1 day
AI Catalog #37 merged 2026-06-25.
ce31cbd fix: conform AI Catalog to post-#37 spec
Five cards. One map.
Machines find an agent or a server through cards — small files they read. There are several, they overlap, and they ask the same things in different words. Every one of these specs lives in public git, so we read every version and drew them as one map.
MCP Registry server.json is the MCP Registry entry — how a server is published to a registry, rather than a card a server serves at its own door. It is not on the map, and it is the piece FAF writes today:
faf cards --target registrymodelcontextprotocol/registry · first in git 2025-07-02
Five, in the order the map draws them. No ranking: distance on the map means different, not better.
West to east, one line per card. The dashed line is the centre: the choices most cards share. A line's distance from it is how many of its choices no other card makes. Stations are spaced by order, not by calendar. Ticks link to the spec at that commit.
| Card | Distance (of 8) | Choices only it makes | Required fields |
|---|---|---|---|
| A2A Agent Card | 5 | identity, discovery, extension, trust, versioning | 8 |
| MCP Server Card | 4 | naming, identity, extension, versioning | 4 |
| AI Catalog | 3 | extension, trust, versioning | 3 |
| ARD | 4 | discovery, encoding, extension, trust | 4 |
| .fafa | 6 | identity, type, encoding, extension, trust, versioning | 4 |
30 spec versions · 269 quotes, each checked against the line it cites.
Every card picks a way to name itself, to identify what it describes, to be found, to declare its type, to encode, to extend, to carry trust, and to version. Where they agree is the centre of the map; where only one card picks a value, that is its distance. Open a cell for the words the spec uses.
| Card | naming | identity | discovery | type | encoding | extension | trust | versioning |
|---|---|---|---|---|---|---|---|---|
| A2A Agent Card v1.0.1 | namestring name = 1 [(google.api.field_behavior) = REQUIRED]; Unchanged from v1.0.0. the line it cites every version | urlThe URL where this interface is available. Must be a valid absolute HTTPS URL in production. Unchanged: endpoint in REQUIRED `supportedInterfaces[].url` (L339). Changed nearby: optional AgentInterface.tenant is now described as "An opaque string used for routing requests to a specific agent or tenant when multiple agents are served behind a single A2A endpoint" (L344-L345); the protocol "does not define its format or semantics" (L349). the line it cites every version | /.well-known/agent-card.jsonAccessing `https://{server_domain}/.well-known/agent-card.json` §14.3 template unchanged (L3328, L3337). IANA's well-known URI registry lists `agent-card.json` as permanent (checked 2026-09-15). the line it cites every version | none · noneThe resource at this URI MUST return an AgentCard object as defined in Section 4.4.1 of the A2A specification. Still no media type for the card at the well-known URI. Changed here: the REST binding now says "application/a2a+json **SHOULD** be used for requests and responses" (L2750), which covers `GET /extendedAgentCard`; the JSON-RPC binding keeps `application/json` (L2236). `application/a2a+json` is still not in IANA's application registry (checked 2026-09-15). the line it cites every version | jsonA JSON metadata document published by an A2A Server, describing its identity, capabilities, skills, service endpoint, and authentication requirements. Unchanged: proto is normative; JSON uses camelCase (§5.5, L1204). the line it cites every version | capabilities.extensionsA list of protocol extensions supported by the agent. `repeated AgentExtension extensions = 3;` (L417). Unchanged. the line it cites every version | jws-signatureAgent Cards **MAY** be digitally signed using JSON Web Signature (JWS) Unchanged: JCS (RFC 8785) canonicalization before signing (L2008); `signatures` optional (proto L395). the line it cites every version | supportedInterfaces[].protocolVersionThe version of the A2A protocol this interface exposes. REQUIRED (L354). Unchanged. Appendix A.2.1 still mentions an AgentCard `protocolVersions` field (L3509, L3517). the line it cites every version |
