-2.3.2.1.1\"><code>Content-Type: application/json</code><a href=\"#section-5.1-2.3.2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n              <li class=\"normal\" id=\"section-5.1-2.3.2.2\">\n                <p id=\"section-5.1-2.3.2.2.1\">Authentication header as required (e.g., <code>Authorization: Bearer &lt;token&gt;</code> or <code>X-API-Key: &lt;key&gt;</code>).<a href=\"#section-5.1-2.3.2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n            </ul>\n</li>\n          <li class=\"normal\" id=\"section-5.1-2.4\">\n            <p id=\"section-5.1-2.4.1\"><strong>Body:</strong> A JSON object containing input data as per the agent's input schema.<a href=\"#section-5.1-2.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n<p id=\"section-5.1-3\">For example, invoking the translation agent:<a href=\"#section-5.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.1-4\"><code>json\n{\n  \"text\": \"Hello, how are you?\",\n  \"source_language\": \"en\",\n  \"target_language\": \"fr\"\n}\n</code><a href=\"#section-5.1-4\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.1-5\">This corresponds to the agent's expected input fields. If the agent had multiple operations and a unified endpoint, there might be an additional field to specify which operation or capability to use. For instance, the JSON could include something like <code>\"operation\": \"translateText\"</code> if needed. Alternatively, different operations could be exposed at different URLs (e.g., <code>/agents/xyz/translate</code> vs <code>/agents/xyz/summarize</code>), in which case the operation is selected by the URL and no extra field is required.<a href=\"#section-5.1-5\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.1-6\">The protocol does not fix a specific parameter naming; it defers to the agent's published schema. The only requirement is that the client's JSON must conform to what the agent expects. For interoperability, using clear field names and standard data types (strings, numbers, booleans, or structured objects) is encouraged. Binary data (like images for an image-processing agent) should be handled carefully: typically, binary inputs can be provided either as URLs (pointing to where the data is stored), or as base64-encoded strings within the JSON, or by using a multipart request. This specification suggests that if agents need to receive large binary payloads, they either use URL references or out-of-scope mechanisms (like a separate upload and then an ID in the JSON). The core invocation remains JSON-based for simplicity and consistency.<a href=\"#section-5.1-6\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.1-7\"><strong>Headers:</strong> If authentication is required (see Security section), the client must also include the appropriate headers (e.g., <code>Authorization: Bearer &lt;token&gt;</code> or an API key header) as dictated by the agent's metadata. The invocation request may also include optional headers for correlation or debugging, such as a request ID, but those are not standardized here.<a href=\"#section-5.1-7\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"invocation-response\">\n<section id=\"section-5.2\">\n        <h3 id=\"name-invocation-response\">\n<a href=\"#section-5.2\" class=\"section-number selfRef\">5.2. </a><a href=\"#name-invocation-response\" class=\"section-name selfRef\">Invocation Response</a>\n        </h3>\n<p id=\"section-5.2-1\">The agent (or gateway) will process the request and return a response. The status code and JSON body of the response follow these guidelines:<a href=\"#section-5.2-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-5.2-2.1\">\n            <p id=\"section-5.2-2.1.1\"><strong>Success (2xx status):</strong> If the agent successfully performed its task and produced a result, the status <span class=\"bcp14\">SHOULD</span> be <strong>200 OK</strong> (or <strong>201 Created</strong> if a new resource was created as a result, though usually for these actions 200 is fine). The response body will contain the output data in JSON. Ideally, the output JSON conforms to the agent's advertised output schema.<a href=\"#section-5.2-2.1.1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.1.2\">\nFor example, for the translation request above, a success response might be:<a href=\"#section-5.2-2.1.2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.1.3\"><code>json\n{\n  \"translated_text\": \"Bonjour, comment êtes-vous?\"\n}\n</code><a href=\"#section-5.2-2.1.3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.1.4\">\nHere the JSON structure matches what was described in the agent metadata's <code>outputs</code>. If the output is complex (e.g., multiple fields or nested objects), those should appear accordingly. The response can include other informational fields if necessary (for example, some agents might return usage metrics, like tokens used or time taken, or a trace id for debugging, but these are optional and out of scope of the core spec).<a href=\"#section-5.2-2.1.4\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.2-2.2\">\n            <p id=\"section-5.2-2.2.1\"><strong>Client Error (4xx status):</strong> If the request was malformed or invalid, the agent returns a <strong>4xx</strong> status code. The most common would be <strong>400 Bad Request</strong> for a JSON that doesn't conform to the expected schema or missing required fields. For example, if the client omitted a required field <code>target_language</code>, the agent might respond with 400. The response body <span class=\"bcp14\">SHOULD</span> include an error object explaining what went wrong. We define a simple standard for error objects:<a href=\"#section-5.2-2.2.1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.2.2\"><code>json\n{\n  \"error\": {\n    \"code\": \"InvalidInput\",\n    \"message\": \"Required field 'target_language' is missing.\"\n  }\n}\n</code><a href=\"#section-5.2-2.2.2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.2.3\">\nHere, <code>\"code\"</code> is a short string identifier for the error type (e.g., <code>InvalidInput</code>, <code>Unauthorized</code>, <code>NotFound</code>), and <code>\"message\"</code> is a human-readable description. The agent can include additional details if available (e.g., a field name that is wrong, etc.). If the error is due to unauthorized access, <strong>401 Unauthorized</strong> or <strong>403 Forbidden</strong> should be used (with an appropriate error message indicating credentials are missing or insufficient). If the agent ID is not found (perhaps the client used an outdated reference), <strong>404 Not Found</strong> is appropriate.<a href=\"#section-5.2-2.2.3\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.2-2.3\">\n            <p id=\"section-5.2-2.3.1\"><strong>Server/Agent Error (5xx status):</strong> If something goes wrong on the agent's side during processing (an exception, a timeout while executing the task, etc.), the agent (or gateway) returns a <strong>5xx</strong> status (most likely <strong>500 Internal Server Error</strong> or <strong>502/504</strong> if there are upstream issues). The response should again include an error object. For example:<a href=\"#section-5.2-2.3.1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.3.2\"><code>json\n{\n  \"error\": {\n    \"code\": \"AgentError\",\n    \"message\": \"The agent encountered an unexpected error while processing the request.\"\n  }\n}\n</code><a href=\"#section-5.2-2.3.2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-5.2-2.3.3\">\nThe agent might log the detailed error internally, but only convey a generic message to the client for security. A <strong>503 Service Unavailable</strong> might be returned if the agent is temporarily overloaded or offline, indicating the client could retry later.<a href=\"#section-5.2-2.3.3\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.2-2.4\">\n            <p id=\"section-5.2-2.4.1\"><strong>Status Codes Summary:</strong> In short, this protocol expects the use of standard status codes to reflect outcome (200 for success, 4xx for client-side issues, 5xx for server-side issues). Agents should avoid using 2xx if the operation did not semantically succeed (even if technically a response was generated). For example, if an agent is a composite that calls other services and one of those calls fails, it should propagate an error rather than returning 200 with an error in the data.<a href=\"#section-5.2-2.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n</section>\n</div>\n<div id=\"additional-considerations-for-invocation\">\n<section id=\"section-5.3\">\n        <h3 id=\"name-additional-considerations-f\">\n<a href=\"#section-5.3\" class=\"section-number selfRef\">5.3. </a><a href=\"#name-additional-considerations-f\" class=\"section-name selfRef\">Additional Considerations for Invocation</a>\n        </h3>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-5.3-1.1\">\n            <p id=\"section-5.3-1.1.1\"><strong>Streaming Responses:</strong> Some agents (especially those wrapping large language models) may produce results that are streamed (for example, token-by-token outputs). While this base protocol assumes a request-response pattern with the full result delivered at once, it can be extended to support streaming by using chunked responses or WebSockets. For instance, an agent might accept a parameter like <code>stream: true</code> and then send partial outputs as they become available. This is an advanced use case and not elaborated in this draft, but implementers should consider compatibility with streaming if real-time responsiveness is needed.<a href=\"#section-5.3-1.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.3-1.2\">\n            <p id=\"section-5.3-1.2.1\"><strong>Batch Requests:</strong> If a client wants to send multiple independent requests to an agent in one go (for efficiency), the protocol can support that by allowing an array of input objects in the POST body instead of a single object. The response would then be an array of output results. This is optional and depends on agent support.<a href=\"#section-5.3-1.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.3-1.3\">\n            <p id=\"section-5.3-1.3.1\"><strong>Idempotency and Retries:</strong> Most agent invocations are not strictly idempotent (since an agent might perform an action or have side effects), but many are pure functions (e.g., translate text). Clients and gateways should design with retry logic carefully — if a network failure happens, a retry might re-run an operation. It's best to ensure that agents' operations are either idempotent or have safeguards (for example, an operation that sends an email might have an idempotency key).<a href=\"#section-5.3-1.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-5.3-1.4\">\n            <p id=\"section-5.3-1.4.1\"><strong>Operation Metadata:</strong> In cases where the agent defines multiple <code>operations</code> in its metadata, the invocation interface might allow a generic endpoint that accepts an operation name. Alternatively, each operation could be a sub-resource. This draft leaves the exact mechanism flexible: an implementation could choose one of these approaches. The key is that the invocation uses POST and a JSON body following the agent's schema.<a href=\"#section-5.3-1.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n</section>\n</div>\n</section>\n</div>\n<div id=\"agent-semantic-resolution\">\n<section id=\"section-6\">\n      <h2 id=\"name-agent-semantic-resolution\">\n<a href=\"#section-6\" class=\"section-number selfRef\">6. </a><a href=\"#name-agent-semantic-resolution\" class=\"section-name selfRef\">Agent Semantic Resolution</a>\n      </h2>\n<p id=\"section-6-1\">Agent Semantic Resolution (ASR) is an optional extension to the discovery mechanism defined in this document. ASR enables a client to resolve a task intent into one or more candidate agents prior to invoking any specific agent.<a href=\"#section-6-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-2\">ASR operates on the following conceptual model:<a href=\"#section-6-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-3\"><code>\n(Intent, Context, Policy) → (Agent Endpoint(s), Invocation Metadata)\n</code><a href=\"#section-6-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6-4\">The intent represents the task to be performed, while context and policy may include domain constraints, trust requirements, or performance considerations.<a href=\"#section-6-4\" class=\"pilcrow\">¶</a></p>\n<div id=\"non-goals\">\n<section id=\"section-6.1\">\n        <h3 id=\"name-non-goals\">\n<a href=\"#section-6.1\" class=\"section-number selfRef\">6.1. </a><a href=\"#name-non-goals\" class=\"section-name selfRef\">Non-Goals</a>\n        </h3>\n<p id=\"section-6.1-1\">ASR explicitly does not provide:<a href=\"#section-6.1-1\" class=\"pilcrow\">¶</a></p>\n<ul class=\"normal\">\n<li class=\"normal\" id=\"section-6.1-2.1\">\n            <p id=\"section-6.1-2.1.1\">Name-to-address resolution<a href=\"#section-6.1-2.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-6.1-2.2\">\n            <p id=\"section-6.1-2.2.1\">Global or persistent agent identifiers<a href=\"#section-6.1-2.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n          <li class=\"normal\" id=\"section-6.1-2.3\">\n            <p id=\"section-6.1-2.3.1\">Replacement for DNS, ANS, or URI-based registries<a href=\"#section-6.1-2.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        </ul>\n<p id=\"section-6.1-3\">ASR answers the question \"Which agent(s) should handle this task now?\" rather than \"Where is agent X located?\".