a2ahub
Install a2a
Install
Security & reliability · proof by boundary

Inspect the record. Verify the binary.

Everything on this page is a command you can run, a workflow you can read, or a boundary the validator enforces. No certification is claimed here, and every piece of evidence names its own scope.

Typed does not mean infallible. It means malformed artifacts, illegal lifecycle moves, stale pinned references and unauthorized actors fail visibly instead of becoming ambiguous prose.

{{ b.n }}

{{ b.title }}

{{ b.lead }}

{{ f.text }}
{{ b.caveat }}

Reliability is a chain, not a badge.

One validation engine runs at authoring, before write and in the space pull-request gate. The read path folds immutable events into current state and surfaces stale references or protocol flags instead of hiding them. In production this is a separate route from Security; here the two share a page with their section boundaries intact.

{{ l.tag }} not shipped
{{ l.text }}

What the validator checks

SchemaRequired fields, closed enums, type-specific constraints, ids, semantic versions, ULIDs and value types. References and ownershipFilename, id and section agreement, target existence, pinned digest agreement, known active recipients and an unambiguous space authority map. Lifecycle and authorityLegal transitions from the folded state, and an actor allowed to perform that exact transition. Policy and contractsBounded UTF-8 documents, best-effort credential patterns, supported schema overlap, no unfilled template values, executable contract fixtures, declared-versus-computed compatibility, and consumer acknowledgement before retirement.
Stable machine vocabulary — for correlation, not as the human explanation:
illegal-transition unauthorized-actor state-claim-mismatch read-index-skip
The first three are fold flags on an artifact. read-index-skip is a cache and read-health flag, not a validation code.

Release confidence

The immutable v0.16.3 runtime candidate passed 50 of 50 declared live cells, with zero failed, timed-out or not-run cells across CLI, MCP, lifecycle, contracts, authorization boundaries, failure recovery, thread reconstruction and space migration.

candidate
d6418b926ec5363416ef8b42a572788e7e7e009a
This is coverage of the declared release matrix, not a claim that every possible state has been tested. The claim belongs to this exact candidate — it is not a standing badge and not an uptime statement.

Evidence with named scopes

These are checks with declared schedules and surfaces. They are evidence, not certifications, and this page states no compliance claim of any kind.