| MCP Server Card Latest (SEP-pinned snapshot 526201bb) | title (optional)Optional human-readable title or display name for the MCP server. `title?: string` (L81). Clients read `title` from the card, not the catalog entry (docs/discovery.md L54-L55). the line it cites every version | reverse-dnsServer name in reverse-DNS format. Must contain exactly one forward slash Pattern `^[a-zA-Z0-9.-]+/[a-zA-Z0-9._-]+$` (L50). The valid example examples/ServerCard/valid/minimal.json uses `example-org/minimal`, with no dot. Catalog-level identifier: `urn:air:{publisher}:{namespace}:{name}` (docs/discovery.md L48). the line it cites every version | via:/.well-known/ai-catalog.jsonFetch `https://{domain}/.well-known/ai-catalog.json` Card location: 'MCP Servers MAY host their Server Card at `GET <streamable-http-url>/server-card`, which we reserve for this purpose, though any unreserved URI (on any domain) is valid' (L174-L175). SEP 5c8483d L90: 'Cards can be hosted at any unreserved URI, with `<streamable-http-url>/server-card` reserved as the recommended location.' the line it cites every version | application/mcp-server-card+json · de-factoServer Cards use the media type `application/mcp-server-card+json`. Not in the IANA application media-type registry (checked 2026-09-15); the only 'mcp' matches are unrelated vnd.3gpp.mcptt-* types. Clients SHOULD send `Accept: application/mcp-server-card+json` (L182). the line it cites every version | jsonAn **MCP Server Card** is a JSON document that describes a single MCP serverthe line it cites every version | _metaextension metadata, which remains the card's extension point. The line begins 'Vendors who genuinely need to attach install hints to a Server Card can use namespaced [`_meta`]'. schema.ts L115 and L121 define `_meta?: MetaObject`. SEP 5c8483d L89: '`_meta` is not used to advertise MCP capabilities or negotiated extension support.' the line it cites every version | noneClients MUST NOT treat Server Card contents as authoritative for security or Advisory only. The 'Server Card Accuracy' security note (L229-L238) calls an inaccurate card 'a mild confusion or downgrade vector'. Hosted cards MUST use HTTPS, TLS 1.2 or later, in production (L273). No signature or trust manifest. the line it cites every version | $schema, version, remotes[].supportedProtocolVersionsSchema URLs are versioned by the `vN` segment rather than by date; a $schema must equal `https://static.modelcontextprotocol.io/schemas/v1/server-card.schema.json` (L35, L40). version = server version, 'Equivalent of `Implementation.version`' (L55-L57). remotes[].supportedProtocolVersions = 'MCP protocol versions actively supported by this remote endpoint' (L199-L202). README.md L63: 'The `v1` shape is still pre-release and card-only'. the line it cites every version |
| AI Catalog latest (#100) | displayName (optional)? displayName: text, Prose: listed under OPTIONAL (L259, L261). Resolution order (L342): entry displayName, then the artifact's own name, then the identifier's trailing segment. the line it cites every version | urn:airthe standard `urn:air` naming structure is **HIGHLY RECOMMENDED** and **MUST** be used for open or federated systems. Open-text field ('any valid URI or URN is accepted', same line). Format `urn:air:{publisher}:{namespace}:{name}` (L209). the line it cites every version | /.well-known/ai-catalog.json/.well-known/ai-catalog.json OPTIONAL; a catalog MAY be served from any URL. Link relation `ai-catalog` (L1256). Registration sections: link relation (L1629), well-known URI (L1645). Neither is in the IANA registries (checked 2026-09-15); IANA lists only RFC 9727 `api-catalog`. the line it cites every version | application/ai-catalog+json · de-factoapplication/ai-catalog+json Registration section L1582. `curl https://www.iana.org/assignments/media-types/application.csv | grep -i catalog` on 2026-09-15 