<a href=\"#section-6.1-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-6.1-4\"></p>\n</section>\n</div>\n</section>\n</div>\n<div id=\"semantic-routing-platform\">\n<section id=\"section-7\">\n      <h2 id=\"name-semantic-routing-platform\">\n<a href=\"#section-7\" class=\"section-number selfRef\">7. </a><a href=\"#name-semantic-routing-platform\" class=\"section-name selfRef\">Semantic Routing Platform</a>\n      </h2>\n<p id=\"section-7-1\">A Semantic Routing Platform (SRP) is a control-plane service that implements ASR. An SRP assists a Host Agent in selecting appropriate agents before standard discovery and invocation procedures are used.<a href=\"#section-7-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-2\">An SRP <span class=\"bcp14\">MAY</span> perform semantic matching, ranking, and policy-based filtering of candidate agents. The SRP does not participate in task execution and does not alter the invocation semantics defined in this document.<a href=\"#section-7-2\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-3\">Interaction with an SRP is <span class=\"bcp14\">OPTIONAL</span>. Clients that do not support ASR continue to operate using the discovery and invocation mechanisms defined in earlier sections.<a href=\"#section-7-3\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-7-4\"></p>\n</section>\n</div>\n<div id=\"backward-compatibility\">\n<section id=\"section-8\">\n      <h2 id=\"name-backward-compatibility\">\n<a href=\"#section-8\" class=\"section-number selfRef\">8. </a><a href=\"#name-backward-compatibility\" class=\"section-name selfRef\">Backward Compatibility</a>\n      </h2>\n<p id=\"section-8-1\">All discovery and invocation mechanisms defined in previous revisions of this document remain valid and unchanged.<a href=\"#section-8-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-8-2\">Agent Semantic Resolution is an optional extension. Implementations <span class=\"bcp14\">MAY</span> support ASR incrementally, and registries <span class=\"bcp14\">MAY</span> provide semantic resolution capabilities without affecting existing clients.<a href=\"#section-8-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"security-considerations\">\n<section id=\"section-9\">\n      <h2 id=\"name-security-considerations\">\n<a href=\"#section-9\" class=\"section-number selfRef\">9. </a><a href=\"#name-security-considerations\" class=\"section-name selfRef\">Security Considerations</a>\n      </h2>\n<p id=\"section-9-1\">Security is a critical aspect of this protocol. All discovery and invocation traffic <span class=\"bcp14\">MUST</span> be protected with TLS <span>[<a href=\"#RFC8446\" class=\"cite xref\">RFC8446</a>]</span>, and authentication mechanisms such as OAuth 2.0 <span>[<a href=\"#RFC6749\" class=\"cite xref\">RFC6749</a>]</span>  bearer tokens, API keys, or mutual TLS are required except for public discovery endpoints. Registries <span class=\"bcp14\">MUST</span> enforce per-client entitlements, ensuring that both search results and invocation access respect permissions and scopes. Gateways forwarding requests should authenticate themselves to agents, and agents should maintain stable identifiers and use signed responses when integrity is essential. All communication <span class=\"bcp14\">MUST</span> be encrypted, and agents are encouraged to disclose data-retention or logging practices, while sensitive data is best handled by on-premises or certified agents. To mitigate abuse, registries and agents <span class=\"bcp14\">MUST</span> implement rate limiting and quotas, particularly in semantic search scenarios. Trust mechanisms such as certification, test harnesses, or reputation systems may be used to validate agent claims, and metadata fields like \"certification\" or \"quality_score\" can inform client trust decisions. Systems <span class=\"bcp14\">SHOULD</span> also provide audit and logging with privacy-aware retention, while clients must treat agent outputs as untrusted until verified, using sandboxing and validation before executing code or commands.<a href=\"#section-9-1\" class=\"pilcrow\">¶</a></p>\n<p id=\"section-9-2\">When Agent Semantic Resolution is used, security considerations extend to the pre-invocation phase. Resolution services <span class=\"bcp14\">SHOULD</span> validate agent capability claims, apply policy constraints, and exclude agents that do not meet trust or reputation requirements. Agents deemed unsafe <span class=\"bcp14\">SHOULD NOT</span> be returned as resolution candidates.<a href=\"#section-9-2\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"example-interaction-flow\">\n<section id=\"section-10\">\n      <h2 id=\"name-example-interaction-flow\">\n<a href=\"#section-10\" class=\"section-number selfRef\">10. </a><a href=\"#name-example-interaction-flow\" class=\"section-name selfRef\">Example Interaction Flow</a>\n      </h2>\n<ol start=\"1\" type=\"1\" class=\"normal type-1\" id=\"section-10-1\">\n<li id=\"section-10-1.1\">\n          <p id=\"section-10-1.1.1\"><strong>Search:</strong> Client <code>POST /agents/search</code> with <code>{\"query\":\"summarize an English document\",\"filters\":{\"capabilities\":[\"summarization\"],\"supported_language\":\"en\"},\"top\":3}</code>.<a href=\"#section-10-1.1.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-10-1.2\">\n          <p id=\"section-10-1.2.1\"><strong>Select:</strong> Registry returns candidate agents with <code>id</code>, <code>name</code>, <code>description</code>, and <code>score</code>. Client retrieves full metadata via <code>GET /agents/{id}</code> if needed.<a href=\"#section-10-1.2.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-10-1.3\">\n          <p id=\"section-10-1.3.1\"><strong>Invoke:</strong> Client <code>POST</code> to the agent's <code>endpoint</code> (or gateway path) with inputs conforming to agent schema and required auth header.<a href=\"#section-10-1.3.1\" class=\"pilcrow\">¶</a></p>\n</li>\n        <li id=\"section-10-1.4\">\n          <p id=\"section-10-1.4.1\"><strong>Handle Response:</strong> Client processes success or error response; may log usage and optionally rate/feedback the agent.<a href=\"#section-10-1.4.1\" class=\"pilcrow\">¶</a></p>\n</li>\n      </ol>\n</section>\n</div>\n<div id=\"iana-considerations\">\n<section id=\"section-11\">\n      <h2 id=\"name-iana-considerations\">\n<a href=\"#section-11\" class=\"section-number selfRef\">11. </a><a href=\"#name-iana-considerations\" class=\"section-name selfRef\">IANA Considerations</a>\n      </h2>\n<p id=\"section-11-1\">This document has no IANA actions.<a href=\"#section-11-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"sec-normative-references\">\n<section id=\"section-12\">\n      <h2 id=\"name-normative-references\">\n<a href=\"#section-12\" class=\"section-number selfRef\">12. </a><a href=\"#name-normative-references\" class=\"section-name selfRef\">Normative References</a>\n      </h2>\n<dl class=\"references\">\n<dt id=\"RFC2119\">[RFC2119]</dt>\n      <dd>\n<span class=\"refAuthor\">Bradner, S.</span>, <span class=\"refTitle\">\"Key words for use in RFCs to Indicate Requirement Levels\"</span>, <span class=\"seriesInfo\">BCP 14</span>, <span class=\"seriesInfo\">RFC 2119</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC2119</span>, <time datetime=\"1997-03\" class=\"refDate\">March 1997</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc2119\">https://www.rfc-editor.org/rfc/rfc2119</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC6749\">[RFC6749]</dt>\n      <dd>\n<span class=\"refAuthor\">Hardt, D., Ed.</span>, <span class=\"refTitle\">\"The OAuth 2.0 Authorization Framework\"</span>, <span class=\"seriesInfo\">RFC 6749</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC6749</span>, <time datetime=\"2012-10\" class=\"refDate\">October 2012</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc6749\">https://www.rfc-editor.org/rfc/rfc6749</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC8174\">[RFC8174]</dt>\n      <dd>\n<span class=\"refAuthor\">Leiba, B.</span>, <span class=\"refTitle\">\"Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words\"</span>, <span class=\"seriesInfo\">BCP 14</span>, <span class=\"seriesInfo\">RFC 8174</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8174</span>, <time datetime=\"2017-05\" class=\"refDate\">May 2017</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8174\">https://www.rfc-editor.org/rfc/rfc8174</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC8259\">[RFC8259]</dt>\n      <dd>\n<span class=\"refAuthor\">Bray, T., Ed.</span>, <span class=\"refTitle\">\"The JavaScript Object Notation (JSON) Data Interchange Format\"</span>, <span class=\"seriesInfo\">STD 90</span>, <span class=\"seriesInfo\">RFC 8259</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8259</span>, <time datetime=\"2017-12\" class=\"refDate\">December 2017</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8259\">https://www.rfc-editor.org/rfc/rfc8259</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC8446\">[RFC8446]</dt>\n      <dd>\n<span class=\"refAuthor\">Rescorla, E.</span>, <span class=\"refTitle\">\"The Transport Layer Security (TLS) Protocol Version 1.3\"</span>, <span class=\"seriesInfo\">RFC 8446</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC8446</span>, <time datetime=\"2018-08\" class=\"refDate\">August 2018</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc8446\">https://www.rfc-editor.org/rfc/rfc8446</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n<dt id=\"RFC9110\">[RFC9110]</dt>\n    <dd>\n<span class=\"refAuthor\">Fielding, R., Ed.</span>, <span class=\"refAuthor\">Nottingham, M., Ed.</span>, and <span class=\"refAuthor\">J. Reschke, Ed.</span>, <span class=\"refTitle\">\"HTTP Semantics\"</span>, <span class=\"seriesInfo\">STD 97</span>, <span class=\"seriesInfo\">RFC 9110</span>, <span class=\"seriesInfo\">DOI 10.17487/RFC9110</span>, <time datetime=\"2022-06\" class=\"refDate\">June 2022</time>, <span>&lt;<a href=\"https://www.rfc-editor.org/rfc/rfc9110\">https://www.rfc-editor.org/rfc/rfc9110</a>&gt;</span>. </dd>\n<dd class=\"break\"></dd>\n</dl>\n</section>\n</div>\n<div id=\"acknowledgments\">\n<section id=\"appendix-A\">\n      <h2 id=\"name-acknowledgments\">\n<a href=\"#name-acknowledgments\" class=\"section-name selfRef\">Acknowledgments</a>\n      </h2>\n<p id=\"appendix-A-1\">TODO acknowledge.<a href=\"#appendix-A-1\" class=\"pilcrow\">¶</a></p>\n</section>\n</div>\n<div id=\"authors-addresses\">\n<section id=\"appendix-B\">\n      <h2 id=\"name-authors-addresses\">\n<a href=\"#name-authors-addresses\" class=\"section-name selfRef\">Authors' Addresses</a>\n      </h2>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Yong Cui</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Tsinghua University</span></div>\n<div dir=\"auto\" class=\"left\">\n<span class=\"region\">Beijing</span>, <span class=\"postal-code\">100084</span>\n</div>\n<div dir=\"auto\" class=\"left\"><span class=\"country-name\">China</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:cuiyong@tsinghua.edu.cn\" class=\"email\">cuiyong@tsinghua.edu.cn</a>\n</div>\n<div class=\"url\">\n<span>URI:</span>\n<a href=\"http://www.cuiyong.net/\" class=\"url\">http://www.cuiyong.net/</a>\n</div>\n</address>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Yihan Chao</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Zhongguancun Laboratory</span></div>\n<div dir=\"auto\" class=\"left\">\n<span class=\"region\">Beijing</span>, <span class=\"postal-code\">100094</span>\n</div>\n<div dir=\"auto\" class=\"left\"><span class=\"country-name\">China</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:chaoyh@zgclab.edu.cn\" class=\"email\">chaoyh@zgclab.edu.cn</a>\n</div>\n</address>\n<address class=\"vcard\">\n        <div dir=\"auto\" class=\"left\"><span class=\"fn nameRole\">Chenguang Du</span></div>\n<div dir=\"auto\" class=\"left\"><span class=\"org\">Zhongguancun Laboratory</span></div>\n<div dir=\"auto\" class=\"left\">\n<span class=\"region\">Beijing</span>, <span class=\"postal-code\">100094</span>\n</div>\n<div dir=\"auto\" class=\"left\"><span class=\"country-name\">China</span></div>\n<div class=\"email\">\n<span>Email:</span>\n<a href=\"mailto:ducg@zgclab.edu.cn\" class=\"email\">ducg@zgclab.edu.cn</a>\n</div>\n</address>\n</section>\n</div>\n<script>const toc = document.getElementById(\"toc\");\ntoc.querySelector(\"h2\").addEventListener(\"click\", e => {\n  toc.classList.toggle(\"active\");\n});\ntoc.querySelector(\"nav\").addEventListener(\"click\", e => {\n  toc.classList.remove(\"active\");\n});\n</script>\n<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a3ba8f879841f46e',t:'MTc4OTUwNjAyMw=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\n</html>\n","snapshot_chars":102949,"live_check":"changed"},{"url":"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/","committed_hash":"sha256:cbe6898ffd78a67092b179d1016e277e5d3ca9d042e3e35701665cd4751f1ce9","committed_hash_short":"sha256:cbe6898f…751f1ce9","mime_type":"text/html","committed_at":"2026-09-15T21:00:24.068162+00:00","content_snapshot":"\n<!DOCTYPE html>\n\n\n\n\n\n\n<html data-bs-theme=\"auto\" lang=\"en\" prefix=\"og: http://ogp.me/ns# article: http://ogp.me/ns/article#\">\n    <head>\n        \n        <meta charset=\"utf-8\">\n        <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n        <title>\n            \n    \n        draft-cui-ai-agent-discovery-invocation-02 - AI Agent Discovery and Invocation Protocol\n    \n\n        </title>\n        <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n        <meta name=\"traceparent\" content=\"\">\n        <link href=\"https://static.ietf.org/fonts/inter/import.css\" rel=\"stylesheet\">\n        <link