TL;DR: Why Agents Need a Passport: .fafa — Portable Identity for the Agentic Era is now on Zenodo. It defines .fafa as a declarative YAML passport for agent identity — who an agent is, what it may do, where it's reached, and what it must never do.

The paper

Identity inferred from a prompt or assembled from a protocol card doesn't travel cleanly between hosts, sessions, and models. The paper's claim: an agent needs its own portable passport, separate from any single protocol's card format.

  • The four questions a passport answers — who, may-do, reached-where, must-never
  • Lifecycle: author → serve → discover → project
  • Relationship to A2A Agent Cards, MCP Server Cards, and AGENTS.md
  • Security posture: declaration is not authorization

.fafa (application/vnd.fafa+yaml, IANA-registered June 2026) complements these existing surfaces. It does not replace them.

Read it

DOI: 10.5281/zenodo.21951641 · CC BY 4.0 · FAF Foundation

Companion Internet-Draft: draft-wolfe-faf-agent-01

See it live

The passport this paper describes is already served, not just specified:

curl https://faf.one/.well-known/fafa

Content-Type application/vnd.fafa+yaml. Source of truth: github.com/Wolfe-Jam/faf-agent.

Related