returns no ai-catalog entry. the line it cites every version | jsonAn AI Catalog document is a JSON object that MUST contain the followingthe line it cites every version | extensions-maprepresent the extension type (namespace), and the corresponding value contains the extension data. Keys 'MUST be a valid URL or a reverse-DNS string' (L1121-1122). Entry `extensions` L326; catalog top level L151; Trust Manifest L612. the line it cites every version | trust-manifest+jwscontain at least one *substantive* trust member: `trustManifest` is OPTIONAL (L553-555). Trust Manifest `signature` is a detached JWS (L604-605); optional top-level catalog `signature` JWS (L156-157). The CDDL still lacks the top-level `signature` (L1670-1675) and TrustManifest `subject`/`issuedAt`/`expiresAt` (L1709-1719). the line it cites every version | specVersion`specVersion` 'Major.Minor' format (L104); Version Handling section L1174. the line it cites every version |
| ARD latest (v0.91) | displayName| displayName | MUST | Human-readable name. | Row of the table introduced by 'An ARD entry MUST carry:' (L86). the line it cites every version | urn:airDomain-anchored URN form (`urn:air:<publisher>:<namespace>:<agent-name>`); see Appendix C. The JSON-LD @id MAY mirror the identifier (L90). ard-entry.schema.json pattern ^urn:air:... (L26). the line it cites every version | /.well-known/ard.jsonHosting a manifest of entries at `https://{domain}/.well-known/ard.json`. Link relation: rel="ard" (L199). A consumer MUST fetch /.well-known/ard.json and MUST honour rel="ard"; it MAY also consult the predecessor /.well-known/ai-catalog.json and rel="ai-catalog" (L202). A publisher on the predecessor path SHOULD move to ard.json (L204). In-page JSON-LD markup (L197), Agentmap and DNS (L200) are also listed. the line it cites every version | none · noneThe manifest is a JSON document with an `entries` array of ARD entries (§4) No media type is defined for the manifest document. Entry `type` is the artifact's IANA media type (L92); registries are found through entries whose type is application/ai-registry+json (L215). The application/ai-catalog+json nested-catalog examples are gone. the line it cites every version | json-ldAn entry is a JSON-LD node describing an agentic resource. Per entry. A consumer MUST expand an entry with the ARD base context (L80; spec/schemas/ard.context.jsonld). Carrying @context in the entry is OPTIONAL (L82). The /.well-known/ard.json manifest itself is 'a JSON document' (L196). the line it cites every version | json-ld-contextTerms from any additional namespace declared in the entry's `@context` MAY also appear Such terms become filter dimensions with no spec change (L108). `metadata` remains an optional descriptive term (L106). The schema sets additionalProperties: true by design (L530); ard.cddl ard-entry ends with a `* tstr => any` wildcard (L25). the line it cites every version | trust-manifestARD does not define a signing or verification procedure of its own. trustManifest is optional; ARD requires only trustManifest.identity (L173), whose trust domain MUST align with the URN publisher (L177). Signing, canonicalization and key resolution come from the framework named in trustManifest.trustSchema (L181). ard-entry.schema.json L170 no longer names JWS. The schema's entry property key is `TrustManifest` (L81); the spec, ard.cddl (L45) and the base context use `trustManifest`. the line it cites every version | not specifiedARD requires only an `entries` array of ARD entries ArdManifest requires only entries (L106); other top-level members are transport-defined and ignored by ARD. ard.cddl ard-manifest is entries plus a wildcard (L13-L15). specVersion is no longer defined. The base context URL ends /context/v1 (spec L78) and entry `version` is the artifact version; neither is a spec-version field. the line it cites every version |