href=\"https://static.ietf.org/fonts/noto-sans-mono/import.css\" rel=\"stylesheet\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.75.0/ietf/css/ietf.css\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.75.0/ietf/css/select2.css\">\n        \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/theme.js\"></script>\n        <style>\n            .inline { display: inline; }\n        </style>\n        \n        \n    \n\n\n\n\n<meta property=\"og:title\" content=\"AI Agent Discovery and Invocation Protocol\">\n<meta property=\"og:url\" content=\"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/\">\n\n\n<link rel=\"canonical\" href=\"https://datatracker.ietf.org/doc/draft-cui-ai-agent-discovery-invocation/\">\n\n<meta property=\"og:site_name\" content=\"IETF Datatracker\">\n<meta property=\"og:description\" content=\"This document proposes a standardized protocol for discovery and invocation of AI agents. It defines a common metadata format for describing AI agents (including capabilities, I/O specifications, supported languages, tags, authentication methods, etc.), a capability-based discovery mechanism, and a unified RESTful invocation interface. This revision refines the discovery mechanism by defining fields for intent-based agent selection. This capability enables a client, host agent, or orchestration system to describe a task intent and receive a ranked set of candidate agents before invocation, without changing existing discovery or invocation semantics. The goal is to enable cross-platform interoperability among AI agents by providing a discover-and-match mechanism and a unified invocation entry point. Security considerations, including authentication and trust measures, are also discussed. This specification aims to facilitate the formation of multi-agent systems by making it easy to find the right agent for a task and invoke it in a consistent manner across different vendors and platforms. Intent-based selection is an application-layer capability and does not define network routing, packet forwarding, path computation, reachability advertisement, or address resolution.\">\n<meta property=\"og:type\" content=\"article\">\n\n<meta property=\"article:section\" content=\"Individual Internet-Draft\">\n\n<meta property=\"article:author\" content=\"Yong Cui\">\n<meta property=\"article:author\" content=\"Yihan Chao\">\n<meta property=\"article:author\" content=\"Chenguang Du\">\n\n\n\n    <link rel=\"alternate\"\n          type=\"application/atom+xml\"\n          title=\"Document changes\"\n          href=\"/feed/document-changes/draft-cui-ai-agent-discovery-invocation/\">\n    <meta name=\"description\"\n          content=\"AI Agent Discovery and Invocation Protocol \">\n\n        <script type=\"module\" crossorigin=\"\" src=\"https://static.ietf.org/dt/12.75.0/assets/embedded-881b2388.js\"></script>\n<link href=\"https://static.ietf.org/dt/12.75.0/assets/create-pinia-singleton-d62960d6.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n<link href=\"https://static.ietf.org/dt/12.75.0/assets/Scrollbar-8c74800b.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n        \n\n<link rel=\"apple-touch-icon\"\n      sizes=\"180x180\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-180.png\">\n<link rel=\"icon\"\n      sizes=\"32x32\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-32.png\">\n<link rel=\"icon\"\n      sizes=\"16x16\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-16.png\">\n<link rel=\"manifest\" href=\"/site.webmanifest\">\n<link rel=\"mask-icon\"\n      href=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-mask.svg\"\n      color=\"#ffffff\">\n<meta name=\"msapplication-TileColor\"\n      content=\"#ffffff\">\n<meta name=\"theme-color\"\n      content=\"#ffffff\">\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/ietf.js\"></script>\n        \n    </head>\n    <body  class=\"navbar-offset position-relative\"\n          data-group-menu-data-url=\"/group/groupmenu.json\">\n        \n        <noscript><iframe class=\"status\" title=\"Site status\" src=\"/status/latest\"></iframe></noscript>\n<div class=\"vue-embed\" data-component=\"Status\"></div>\n        <a class=\"visually-hidden visually-hidden-focusable\" href=\"#content\">Skip to main content</a>\n        <nav class=\"navbar navbar-expand-lg fixed-top bg-secondary-subtle\">\n            <div class=\"container-fluid\">\n                <a class=\"navbar-brand\" href=\"/\">\n                    \n\n\n\n<img alt=\"IETF Logo\"\n     class=\"d-lm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor-white.svg\"\n        \n     \n     >\n\n<img alt=\"IETF Logo\"\n     class=\"d-dm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.75.0/ietf/images/ietf-logo-nor.svg\"\n        \n     \n     >\n                    Datatracker\n                    \n                </a>\n                <div class=\"collapse navbar-collapse\" id=\"navbar-collapse\">\n                    <ul class=\"nav navbar-nav flex-nowrap\">\n                        \n\n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Groups\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li class=\"dropdown-header\">By area/parent</li>\n    \n\n\n\n    \n    <li class=\"dropend group-menu group-parent-2010\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#ART\">\n            Apps &amp; Realtime\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1008\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#GEN\">\n            General\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1052\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#INT\">\n            Internet\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1193\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#OPS\">\n            Ops &amp; Management\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1249\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#RTG\">\n            Routing\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1260\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#SEC\">\n            Security\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2412\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#WIT\">\n            Web and Internet Transport\n        </a>\n    </li>\n\n    \n        <li><a class=\"dropdown-item\" href=\"/group/iesg/about/\">IESG</a></li>\n    \n    <li class=\"dropend group-menu group-parent-7\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/program/\">\n            IAB\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-3\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rg/\">\n            IRTF\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2309\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/adm/\">\n            IETF LLC\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1876\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rfcedtyp/\">\n            RFC Editor\n        </a>\n    </li>\n\n\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/group/\">\n            Other\n        </a>\n        \n\n\n<ul class=\"dropdown-menu ms-n1\">\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/ag/\">Active AGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/area/\">Active Areas</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/dir/\">Active Directorates</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/iabworkshop/\">Active IAB Workshops</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/program/\">Active Programs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/rag/\">Active RAGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/team/\">Active Teams</a>\n        </li>\n    \n    \n</ul>\n\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">New work</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/chartering/\">\n            Chartering groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/wg/bofs/\">\n            BOFs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bof-requests\">\n            BOF Requests\n        </a>\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">Other groups</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/concluded/\">\n            Concluded groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/list/nonwg\">\n            Non-WG lists\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Documents\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/search\">\n            Search\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/recent\">\n            Recent I-Ds\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/submit/\">\n            Submit an Internet-Draft\n        </a>\n    </li>\n    \n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        RFC streams\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/iab/\">\n            IAB\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/irtf/\">\n            IRTF\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/ise/\">\n            ISE\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/editorial/\">\n            Editorial\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        Subseries\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/std\">\n            STD\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bcp\">\n            BCP\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/fyi\">\n            FYI\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Meetings\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/agenda\">\n            Agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/materials\">\n            Materials\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/floor-plan\">\n            Floor plan\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/register/\">\n            Registration\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/important-dates/\">\n            Important dates\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/session/request/\">\n            Request a session\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/requests\">\n            Session requests\n        </a>\n    </li>\n    \n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Upcoming meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/upcoming\">\n            Upcoming meetings\n        </a>\n    </li>\n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Past meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/past\">\n            Past meetings\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/past/\">\n            Meeting proceedings\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Other\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/ipr/\">\n            IPR disclosures\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/liaison/\">\n            Liaison statements\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/iesg/agenda/\">\n            IESG agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/nomcom/\">\n            NomComs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/downref\">\n            Downref registry\n        </a>\n    </li>\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n            Statistics\n        </a>\n        <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/document/\">\n                    I-Ds/RFCs\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/meeting/\">\n                    Meetings\n                </a>\n            </li>\n            \n            \n        </ul>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/api/\">\n            API Help\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/release/\">\n            Release notes\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           target=\"_blank\" href=\"https://status.ietf.org\">\n            System status\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item text-danger \"\n           target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n            <i class=\"bi bi-bug\">\n            </i>\n            Report a bug\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n\n    \n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            \n                User\n            \n        </a>\n        <ul class=\"dropdown-menu  mt-n1 \">\n        \n    \n    \n        \n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/login/?next=/doc/draft-cui-ai-agent-discovery-invocation/\">\n                    Sign in\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/reset/\">\n                    Password reset\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   href=\"/accounts/settings/\"\n                   rel=\"nofollow\">\n                    Preferences\n                </a>\n            </li>\n        \n    \n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/accounts/create/\">\n                New account\n            </a>\n        </li>\n    \n    <li class=\"dropend\">\n      <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n        List subscriptions\n      </a>\n      <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.ietf.org/mailman3/lists/\">\n                    IETF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.irtf.org/mailman3/lists/\">\n                IRTF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.iab.org/mailman3/lists/\">\n                    IAB Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.rfc-editor.org/mailman3/lists/\">\n                    RFC-Editor Lists\n                </a>\n            </li>\n        </ul>\n    </li>\n    \n    \n    \n    \n    \n    </ul></li>\n\n\n                    </ul>\n                </div>\n                <div class=\"d-flex align-items-center\">\n                    <a class=\"nav-link text-danger d-none d-xl-inline me-xl-4\"\n                       target=\"_blank\"\n                       href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n                        Report a bug\n                        <i class=\"bi bi-bug\"></i>\n                    </a>\n\n                    \n                        <a class=\"btn me-1  btn-warning  d-none d-sm-block\"\n                           rel=\"nofollow\"\n                           href=\"/accounts/login/?next=/doc/draft-cui-ai-agent-discovery-invocation/\">\n                            Sign in\n                        </a>\n                    \n\n                    <div class=\"d-none d-md-block dropdown\" id=\"navbar-doc-search-wrapper\">\n                        <input class=\"form-control\"\n                               id=\"navbar-doc-search\"\n                               type=\"text\"\n                               placeholder=\"Document search\"\n                               autocomplete=\"off\"\n                               data-ajax-url=\"/doc/select2search/document/all/\"\n                               aria-label=\"Document search\">\n                        <ul class=\"dropdown-menu\" id=\"navbar-doc-search-results\">\n                        </ul>\n                    </div>\n                </div>\n                <button class=\"navbar-toggler\"\n                        type=\"button\"\n                        data-bs-toggle=\"collapse\"\n                        data-bs-target=\"#navbar-collapse\"\n                        aria-controls=\"navbar-collapse\"\n                        aria-expanded=\"false\"\n                        aria-label=\"Toggle navigation\">\n                    <i class=\"navbar-toggler-icon\"></i>\n                </button>\n            </div>\n        </nav>\n        \n        <main class=\"pt-3 container-fluid\" id=\"main\">\n            <div class=\"row\">\n                \n                <div class=\"col mx-lg-3 ietf-auto-nav\" id=\"content\">\n                    <noscript data-nosnippet>\n                        <div class=\"alert alert-danger alert-ignore my-3\">\n                            <b>Javascript disabled?