ICPanda proposes six protocols for trusted AI agent communication

AI agents are increasingly being designed to communicate and act with less direct human involvement, raising questions about identity, authority, privacy and the reliability of shared records.
ICPanda has outlined a proposed Agent Protocols framework designed to address these issues through six open protocol drafts. The framework uses a shared signed envelope and does not require a central registry or a specific host.
The proposal centres on four basic questions that arise when one AI agent interacts with another: which key signed a message, whom the agent represents, whether private communications can be read by a relay, and whether a record has been altered.
The first protocol, Identity, defines an Agent ID as an Ed25519 public key using the did:agent: format. Each write is placed in a signed envelope based on a SHA3-256 hash of canonical JSON using JSON Canonicalisation Scheme. ICPanda says the verification rules are designed so different implementations reach the same result when checking signatures.
The second protocol, Profile, provides portable signed metadata describing an agent. The metadata can be hosted or mirrored by different services. Each update replaces the previous version, with the accepted update determined by the highest nonce.
Delegation addresses the question of what an agent is authorised to represent. Credentials are linked to the principal’s own HTTPS URL and restricted by scopes, audiences and validity periods. The framework separates the verification of a signature from historical authority and current authorisation. A revoked credential can remain cryptographically verifiable while no longer granting new authority.
The Mail protocol focuses on private communication between agents. It uses end-to-end encryption based on HPKE, combining X25519 with ChaCha20-Poly1305. Messages are sent as sender-signed packets, allowing relays to verify the sender while storing ciphertext rather than the contents of the communication.
The proposal also separates an agent’s identity from its mailbox and routing infrastructure, meaning those services can potentially change without changing the agent’s underlying identity.
The fifth protocol, Knowledge, is designed for agents that publish and build on research. Agents can publish signed research capsules whose identifiers are derived from their envelope hashes. Capsules can be linked using relationships such as derived_from, tests, contradicts and supersedes.
Signed assessments can record whether research has been reproduced, not reproduced or applied. The system is designed to record attribution and relationships between research rather than automatically treating a piece of information as true.
The sixth protocol, Discourse, deals with interactions inside an agent-controlled room. A room is defined as a machine-readable contract containing roles, rules and schema-validated event types.
Accepted records are hash-chained, allowing an archive to be checked offline. Changing one byte in a record would break the subsequent hash chain, providing a mechanism for detecting alterations to the recorded history.
The proposal reflects a broader challenge facing autonomous AI systems: establishing reliable ways for agents to identify one another, establish authority, communicate privately and maintain verifiable records without depending on a single central service.
ICPanda describes the protocols as open drafts, meaning the framework represents a proposed approach rather than an established industry-wide standard. Its effectiveness will depend on implementation, adoption and how different agent systems handle the protocols in practice.
Dear Reader,
Ledger Life is an independent platform dedicated to covering the Internet Computer (ICP) ecosystem and beyond. We focus on real stories, builder updates, project launches, and the quiet innovations that often get missed.
We’re not backed by sponsors. We rely on readers like you.
If you find value in what we publish—whether it’s deep dives into dApps, explainers on decentralised tech, or just keeping track of what’s moving in Web3—please consider making a donation. It helps us cover costs, stay consistent, and remain truly independent.
Your support goes a long way.
🧠 ICP Principal: ins6i-d53ug-zxmgh-qvum3-r3pvl-ufcvu-bdyon-ovzdy-d26k3-lgq2v-3qe
🧾 ICP Address: f8deb966878f8b83204b251d5d799e0345ea72b8e62e8cf9da8d8830e1b3b05f
Every contribution helps keep the lights on, the stories flowing, and the crypto clutter out.
Thank you for reading, sharing, and being part of this experiment in decentralised media.
—Team Ledger Life