| .fafa v1.0 IANA-registered + DOI (latest) | agent.name**Required:** `name` (Unicode string, unique within the issuing vendor namespace) The spec text still has no display-name field. The companion schema schemas/fafa.schema.json documents an optional `agent.displayName` from 9e79b6914b6cb0ef6df299e52de17ccc47657a5e (2026-07-05), and FAFA's published card uses it (agent.fafa L9). See notes. the line it cites every version | agent-id`id` (globally unique identifier — DID, URI, or vendor-scoped UUID) Practice: FAFA's card uses `id: did:web:faf.one:agent`. the line it cites every version | noneIt does not define discovery, transport, authorization, or orchestration. Spec unchanged. Practice only (not in spec): faf.one serves FAFA's card at /.well-known/fafa with Content-Type application/vnd.fafa+yaml (checked 2026-09-15). The one well-known URI request filed is for /.well-known/faf (protocol-registries/well-known-uris#97, open, labels 'new registration' and 'waiting for stable reference'). No request covers /.well-known/fafa. the line it cites every version | application/vnd.fafa+yaml · iana-registered(registered 2026-06-26, last updated 2026-06-26) Spec at this SHA: L5 '**MIME Type:** `application/vnd.fafa+yaml`', L7 '**IANA Registration:** Registered 2026-06-26 (vendor tree)' (https://github.com/Wolfe-Jam/faf/blob/190c3380847c022da3e13a28af57c4dc68b3e02c/AGENT-FORMAT.md#L7). The IANA record's 'Published specification' is https://github.com/Wolfe-Jam/faf/blob/main/AGENT-FORMAT.md. the line it cites every version | yamlA `.fafa` file is a single YAML document: §13 (L216): YAML 1.2 / RFC 9512. the line it cites every version | metadata-object**Optional top-level fields:** `attachment`, `provenance`, `signature`, `metadata` (free-form vendor extensions). §13 (L219): forward-compat rule for unknown top-level fields and unknown agent/capabilities/endpoints subfields. It does not name `provenance` subfields. the line it cites every version | other:optional signature object (method, value); signing scheme unspecifiedWhere present, `signature` carries provenance/integrity material; verification is the consumer's responsibility. Unchanged. FAFA's published card carries no `signature` block. the line it cites every version | versionThe top-level `version` field declares which version of this specification the document conforms to. Spec §16 (L252) lists 'Optional parameters: version', but the IANA record says 'Optional parameters: N/A' and 'versioning is handled in-band via the top-level "version" field'. the line it cites every version |
The specs move, and we move with them. Every FAF change below sits in a public repo, so each links to the commit. 54 spec events, 4 FAF surfaces.
AI Catalog #37 merged 2026-06-25.
ce31cbd fix: conform AI Catalog to post-#37 spec
AI Catalog #77 merged 2026-07-30. We answered in 3 days — and used the wrong container.
4d0d914 chore: conform ai-catalog.json to ADR-0017 (metadata→extensions array, remove legacy mediaType)
bf5fb3f fix(ai-catalog): serve extensions as a map, not an array
Working group parsers rejected the document in between. Speed is not currency on its own — the check is.
| Spec | Merged | FAF | Lag | Commit says |
|---|---|---|---|---|
| AI Catalog ADR-0016 | 2026-06-18 | 2026-06-30 | 12d | fix: align ai-catalog.json with ADR-0016 (#6) |
| AI Catalog #37 | 2026-06-25 | 2026-06-26 | 1d | fix: conform AI Catalog to post-#37 spec |
| AI Catalog #77 | 2026-07-30 | 2026-08-02 | 3d | chore: conform ai-catalog.json to ADR-0017 (metadata→extensions array, remove legacy mediaType) |
| AI Catalog #77 | 2026-07-30 | 2026-09-13 | 45d | fix(ai-catalog): serve extensions as a map, not an array |
| ARD v0.91 | 2026-08-26 | 2026-09-14 | 19d | fix: Add displayName to the context-server AI Catalog entry |
The map draws five. These are the others we looked at, and why each is or is not drawn. The test: a public spec with git history, describing an agent or a server so machines can find it.
30 spec versions across 5 cards. 269 of 270 values link to the line they were quoted from; each quote is re-checked against that line, so a spec that moves shows up as a failed check rather than a wrong page. As of 2026-09-12.