</b> Like other modern websites, the IETF Datatracker relies on Javascript.\n                            Please enable Javascript for full functionality.\n                        </div>\n                    </noscript>\n                    \n                    \n    \n    \n\n\n\n<h1>\n    AI Agent Discovery and Invocation Protocol\n    <br>\n    <small class=\"text-body-secondary\">draft-cui-ai-agent-discovery-invocation-02</small>\n</h1>\n<ul class=\"nav nav-tabs my-3\">\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link active\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/\">\n                Status\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/email/\">\n                Email expansions\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/history/\">\n                History\n            </a>\n        </li>\n    \n</ul>\n\n    \n\n\n\n    <label class=\"my-1 fw-bold\">Versions:</label>\n    <nav class=\"mb-3\">\n\n    <ul class=\"revision-list pagination pagination-sm text-center flex-wrap\">\n        \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/00/\"\n                        >\n                            00\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item \">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/01/\"\n                        rel=\"nofollow\">\n                            01\n                        </a>\n                    </li>\n                \n            \n                 \n                    <li class=\"page-item active\">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-cui-ai-agent-discovery-invocation/02/\"\n                        >\n                            02\n                        </a>\n                    </li>\n                \n            \n            \n        \n    </ul>\n\n    </nav>\n\n    \n\n\n\n\n    <div class=\"alert alert-warning \" role=\"alert\">\n        This document is an Internet-Draft (I-D).\n        Anyone may submit an I-D to the IETF.\n        This I-D is <strong>not endorsed by the IETF</strong> and has <strong>no formal standing</strong> in the\n        <a href=\"/doc/rfc2026/\">IETF standards process</a>.\n    </div>\n\n\n    <div id=\"doc-timeline\"></div>\n    \n        \n    \n    <table class=\"table table-sm table-borderless\">\n        \n\n\n\n\n\n\n\n<tbody class=\"meta align-top  border-top\">\n    <tr>\n        <th scope=\"row\">Document</th>\n        <th scope=\"row\">Type</th>\n        <td class=\"edit\"></td>\n        <td>\n            \n\n\n\n\n\n\n\n    <span class=\"text-success\">Active Internet-Draft</span>\n    (individual)\n    \n\n            \n            \n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Authors</th>\n        <td class=\"edit\">\n            \n        </td>\n        <td>\n            \n            \n                <span ><a \n           title=\"Datatracker profile of Yong Cui\"\n            href=\"/person/cuiyong@tsinghua.edu.cn\" >Yong Cui</a> <a \n               href=\"mailto:cuiyong%40tsinghua.edu.cn\"\n               aria-label=\"Compose email to cuiyong@tsinghua.edu.cn\"\n               title=\"Compose email to cuiyong@tsinghua.edu.cn\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Yihan Chao\"\n            href=\"/person/chao_yihan@outlook.com\" >Yihan Chao</a> <a \n               href=\"mailto:chao_yihan%40outlook.com\"\n               aria-label=\"Compose email to chao_yihan@outlook.com\"\n               title=\"Compose email to chao_yihan@outlook.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>,\n            \n                <span ><a \n           title=\"Datatracker profile of Chenguang Du\"\n            href=\"/person/du_chenguang@outlook.com\" >Chenguang Du</a> <a \n               href=\"mailto:du_chenguang%40outlook.com\"\n               aria-label=\"Compose email to du_chenguang@outlook.com\"\n               title=\"Compose email to du_chenguang@outlook.com\">\n                <i class=\"bi bi-envelope\"></i></a></span>\n            \n            \n        </td>\n    </tr>\n    \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Last updated</th>\n        <td class=\"edit\"></td>\n        <td>\n            2026-07-06\n            \n        </td>\n    </tr>\n    \n    \n        \n        \n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            RFC stream\n        </th>\n        <td class=\"edit\">\n            \n        </td>\n        <td class=\"text-body-secondary\">\n            \n                (None)\n            \n        </td>\n    </tr>\n    \n        <tr>\n            <td></td>\n            <th scope=\"row\">\n                Intended RFC status\n            </th>\n            <td class=\"edit\">\n                \n            </td>\n            <td>\n                \n                    <span class=\"text-body-secondary\">\n                        (None)\n                    </span>\n                \n            </td>\n        </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            Formats\n        </th>\n        <td class=\"edit\">\n        </td>\n        <td>\n            \n                \n    <div class=\"buttonlist\">\n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.txt\">\n            \n                <i class=\"bi bi-file-text\"></i> txt\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.html\">\n            \n                <i class=\"bi bi-file-code\"></i> html\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> xml\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          \n          href=\"/doc/html/draft-cui-ai-agent-discovery-invocation-02\">\n            \n                <i class=\"bi bi-file-code\"></i> htmlized\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/draft-cui-ai-agent-discovery-invocation/02/bibtex/\">\n            \n                <i class=\"bi bi-file-ruled\"></i> bibtex\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/bibxml3/draft-cui-ai-agent-discovery-invocation-02.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> bibxml\n            \n        </a>\n        \n    \n</div>\n\n            \n        </td>\n    </tr>\n    \n    \n        \n    \n        \n            \n            \n        \n    \n    \n        \n    \n</tbody>\n        <tbody class=\"meta border-top\">\n            <tr>\n                <th scope=\"row\">\n                    Stream\n                </th>\n                \n                    <th scope=\"row\">\n                        Stream state\n                    </th>\n                    <td class=\"edit\">\n                    </td>\n                    <td>\n                        <span class=\"text-body-secondary\">(No stream defined)</span>\n                    </td>\n                \n            </tr>\n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        Consensus boilerplate\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"text-danger\"\n                              title=\"Whether the document is the result of a community consensus process as defined in RFC 5741\">\n                            Unknown\n                        </span>\n                    </td>\n                </tr>\n            \n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        RFC Editor Note\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        \n                            <span class=\"text-body-secondary\">\n                                (None)\n                            </span>\n                        \n                    </td>\n                </tr>\n            \n            \n        </tbody>\n        \n            <tbody class=\"meta border-top\">\n                <tr>\n                    <th scope=\"row\">\n                        IESG\n                    </th>\n                    <th scope=\"row\">\n                        <a href=\"/doc/help/state/draft-iesg/\">\n                            IESG state\n                        </a>\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"\">\n                            \n                                I-D Exists\n                            \n                        </span>\n                    </td>\n                </tr>\n                \n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Telechat date\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                            \n                        </td>\n                    </tr>\n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Responsible AD\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Send notices to\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                </tbody>\n            \n            \n                \n            \n            \n        </table>\n        <div class=\"buttonlist\">\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"mailto:draft-cui-ai-agent-discovery-invocation@ietf.org?subject=Mail%20regarding%20draft-cui-ai-agent-discovery-invocation\">\n                <i class=\"bi bi-envelope\">\n                </i>\n                Email authors\n            </a>\n            \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/ipr/search/?submit=draft&amp;id=draft-cui-ai-agent-discovery-invocation\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-lightning\">\n                </i>\n                IPR\n                \n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/references/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-left\">\n                </i>\n                References\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-cui-ai-agent-discovery-invocation/referencedby/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-right\">\n                </i>\n                Referenced by\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/api/idnits?url=https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation\">\n                </i>\n                Nits\n            </a>\n             <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/idnits3/results?url=https://www.ietf.org/archive/id/draft-cui-ai-agent-discovery-invocation-02.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation-diamond\">\n                </i>\n                Nits v3\n            </a>           \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://mailarchive.ietf.org/arch/search/?q=%22draft-cui-ai-agent-discovery-invocation%22\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-search\">\n                </i>\n                Search email archive\n            </a>\n            \n            \n            \n            \n        </div>\n        \n            <div class=\"card mt-5\">\n                <div class=\"card-header\">\n                    \n                        draft-cui-ai-agent-discovery-invocation-02\n                    \n                </div>\n                <div class=\"card-body\">\n                    <pre>Network Working Group                                             Y. Cui\nInternet-Draft                                       Tsinghua University\nIntended status: Informational                                   Y. Chao\nExpires: 7 January 2027                                            C. Du\n                                                 Zhongguancun Laboratory\n                                                             6 July 2026\n\n               AI Agent Discovery and Invocation Protocol\n               draft-cui-ai-agent-discovery-invocation-02\n\n<span>Abstract</span>\n\n   This document proposes a standardized protocol for discovery and\n   invocation of AI agents.  It defines a common metadata format for\n   describing AI agents (including capabilities, I/O specifications,\n   supported languages, tags, authentication methods, etc.), a\n   capability-based discovery mechanism, and a unified RESTful\n   invocation interface.\n\n   This revision refines the discovery mechanism by defining fields for\n   intent-based agent selection.  This capability enables a client, host\n   agent, or orchestration system to describe a task intent and receive\n   a ranked set of candidate agents before invocation, without changing\n   existing discovery or invocation semantics.\n\n   The goal is to enable cross-platform interoperability among AI agents\n   by providing a discover-and-match mechanism and a unified invocation\n   entry point.  Security considerations, including authentication and\n   trust measures, are also discussed.  This specification aims to\n   facilitate the formation of multi-agent systems by making it easy to\n   find the right agent for a task and invoke it in a consistent manner\n   across different vendors and platforms.  Intent-based selection is an\n   application-layer capability and does not define network routing,\n   packet forwarding, path computation, reachability advertisement, or\n   address resolution.\n\nAbout This Document\n\n   This note is to be removed before publishing as an RFC.\n\n   The latest revision of this draft can be found at\n   https://example.com/LATEST.  Status information for this document may\n   be found at https://datatracker.ietf.org/doc/draft-cui-ai-agent-\n   discovery-invocation/.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 1]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   Discussion of this document takes place on the WG Working Group\n   mailing list (mailto:WG@example.com), which is archived at\n   https://example.com/WG.\n\n   Source for this draft and an issue tracker can be found at\n   https://github.com/USER/REPO.\n\n<span>Status of This Memo</span>\n\n   This Internet-Draft is submitted in full conformance with the\n   provisions of BCP 78 and BCP 79.\n\n   Internet-Drafts are working documents of the Internet Engineering\n   Task Force (IETF).  Note that other groups may also distribute\n   working documents as Internet-Drafts.  The list of current Internet-\n   Drafts is at https://datatracker.ietf.org/drafts/current/.\n\n   Internet-Drafts are draft documents valid for a maximum of six months\n   and may be updated, replaced, or obsoleted by other documents at any\n   time.  It is inappropriate to use Internet-Drafts as reference\n   material or to cite them other than as &quot;work in progress.&quot;\n\n   This Internet-Draft will expire on 7 January 2027.\n\n<span>Copyright Notice</span>\n\n   Copyright (c) 2026 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust&#x27;s Legal\n   Provisions Relating to IETF Documents (https://trustee.ietf.org/\n   license-info) in effect on the date of publication of this document.\n   Please review these documents carefully, as they describe your rights\n   and restrictions with respect to this document.  Code Components\n   extracted from this document must include Revised BSD License text as\n   described in Section 4.e of the Trust Legal Provisions and are\n   provided without warranty as described in the Revised BSD License.\n\n<span>Table of Contents</span>\n\n   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . . .   3\n   2.  Conventions and Definitions . . . . . . . . . . . . . . . . .   5\n   3.  Agent Metadata Specification  . . . . . . . . . . . . . . . .   6\n     3.1.  Core Fields . . . . . . . . . . . . . . . . . . . . . . .   6\n     3.2.  Operations and I/O Schema . . . . . . . . . . . . . . . .   8\n     3.3.  Example Agent Metadata  . . . . . . . . . . . . . . . . .   9\n   4.  Agent Discovery Mechanism . . . . . . . . . . . . . . . . . .   9\n     4.1.  Registry Overview . . . . . . . . . . . . . . . . . . . .   9\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 2]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n     4.2.  Agent Registration  . . . . . . . . . . . . . . . . . . .  10\n     4.3.  Querying Agents . . . . . . . . . . . . . . . . . . . . .  11\n       4.3.1.  Attribute-Based Query (Filter)  . . . . . . . . . . .  11\n       4.3.2.  Intent-Based Query  . . . . . . . . . . . . . . . . .  11\n       4.3.3.  Retrieve Single Agent . . . . . . . . . . . . . . . .  12\n   5.  Agent Invocation  . . . . . . . . . . . . . . . . . . . . . .  12\n     5.1.  Invocation Request  . . . . . . . . . . . . . . . . . . .  12\n     5.2.  Invocation Response . . . . . . . . . . . . . . . . . . .  14\n     5.3.  Additional Considerations for Invocation  . . . . . . . .  15\n   6.  Intent-Based Agent Selection  . . . . . . . . . . . . . . . .  16\n     6.1.  Selection Request . . . . . . . . . . . . . . . . . . . .  17\n     6.2.  Selection Response  . . . . . . . . . . . . . . . . . . .  17\n     6.3.  Relationship to Discovery . . . . . . . . . . . . . . . .  18\n     6.4.  Non-Goals . . . . . . . . . . . . . . . . . . . . . . . .  18\n   7.  Backward Compatibility  . . . . . . . . . . . . . . . . . . .  19\n   8.  Security Considerations . . . . . . . . . . . . . . . . . . .  19\n   9.  Example Interaction Flow  . . . . . . . . . . . . . . . . . .  20\n   10. IANA Considerations . . . . . . . . . . . . . . . . . . . . .  20\n   11. References  . . . . . . . . . . . . . . . . . . . . . . . . .  20\n     11.1.  Normative References . . . . . . . . . . . . . . . . . .  20\n     11.2.  Informative References . . . . . . . . . . . . . . . . .  21\n   Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . . .  21\n   Authors&#x27; Addresses  . . . . . . . . . . . . . . . . . . . . . . .  21\n\n1.  Introduction\n\n   As artificial intelligence technologies advance rapidly, AI agents-\n   autonomous software components capable of perceiving their\n   environment, reasoning, and taking actions to achieve goals-have\n   emerged as a powerful paradigm for task execution.  Today, many\n   organizations develop specialized AI agents for various purposes:\n   from text translation and summarization, to code generation, to data\n   analysis and beyond.  These agents are often offered as services,\n   accessible over the network and may be integrated into larger\n   systems.  However, despite the proliferation of AI agents, there is\n   currently no standard protocol for discovering available agents and\n   invoking their capabilities in a uniform way.\n\n   Existing agent frameworks and platforms facilitate building agents\n   but typically operate in isolated ecosystems, making cross-platform\n   or cross-organization agent interoperability difficult.  Each\n   platform tends to define its own APIs for agent description and\n   invocation, which means a client wishing to use agents from multiple\n   sources must adapt to disparate interfaces.  This lack of\n   standardization creates friction, increases integration costs, and\n   hampers the development of multi-agent collaborative systems.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 3]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   This document addresses these issues by proposing a standardized AI\n   Agent Discovery and Invocation Protocol.  The protocol provides:\n\n   1.  *Agent Metadata Specification:* A structured JSON Schema for\n       describing an agent&#x27;s identity, capabilities, inputs, outputs,\n       authentication requirements, and other attributes.  This enables\n       agents to publish their specifications in a machine-readable\n       form.\n\n   2.  *Discovery Mechanism:* A registry-based approach where agents\n       register themselves and clients can search for agents by\n       capability, tags, or intent-based queries.  The registry is\n       language and platform agnostic, facilitating cross-platform\n       discovery.\n\n   3.  *Invocation Interface:* A RESTful API that enables a client\n       (which could be a human user application, another agent, or an\n       orchestration system) to invoke an agent&#x27;s capabilities through a\n       standard endpoint and JSON payloads.\n\n   4.  *Security Considerations:* Guidelines for authentication,\n       authorization, encrypted transport (TLS), and trust\n       establishment, ensuring that discovery and invocation happen\n       securely.\n\n   5.  *Interoperability with Existing Standards:* This specification\n       references existing standards such as JSON Schema, OAuth 2.0\n       [RFC6749], and OpenAPI concepts, and leverages established web\n       technologies for broad compatibility.\n\n   The primary audience for this specification includes developers of AI\n   agent platforms, providers of AI agent services, and system\n   architects building AI-enabled applications or multi-agent systems.\n   By adopting this protocol, an AI agent developer can make their agent\n   accessible to a wide ecosystem, and a client application can\n   integrate AI agents from multiple vendors without custom integration\n   for each.\n\n   This revision refines the discovery mechanism by defining fields for\n   intent-based agent selection.  This capability allows a client, host\n   agent, or coordinator to describe a task intent and receive a ranked\n   set of candidate agents without predetermining which agent to invoke.\n   Intent-based selection does not replace discovery; it can precede or\n   augment the capability-based search defined in earlier sections.\n\n   Some deployments may describe this task-to-agent selection behavior\n   as semantic routing.  In this document, that term is only\n   descriptive: it refers to selecting suitable AI agents for a task at\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 4]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   the application layer.  This document does not define a routing\n   protocol, packet forwarding behavior, path computation, reachability\n   advertisement, DNS behavior, or transport-layer load balancing.\n\n2.  Conventions and Definitions\n\n   The key words &quot;MUST&quot;, &quot;MUST NOT&quot;, &quot;REQUIRED&quot;, &quot;SHALL&quot;, &quot;SHALL NOT&quot;,\n   &quot;SHOULD&quot;, &quot;SHOULD NOT&quot;, &quot;RECOMMENDED&quot;, &quot;NOT RECOMMENDED&quot;, &quot;MAY&quot;, and\n   &quot;OPTIONAL&quot; in this document are to be interpreted as described in\n   BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all\n   capitals, as shown here.\n\n   *  *AI Agent:* An autonomous software component that can perform\n      tasks using artificial intelligence capabilities.  Agents may wrap\n      language models, specialized ML models, or reasoning engines,\n      exposing their abilities via defined interfaces.\n\n   *  *Agent Metadata:* A structured description of an agent, including\n      name, description, capabilities, input/output schemas,\n      authentication requirements, and endpoint information.\n\n   *  *Agent Registry (Discovery Service):* A service that maintains a\n      directory of registered agents and supports queries for\n      discovering agents by attributes or intent-based search.\n\n   *  *Gateway:* (Optional) An intermediary service that forwards or\n      dispatches client requests to appropriate agents.  In some\n      deployments, the registry or another service acts as a gateway to\n      simplify client-to-agent connections.\n\n   *  *Invocation Endpoint:* The URL provided by an agent (or gateway)\n      where clients send requests to invoke the agent&#x27;s capabilities.\n\n   *  *Capability:* A high-level function an agent can perform,\n      identified by a string (e.g., &quot;translation&quot;, &quot;summarization&quot;,\n      &quot;image_classification&quot;).\n\n   *  *Operation:* A specific action supported by an agent.  Some agents\n      may have multiple operations; for example, an agent offering both\n      translation and language detection could list these as separate\n      operations, each with its own input/output schema.\n\n   *  *Task Intent:* A natural-language or structured description of the\n      task that a client wants to accomplish.\n\n   *  *Execution Context:* Information relevant to selecting an agent\n      for a task, such as domain, language, data location, latency\n      needs, user preferences, or environmental constraints.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 5]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   *  *Selection Constraint:* A rule or requirement that constrains\n      agent selection, such as trust level, compliance requirements,\n      cost limits, authentication scope, data residency, or allowed\n      providers.\n\n   *  *Intent-Based Agent Selection:* An application-layer capability\n      that maps a task intent, together with execution context and\n      selection constraints, to one or more candidate agents.\n\n   *  *Candidate Agent:* An agent returned by intent-based selection,\n      together with matching metadata such as match score, selection\n      reason, operation identifier, endpoint, authentication\n      requirements, and invocation requirements.\n\n   *  *Selection Function:* A registry function, coordinator function,\n      or host-agent function that performs intent-based agent selection\n      by matching task intent against registered agent metadata,\n      execution context, and selection constraints.\n\n3.  Agent Metadata Specification\n\n   The Agent Metadata Specification defines a standard JSON document\n   that describes an agent.  All agents that wish to be discoverable and\n   invocable through this protocol MUST provide a metadata document\n   conforming to the schema below.  This metadata is used for agent\n   registration and returned to clients during discovery.\n\n3.1.  Core Fields\n\n   The following are the core fields of an agent metadata document:\n\n   *  *id (string):* A globally unique identifier for the agent.  This\n      could be a UUID, a W3C Decentralized Identifier (DID) [DIDCore],\n      or a similarly unique value, assigned by the registry upon\n      registration or by the agent provider in advance.  This ID is used\n      to refer to the agent in all subsequent operations (e.g.,\n      retrieval or invocation).\n\n   *  *name (string):* A human-readable name for the agent (e.g.,\n      &quot;Chinese-English Translator Agent&quot;).  Names need not be unique but\n      should be descriptive.\n\n   *  *description (string):* A detailed description of the agent, its\n      purpose, and capabilities in natural language.  This helps both\n      human users and selection functions understand what the agent\n      does.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 6]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   *  *version (string):* The version of the agent or its metadata\n      (e.g., &quot;1.0.0&quot;).  This allows tracking of agent updates over time.\n\n   *  *publisher (string):* The name or identifier of the entity\n      publishing the agent (e.g., an organization name or developer\n      name).\n\n   *  *capabilities (array of strings):* A list of capabilities the\n      agent supports.  Capabilities are high-level descriptors (like\n      tags or categories) that clients can filter by.  Examples:\n      [&quot;translation&quot;, &quot;summarization&quot;, &quot;text_generation&quot;].\n\n   *  *tags (array of strings):* Additional tags for search and\n      categorization (e.g., [&quot;nlp&quot;, &quot;chinese&quot;, &quot;transformer_model&quot;,\n      &quot;cloud&quot;]).  Tags differ from capabilities in that they can include\n      broader or orthogonal categories (like domain, language support,\n      deployment model, etc.).\n\n   *  *endpoint (string):* The URL of the agent&#x27;s invocation endpoint.\n      If the agent is behind a gateway, this could be either the direct\n      endpoint or, if direct access is not allowed, a gateway path\n      (e.g., the gateway might provide a unified endpoint like\n      /agents/{id}/invoke and internally forward the request to the\n      actual agent endpoint).  If a shared gateway endpoint is used for\n      multiple agents, the target agent can be identified by the URL\n      path, by gateway-maintained session state, or by an explicit\n      target_agent_id field in the invocation request.\n\n   *  *Location(string, optional):* The location of the registered\n      agent.\n\n   *  *supported_languages (array of strings, optional):* A list of\n      languages the agent supports (e.g., [&quot;en&quot;, &quot;zh&quot;, &quot;fr&quot;]).  For\n      agents dealing with natural language tasks, this field indicates\n      which languages are handled.  If omitted, the agent is either\n      language-agnostic or should not be filtered by language.\n\n   *  *authentication (object, optional):* Describes the authentication\n      mechanism required to invoke the agent.  This object may include:\n\n      -  *type (string):* e.g., &quot;api_key&quot;, &quot;oauth2_bearer&quot;, &quot;mtls&quot;\n         (mutual TLS), &quot;none&quot;.\n\n      -  *instructions (string):* Human-readable note or URL for\n         obtaining credentials.\n\n      -  *scopes (array of strings):* If OAuth 2.0 is used, the OAuth\n         scopes required.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 7]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n      If no authentication is required, this field can be omitted or set\n      with type: &quot;none&quot;.\n\n   *  *status (string, optional):* Operational status of the agent\n      (e.g., &quot;active&quot;, &quot;inactive&quot;, &quot;deprecated&quot;).  The registry may use\n      this to filter out agents that are not currently available.\n\n   *  *available area(string, optional):* It specifies the area of the\n      agent that can be discovered.\n\n   *  *additional fields:* Additional fields may include metadata about\n      rate limits (e.g., max calls per minute), pricing info (if the\n      agent charges per use), or links to documentation.  These are not\n      standardized here but can be included in agent metadata as needed.\n\n3.2.  Operations and I/O Schema\n\n   Each agent MUST describe its input and output formats.  This is done\n   using the *operations* field:\n\n   *  *operations (array of objects):* A list of operations the agent\n      supports.  Each operation object has:\n\n      -  *name (string):* The operation name/identifier (e.g.,\n         &quot;translateText&quot;, &quot;summarize&quot;).\n\n      -  *description (string):* A description of what the operation\n         does.\n\n      -  *inputs (object):* A JSON Schema describing the expected input.\n         This allows clients to understand what data to send.  The JSON\n         Schema can specify required fields, types, enums, media\n         references, or structured objects for different input\n         modalities such as text, images, files, audio, or video.\n\n      -  *outputs (object):* A JSON Schema describing the output format\n         such as text, images, files, audio, or video.\n\n      -  *examples (array of objects, optional):* Example input/output\n         pairs.  Each example is an object {&quot;input&quot;: {...}, &quot;output&quot;:\n         {...}} showing a sample invocation.\n\n   The term &quot;operation&quot; is used because an agent may expose more than\n   one callable action under the same identity and metadata document.\n   For example, one agent might provide separate operations for\n   detectLanguage, translateText, and summarizeText, each with different\n   input and output schemas.  The operation level lets clients select\n   the callable action without treating each action as a separate agent.\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 8]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   If an agent has a single operation, this array will have one element.\n   If it can do multiple distinct tasks, each is listed here.  Some\n   agents may not have structured operations; in that case, the\n   operations field might include a generic operation such as {&quot;name&quot;:\n   &quot;generate&quot;, ...}. For simple agents with one primary function, an\n   alternative is to use top-level inputs and outputs fields directly.\n   This spec allows both styles, but using operations is recommended for\n   future extensibility.\n\n3.3.  Example Agent Metadata\n\n   Below is an example metadata JSON for a translation agent:\n\n   json { &quot;id&quot;: &quot;agent-12345@example.com&quot;, &quot;name&quot;: &quot;Chinese-English\n   Translator&quot;, &quot;description&quot;: &quot;Translates text between Chinese and\n   English with high accuracy using a fine-tuned model.&quot;, &quot;version&quot;:\n   &quot;1.2.0&quot;, &quot;publisher&quot;: &quot;ExampleAI Inc.&quot;, &quot;capabilities&quot;:\n   [&quot;translation&quot;], &quot;tags&quot;: [&quot;nlp&quot;, &quot;chinese&quot;, &quot;english&quot;, &quot;cloud&quot;],\n   &quot;endpoint&quot;: &quot;https://api.example.com/agents/translate&quot;, &quot;location&quot;:\n   &quot;112.40832, 34.636055&quot;, &quot;supported_languages&quot;: [&quot;en&quot;, &quot;zh&quot;],\n   &quot;authentication&quot;: { &quot;type&quot;: &quot;api_key&quot;, &quot;instructions&quot;: &quot;Include &#x27;X-\n   API-Key&#x27; header with your API key.&quot; }, &quot;status&quot;: &quot;active&quot;, &quot;available\n   area&quot;: &quot;shenzhen&quot;, &quot;operations&quot;: [ { &quot;name&quot;: &quot;translateText&quot;,\n   &quot;description&quot;: &quot;Translates text from source language to target\n   language.&quot;, &quot;inputs&quot;: { &quot;type&quot;: &quot;object&quot;, &quot;properties&quot;: { &quot;text&quot;:\n   {&quot;type&quot;: &quot;string&quot;}, &quot;source_language&quot;: {&quot;type&quot;: &quot;string&quot;, &quot;enum&quot;:\n   [&quot;en&quot;, &quot;zh&quot;]}, &quot;target_language&quot;: {&quot;type&quot;: &quot;string&quot;, &quot;enum&quot;: [&quot;en&quot;,\n   &quot;zh&quot;]} }, &quot;required&quot;: [&quot;text&quot;, &quot;source_language&quot;, &quot;target_language&quot;]\n   }, &quot;outputs&quot;: { &quot;type&quot;: &quot;object&quot;, &quot;properties&quot;: { &quot;translated_text&quot;:\n   {&quot;type&quot;: &quot;string&quot;} } }, &quot;examples&quot;: [ { &quot;input&quot;: {&quot;text&quot;: &quot;你好世界&quot;,\n   &quot;source_language&quot;: &quot;zh&quot;, &quot;target_language&quot;: &quot;en&quot;}, &quot;output&quot;:\n   {&quot;translated_text&quot;: &quot;Hello World&quot;} } ] } ] }\n\n   This metadata tells us the agent is an active translation agent for\n   Chinese and English, requires an API key for authentication, and has\n   one operation translateText with a clear input/output schema.\n\n4.  Agent Discovery Mechanism\n\n   The discovery mechanism allows clients to find agents that meet\n   certain criteria.  Discovery is provided by an Agent Registry (or\n   Discovery Service) that aggregates metadata from multiple agents.\n\n4.1.  Registry Overview\n\n   The Agent Registry is a network-accessible service that:\n\n<span>Cui, et al.              Expires 7 January 2027                 [Page 9]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   1.  Allows agents (or their administrators) to register metadata\n       about the agent.\n\n   2.  Stores and indexes these metadata entries for efficient search.\n\n   3.  Provides endpoints for clients to query and retrieve agent\n       information.\n\n   A registry may be operated by an organization for its internal\n   agents, or by a third party acting as a directory of agents across\n   multiple providers.  Multiple registries can coexist;\n   interoperability between registries is facilitated by consistent\n   metadata formats, though formal registry federation is out of scope\n   for this draft.\n\n4.2.  Agent Registration\n\n   An agent (or its administrator) registers with the registry by\n   sending its metadata to a registration endpoint:\n\n   *  *Endpoint:* POST /agents\n\n   *  *Request Body:* The agent metadata JSON document.\n\n   *  *Response:* On success, the registry returns *201 Created* (if a\n      new agent was added) or *200 OK* (if an existing agent was\n      updated), with the stored agent metadata (including the assigned\n      id if the agent did not provide one).  If validation fails (e.g.,\n      missing required fields), the registry returns a *400 Bad Request*\n      with error details.\n\n   The registry MUST validate the metadata against the schema.\n   Registration may require authentication (for example, the registry\n   only allows verified publishers to register agents).\n\n   Updates to an agent&#x27;s metadata (e.g., a new version, changed\n   endpoint, etc.) can be done via a PUT request to the agent&#x27;s entry:\n\n   *  *Endpoint:* PUT /agents/{id}\n\n   *  *Request Body:* Updated metadata.\n\n   *  *Response:* *200 OK* on success; *404 Not Found* if no agent with\n      that ID exists; *403 Forbidden* if the requester is not authorized\n      to update that agent.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 10]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n4.3.  Querying Agents\n\n   Clients query the registry using the search endpoint.  The protocol\n   supports two types of queries:\n\n4.3.1.  Attribute-Based Query (Filter)\n\n   Clients can specify criteria to filter agents by capabilities, tags,\n   supported languages, etc.\n\n   *  *Endpoint:* GET\n      /agents?capabilities=X&amp;tags=Y&amp;language=Z&amp;location=shenzhen\n\n   *  or a structured query via *POST /agents/search* with a JSON body.\n\n   For simplicity, *POST /agents/search* is recommended for more complex\n   queries.  The body might look like:\n\n   json { &quot;filters&quot;: { &quot;capabilities&quot;: [&quot;translation&quot;],\n   &quot;supported_languages&quot;: [&quot;en&quot;, &quot;zh&quot;], &quot;tags&quot;: [&quot;nlp&quot;] }, &quot;top&quot;: 10 }\n\n   This returns up to 10 agents that match all the specified filters.\n   Filters are combined with AND logic (the agent must satisfy all\n   conditions).  Capabilities and tags are matched by set intersection\n   (the agent must have at least the ones listed).\n\n   The response is a JSON array of agent summary objects:\n\n   json [ { &quot;id&quot;: &quot;agent-12345&quot;, &quot;name&quot;: &quot;Chinese-English Translator&quot;,\n   &quot;description&quot;: &quot;...&quot;, &quot;endpoint&quot;: &quot;https://api.example.com/agents/\n   translate&quot;, &quot;capabilities&quot;: [&quot;translation&quot;] }, ... ]\n\n   Summary objects include essential fields to help the client decide\n   which agent to use, without returning the full detailed metadata.  A\n   client can retrieve full metadata via the single-agent endpoint.\n\n4.3.2.  Intent-Based Query\n\n   In addition to attribute-based search, the registry can support\n   intent-based queries where the client describes the task to be\n   performed.  The matching mechanism is implementation-specific and is\n   outside the scope of this document.\n\n   *  *Endpoint:* POST /agents/search\n\n   *  *Request Body:* json { &quot;intent&quot;: &quot;Summarize long legal documents\n      in Chinese.&quot;, &quot;top&quot;: 5 }\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 11]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   The registry returns a ranked list of candidate agents whose metadata\n   matches the task intent.  For example:\n\n   json [ { &quot;id&quot;: &quot;agent-67890&quot;, &quot;name&quot;: &quot;Legal Document Summarizer&quot;,\n   &quot;description&quot;: &quot;...&quot;, &quot;match_score&quot;: 0.93 }, ... ]\n\n   Intent-based queries enable flexible discovery beyond exact filter\n   matching, aligning with how users or orchestrating agents might\n   reason about tasks.  Registries that do not process the intent field\n   can rely on provided filters.\n\n4.3.3.  Retrieve Single Agent\n\n   *  *Endpoint:* GET /agents/{id}\n\n   *  *Response:* Full metadata JSON for the specified agent, or *404*\n      if not found.\n\n5.  Agent Invocation\n\n   Once a client discovers a suitable agent, it invokes the agent by\n   sending a request to the agent&#x27;s endpoint.  This section defines the\n   interface for invocation.\n\n5.1.  Invocation Request\n\n   To invoke an agent, the client sends an HTTP POST request to the\n   agent&#x27;s invocation endpoint with a JSON body containing the input\n   data for the agent&#x27;s task.\n\n   *  *Method:* POST\n\n   *  *URL:* The endpoint URL from the agent&#x27;s metadata (e.g.,\n      https://api.example.com/agents/translate).  If a gateway is used,\n      the URL might be a gateway-provided path.\n\n   *  *Headers:*\n\n      -  Content-Type: application/json\n\n      -  Authentication header as required (e.g., Authorization: Bearer\n         &lt;token&gt; or X-API-Key: &lt;key&gt;).\n\n   *  *Body:* A JSON object containing input data as per the agent&#x27;s\n      input schema.  If a shared gateway endpoint is used and the target\n      agent is not already identified by the URL or authenticated\n      session, the body SHOULD include target_agent_id.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 12]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   For example, invoking the translation agent:\n\n   json { &quot;text&quot;: &quot;Hello, how are you?&quot;, &quot;source_language&quot;: &quot;en&quot;,\n   &quot;target_language&quot;: &quot;fr&quot; }\n\n   This corresponds to the agent&#x27;s expected input fields.  If the agent\n   had multiple operations and a unified endpoint, there might be an\n   additional field to specify which operation or capability to use.\n   For instance, the JSON could include something like &quot;operation_id&quot;:\n   &quot;translateText&quot; if needed.  Alternatively, different operations could\n   be exposed at different URLs (e.g., /agents/xyz/translate vs\n   /agents/xyz/summarize), in which case the operation is selected by\n   the URL and no extra field is required.\n\n   If the request is sent to a gateway endpoint shared by multiple\n   agents, the invocation body can identify the destination agent\n   explicitly:\n\n   json { &quot;target_agent_id&quot;: &quot;agent-12345@example.com&quot;, &quot;operation_id&quot;:\n   &quot;translateText&quot;, &quot;text&quot;: &quot;Hello, how are you?&quot;, &quot;source_language&quot;:\n   &quot;en&quot;, &quot;target_language&quot;: &quot;fr&quot; }\n\n   When a gateway receives such a request, it SHOULD use the\n   target_agent_id, together with registration metadata and local\n   authorization policy, to forward or dispatch the request to the\n   appropriate agent endpoint.  If the target agent is already\n   identified by the gateway URL (for example, /agents/{id}/invoke) or\n   by prior gateway state, the target_agent_id field MAY be omitted.\n\n   Except for common fields such as target_agent_id or operation_id\n   where they are used, the protocol does not fix specific application\n   parameter names; it defers to the agent&#x27;s published schema.  The only\n   requirement is that the client&#x27;s JSON must conform to what the agent\n   expects.  For interoperability, using clear field names and standard\n   data types (strings, numbers, booleans, or structured objects) is\n   encouraged.  Binary data (like images for an image-processing agent)\n   should be handled carefully: typically, binary inputs can be provided\n   either as URLs (pointing to where the data is stored), or as\n   base64-encoded strings within the JSON, or by using a multipart\n   request.  This specification suggests that if agents need to receive\n   large binary payloads, they either use URL references or out-of-scope\n   mechanisms (like a separate upload and then an ID in the JSON).  The\n   core invocation remains JSON-based for simplicity and consistency.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 13]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   *Headers:* If authentication is required (see Security section), the\n   client must also include the appropriate headers (e.g.,\n   Authorization: Bearer &lt;token&gt; or an API key header) as dictated by\n   the agent&#x27;s metadata.  The invocation request may also include\n   optional headers for correlation or debugging, such as a request ID,\n   but those are not standardized here.\n\n5.2.  Invocation Response\n\n   The agent (or gateway) will process the request and return a\n   response.  The status code and JSON body of the response follow these\n   guidelines:\n\n   *  *Success (2xx status):* If the agent successfully performed its\n      task and produced a result, the status SHOULD be *200 OK* (or *201\n      Created* if a new resource was created as a result, though usually\n      for these actions 200 is fine).  The response body will contain\n      the output data in JSON.  Ideally, the output JSON conforms to the\n      agent&#x27;s advertised output schema.\n\n      For example, for the translation request above, a success response\n      might be:\n\n      json { &quot;translated_text&quot;: &quot;Bonjour, comment êtes-vous?&quot; }\n\n      Here the JSON structure matches what was described in the agent\n      metadata&#x27;s outputs.  If the output is complex (e.g., multiple\n      fields or nested objects), those should appear accordingly.  The\n      response can include other informational fields if necessary (for\n      example, some agents might return usage metrics, like tokens used\n      or time taken, or a trace id for debugging, but these are optional\n      and out of scope of the core spec).\n\n   *  *Client Error (4xx status):* If the request was malformed or\n      invalid, the agent returns a *4xx* status code.  The most common\n      would be *400 Bad Request* for a JSON that doesn&#x27;t conform to the\n      expected schema or missing required fields.  For example, if the\n      client omitted a required field target_language, the agent might\n      respond with 400.  The response body SHOULD include an error\n      object explaining what went wrong.  We define a simple standard\n      for error objects:\n\n      json { &quot;error&quot;: { &quot;code&quot;: &quot;InvalidInput&quot;, &quot;message&quot;: &quot;Required\n      field &#x27;target_language&#x27; is missing.&quot; } }\n\n      Here, &quot;code&quot; is a short string identifier for the error type\n      (e.g., InvalidInput, Unauthorized, NotFound), and &quot;message&quot; is a\n      human-readable description.  The agent can include additional\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 14]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n      details if available (e.g., a field name that is wrong, etc.).  If\n      the error is due to unauthorized access, *401 Unauthorized* or\n      *403 Forbidden* should be used (with an appropriate error message\n      indicating credentials are missing or insufficient).  If the agent\n      ID is not found (perhaps the client used an outdated reference),\n      *404 Not Found* is appropriate.\n\n   *  *Server/Agent Error (5xx status):* If something goes wrong on the\n      agent&#x27;s side during processing (an exception, a timeout while\n      executing the task, etc.), the agent (or gateway) returns a *5xx*\n      status (most likely *500 Internal Server Error* or *502/504* if\n      there are upstream issues).  The response should again include an\n      error object.  For example:\n\n      json { &quot;error&quot;: { &quot;code&quot;: &quot;AgentError&quot;, &quot;message&quot;: &quot;The agent\n      encountered an unexpected error while processing the request.&quot; } }\n\n      The agent might log the detailed error internally, but only convey\n      a generic message to the client for security.  A *503 Service\n      Unavailable* might be returned if the agent is temporarily\n      overloaded or offline, indicating the client could retry later.\n\n   *  *Status Codes Summary:* In short, this protocol expects the use of\n      standard status codes to reflect outcome (200 for success, 4xx for\n      client-side issues, 5xx for server-side issues).  Agents should\n      avoid using 2xx if the operation did not semantically succeed\n      (even if technically a response was generated).  For example, if\n      an agent is a composite that calls other services and one of those\n      calls fails, it should propagate an error rather than returning\n      200 with an error in the data.\n\n5.3.  Additional Considerations for Invocation\n\n   *  *Streaming Responses:* Some agents (especially those wrapping\n      large language models) may produce results that are streamed (for\n      example, token-by-token outputs).  While this base protocol\n      assumes a request-response pattern with the full result delivered\n      at once, it can be extended to support streaming by using chunked\n      responses or WebSockets.  For instance, an agent might accept a\n      parameter like stream: true and then send partial outputs as they\n      become available.  This is an advanced use case and not elaborated\n      in this draft, but implementers should consider compatibility with\n      streaming if real-time responsiveness is needed.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 15]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   *  *Batch Requests:* If a client wants to send multiple independent\n      requests to an agent in one go (for efficiency), the protocol can\n      support that by allowing an array of input objects in the POST\n      body instead of a single object.  The response would then be an\n      array of output results.  This is optional and depends on agent\n      support.\n\n   *  *Idempotency and Retries:* Most agent invocations are not strictly\n      idempotent (since an agent might perform an action or have side\n      effects), but many are pure functions (e.g., translate text).\n      Clients and gateways should design with retry logic carefully - if\n      a network failure happens, a retry might re-run an operation.\n      It&#x27;s best to ensure that agents&#x27; operations are either idempotent\n      or have safeguards (for example, an operation that sends an email\n      might have an idempotency key).\n\n   *  *Operation Metadata:* In cases where the agent defines multiple\n      operations in its metadata, the invocation interface might allow a\n      generic endpoint that accepts an operation name.  Alternatively,\n      each operation could be a sub-resource.  This draft leaves the\n      exact mechanism flexible: an implementation could choose one of\n      these approaches.  The key is that the invocation uses POST and a\n      JSON body following the agent&#x27;s schema.\n\n6.  Intent-Based Agent Selection\n\n   Intent-based agent selection is a capability of the discovery\n   mechanism defined in this document.  It enables a client, host agent,\n   or orchestration system to describe a task intent and receive one or\n   more candidate agents prior to invoking any specific agent.\n\n   This capability is intended for cases where the requester knows what\n   task should be performed, but does not know in advance which agent,\n   operation, provider, or deployment should perform it.  An\n   implementation can use semantic matching, metadata filtering,\n   constraint evaluation, and ranking to produce a candidate set.\n\n   It operates on the following conceptual model:\n\n   (Task Intent, Execution Context, Selection Constraints) -&gt; Ranked\n   Candidate Agent Set\n\n   The task intent represents the work to be performed.  The execution\n   context supplies information that can affect selection, such as\n   language, domain, data location, latency requirements, or user\n   preferences.  Selection constraints express requirements that MUST or\n   SHOULD be satisfied, such as trust level, certification, access\n   control, cost limits, or data residency.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 16]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   Intent-based selection returns candidate agents rather than directly\n   invoking an agent.  A client MAY invoke one of the returned agents\n   using the invocation mechanism defined in this document, MAY retrieve\n   additional metadata before invocation, or MAY decline all returned\n   candidates.\n\n   This document defines only the information that can be exchanged to\n   support intent-based selection before normal invocation.\n\n6.1.  Selection Request\n\n   A registry that supports intent-based selection MAY expose this\n   capability through the existing POST /agents/search endpoint or\n   through another deployment-specific endpoint.  The following request\n   body illustrates the information model:\n\n   For example:\n\n   json { &quot;intent&quot;: &quot;Summarize a long Chinese legal contract and\n   identify unusual risk clauses.&quot;, &quot;context&quot;: { &quot;language&quot;: &quot;zh&quot;,\n   &quot;domain&quot;: &quot;legal&quot;, &quot;data_location&quot;: &quot;cn&quot;, &quot;latency_ms&quot;: 3000 },\n   &quot;constraints&quot;: { &quot;required_trust_level&quot;: &quot;verified&quot;,\n   &quot;data_residency&quot;: &quot;cn&quot;, &quot;max_price_per_call&quot;: &quot;0.10&quot; }, &quot;top&quot;: 3 }\n\n   The intent field SHOULD describe the desired outcome rather than\n   naming a specific agent.  The context and constraints fields are\n   optional, but implementations SHOULD treat selection constraints as\n   binding requirements when their semantics are understood.\n\n6.2.  Selection Response\n\n   The response is a ranked list of candidate agents.  Each candidate\n   identifies an agent and MAY include the operation identifier,\n   endpoint, match score, selection explanation, constraint evaluation\n   result, and invocation metadata.\n\n   For example:\n\n   json [ { &quot;agent_id&quot;: &quot;agent-67890&quot;, &quot;name&quot;: &quot;Legal Contract Analysis\n   Agent&quot;, &quot;operation_id&quot;: &quot;summarizeAndAssessRisk&quot;, &quot;endpoint&quot;:\n   &quot;https://api.example.com/agents/legal-contract&quot;, &quot;match_score&quot;: 0.94,\n   &quot;selection_reason&quot;: &quot;Matches Chinese legal summarization and risk-\n   clause analysis requirements.&quot;, &quot;constraint_result&quot;: { &quot;trust_level&quot;:\n   &quot;verified&quot;, &quot;data_residency&quot;: &quot;cn&quot; }, &quot;authentication&quot;: { &quot;type&quot;:\n   &quot;oauth2_bearer&quot;, &quot;scopes&quot;: [&quot;agent.invoke&quot;, &quot;legal.analysis&quot;] },\n   &quot;expires_at&quot;: &quot;2026-07-02T12:00:00Z&quot; } ]\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 17]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   The match_score field is a relative ranking signal whose scale is\n   implementation-specific unless otherwise documented by the registry.\n   The selection_reason field is intended to support transparency and\n   debugging; clients MUST NOT treat it as a security assertion.  If\n   expires_at is present, the client SHOULD NOT rely on the candidate\n   after that time without repeating selection or discovery.\n\n6.3.  Relationship to Discovery\n\n   Intent-based selection and discovery are complementary.  Discovery\n   allows clients to search for agents by known attributes, tags,\n   capabilities, or intent terms.  Intent-based selection allows clients\n   to provide a task intent and receive a ranked candidate set that may\n   reflect semantic fit, context, and selection constraints.\n\n   An implementation MAY provide intent-based selection as part of an\n   Agent Registry, or as a function of a host agent or coordinator.\n   Regardless of deployment model, it does not change the agent metadata\n   format or invocation interface defined by this document.\n\n6.4.  Non-Goals\n\n   Intent-based selection explicitly does not define or replace:\n\n   *  IP routing or packet forwarding\n\n   *  Path computation or next-hop selection\n\n   *  Reachability advertisement\n\n   *  DNS or name-to-address resolution\n\n   *  Transport-layer load balancing\n\n   *  Service mesh traffic routing\n\n   *  Agent invocation semantics\n\n   *  Global or persistent agent identifiers\n\n   Intent-based selection answers the question &quot;Which agent or agents\n   are suitable for this task under the current context and\n   constraints?&quot;  It does not answer &quot;How should network traffic reach a\n   destination?&quot; or &quot;Where is a named service located on the network?&quot;.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 18]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n7.  Backward Compatibility\n\n   All discovery and invocation mechanisms defined in previous revisions\n   of this document remain valid and unchanged.\n\n   Intent-based agent selection is optional for baseline protocol\n   conformance.  Implementations MAY support this capability\n   incrementally, and registries MAY provide intent-based selection\n   without affecting existing clients.  Intent-based selection is\n   RECOMMENDED for deployments that support dynamic agent selection,\n   multi-agent orchestration, or intent-driven task delegation.\n\n8.  Security Considerations\n\n   Security is a critical aspect of this protocol.  All discovery and\n   invocation traffic MUST be protected with TLS [RFC8446], and\n   authentication mechanisms such as OAuth 2.0 [RFC6749] bearer tokens,\n   API keys, or mutual TLS are required except for public discovery\n   endpoints.  Registries MUST enforce per-client entitlements, ensuring\n   that both search results and invocation access respect permissions\n   and scopes.  Gateways forwarding requests should authenticate\n   themselves to agents, and agents should maintain stable identifiers\n   and use signed responses when integrity is essential.  All\n   communication MUST be encrypted, and agents are encouraged to\n   disclose data-retention or logging practices, while sensitive data is\n   best handled by on-premises or certified agents.  To mitigate abuse,\n   registries and agents MUST implement rate limiting and quotas,\n   particularly in intent-based search scenarios.  Trust mechanisms such\n   as certification, test harnesses, or reputation systems may be used\n   to validate agent claims, and metadata fields like &quot;certification&quot; or\n   &quot;quality_score&quot; can inform client trust decisions.  Systems SHOULD\n   also provide audit and logging with privacy-aware retention, while\n   clients must treat agent outputs as untrusted until verified, using\n   sandboxing and validation before executing code or commands.\n\n   When a gateway accepts target_agent_id in an invocation request, it\n   MUST verify that the requester is authorized to invoke the identified\n   agent and operation.  A gateway MUST NOT treat a client-provided\n   target_agent_id as sufficient proof of authorization.\n\n   When intent-based selection is used, security considerations extend\n   to the pre-invocation phase.  Implementations SHOULD validate agent\n   capability claims, apply selection constraints, and exclude agents\n   that do not meet trust or reputation requirements.  Agents deemed\n   unsafe SHOULD NOT be returned as candidate agents.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 19]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n9.  Example Interaction Flow\n\n   1.  *Search or Select:* Client POST /agents/search with\n       {&quot;intent&quot;:&quot;summarize an English financial report and identify\n       risk factors&quot;,&quot;context&quot;:{&quot;language&quot;:&quot;en&quot;,&quot;domain&quot;:&quot;finance&quot;},\n       &quot;constraints&quot;:{&quot;required_trust_level&quot;:&quot;verified&quot;},&quot;top&quot;:3}.\n\n   2.  *Select Candidate:* Registry returns ranked candidate agents with\n       agent_id, name, operation_id, endpoint, match_score,\n       selection_reason, and invocation metadata.  Client may retrieve\n       full metadata via GET /agents/{id} if needed.\n\n   3.  *Invoke:* Client POST to the selected agent&#x27;s endpoint (or\n       gateway path) with inputs conforming to the selected operation\n       schema and required authentication header.\n\n   4.  *Handle Response:* Client processes the success or error\n       response; it may log usage and optionally provide feedback to the\n       registry.\n\n10.  IANA Considerations\n\n   This document has no IANA actions.\n\n11.  References\n\n11.1.  Normative References\n\n   [RFC2119]  Bradner, S., &quot;Key words for use in RFCs to Indicate\n              Requirement Levels&quot;, BCP 14, RFC 2119,\n              DOI 10.17487/RFC2119, March 1997,\n              &lt;https://www.rfc-editor.org/rfc/rfc2119&gt;.\n\n   [RFC6749]  Hardt, D., Ed., &quot;The OAuth 2.0 Authorization Framework&quot;,\n              RFC 6749, DOI 10.17487/RFC6749, October 2012,\n              &lt;https://www.rfc-editor.org/rfc/rfc6749&gt;.\n\n   [RFC8174]  Leiba, B., &quot;Ambiguity of Uppercase vs Lowercase in RFC\n              2119 Key Words&quot;, BCP 14, RFC 8174, DOI 10.17487/RFC8174,\n              May 2017, &lt;https://www.rfc-editor.org/rfc/rfc8174&gt;.\n\n   [RFC8259]  Bray, T., Ed., &quot;The JavaScript Object Notation (JSON) Data\n              Interchange Format&quot;, STD 90, RFC 8259,\n              DOI 10.17487/RFC8259, December 2017,\n              &lt;https://www.rfc-editor.org/rfc/rfc8259&gt;.\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 20]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   [RFC8446]  Rescorla, E., &quot;The Transport Layer Security (TLS) Protocol\n              Version 1.3&quot;, RFC 8446, DOI 10.17487/RFC8446, August 2018,\n              &lt;https://www.rfc-editor.org/rfc/rfc8446&gt;.\n\n   [RFC9110]  Fielding, R., Ed., Nottingham, M., Ed., and J. Reschke,\n              Ed., &quot;HTTP Semantics&quot;, STD 97, RFC 9110,\n              DOI 10.17487/RFC9110, June 2022,\n              &lt;https://www.rfc-editor.org/rfc/rfc9110&gt;.\n\n11.2.  Informative References\n\n   [AutoGen]  Wu, Y. and et. al., &quot;AutoGen: Enabling Next-Gen LLM\n              Applications via Multi-Agent Conversation&quot;,\n              arXiv:2308.08155 , 2023.\n\n   [DIDCore]  W3C, &quot;Decentralized Identifiers (DIDs) v1.0&quot;, 2022,\n              &lt;https://www.w3.org/TR/did-core/&gt;.\n\n   [LangChain]\n              Chase, H., &quot;LangChain: Building Applications with LLMs\n              through Composition&quot;, 2023, &lt;https://www.langchain.com/&gt;.\n\n   [RosenbergDraft]\n              Rosenberg, J., &quot;AI Protocols&quot;, draft-rosenberg-ai-\n              protocols-00 , 2023.\n\n   [ServiceMesh]\n              Buisson, J., &quot;Service Mesh: The Next Step in\n              Microservices&quot;, Communications of the ACM, Vol. 63 No. 12,\n              December 2020 , 2020.\n\n<span>Acknowledgments</span>\n\n   TODO acknowledge.\n\n<span>Authors&#x27; Addresses</span>\n\n   Yong Cui\n   Tsinghua University\n   Beijing, 100084\n   China\n   Email: cuiyong@tsinghua.edu.cn\n   URI:   http://www.cuiyong.net/\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 21]</span>\n<span>Internet-Draft                    AIDIP                        July 2026</span>\n\n   Yihan Chao\n   Zhongguancun Laboratory\n   Beijing, 100094\n   China\n   Email: chaoyh@zgclab.edu.cn\n\n   Chenguang Du\n   Zhongguancun Laboratory\n   Beijing, 100094\n   China\n   Email: ducg@zgclab.edu.cn\n\n<span>Cui, et al.              Expires 7 January 2027                [Page 22]</span>\n</pre>\n                </div>\n            </div>\n            \n        \n    \n                    \n                </div>\n            </div>\n        </main>\n        \n            <footer class=\"col-md-12 col-sm-12 border-top mt-5 py-5 bg-light-subtle text-center position-sticky\">\n                <a href=\"https://www.ietf.org/\" class=\"p-3\">IETF</a>\n                <a href=\"https://www.ietf.org/iesg/\" class=\"p-3\">IESG</a>\n                <a href=\"https://www.iab.org/\" class=\"p-3\">IAB</a>\n                <a href=\"https://www.irtf.org/\" class=\"p-3\">IRTF</a>\n                <a href=\"https://www.ietf.org/llc/\" class=\"p-3 text-nowrap\">IETF LLC</a>\n                <a href=\"https://trustee.ietf.org/\" class=\"p-3 text-nowrap\">IETF Trust</a>\n                <a href=\"https://www.rfc-editor.org/\" class=\"p-3 text-nowrap\">RFC Editor</a>\n                <a href=\"https://www.iana.org/\" class=\"p-3\">IANA</a>\n                <a href=\"https://www.ietf.org/privacy-statement/\" class=\"p-3 text-nowrap\">Privacy Statement</a>\n                <div class=\"small text-body-secondary py-3\">\n                    \n                        <a class=\"mx-2\" href=\"/release/about\">About IETF Datatracker</a>\n                        <span class=\"mx-2\">\n                            \n                                <a href=\"https://github.com/ietf-tools/datatracker/releases/tag/12.75.0\">\n                            \n                            Version 12.75.0\n                            (release - a9042bf)\n                            \n                                </a>\n                            \n                        </span>\n                    \n                    <a class=\"mx-2\" href=\"https://status.ietf.org\" target=\"_blank\">System Status</a>\n                    <span class=\"mx-2 text-danger\">\n                        <i class=\"bi bi-bug\"></i>\n                        Report a bug:\n                        <a class=\"text-reset\" target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">GitHub</a>\n                        \n                            <a class=\"text-reset\" href=\"mailto:tools-help@ietf.org\">Email</a>\n                        \n                    </span>\n                    \n                </div>\n            </footer>\n        \n        \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/d3.js\">\n        </script>\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/document_timeline.js\">\n        </script>\n    \n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/select2.js\"></script>\n        <script src=\"https://static.ietf.org/dt/12.75.0/ietf/js/navbar-doc-search.js\"></script>\n      \n<script>\n  var _paq = window._paq || [];\n  \n  _paq.push(['disableCookies']);\n  _paq.push(['trackPageView']);\n  _paq.push(['enableLinkTracking']);\n  (function() {\n    var u=\"//analytics.ietf.org/\";\n    _paq.push(['setTrackerUrl', u+'matomo.php']);\n    _paq.push(['setSiteId', 7]);\n    var d=document, g=d.createElement('script'), s=d.getElementsByTagName('script')[0];\n    g.type='text/javascript'; g.async=true; g.defer=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);\n  })();\n</script>\n<noscript><p><img src=\"//analytics.ietf.org/matomo.php?idsite=7\" style=\"border:0;\" alt=\"\" /></p></noscript>\n\n    <script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a3ba8f888f946cb7',t:'MTc4OTUwNjAyMw=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\n</html>\n","snapshot_chars":91822,"live_check":"changed"}]}