TRACE SDK 0.5.1
Fixed
transparencyis optional below Level 2. The model required a non-empty URI on every record, which was stricter than bothschema/trace-claim.json(required, nominLength) and the conformance suite, which runsTR-ANCat Level 2 only. A Level 0 or Level 1 record is not anchored, so it has no receipt to name, and that state was unrepresentable.Nonenow means unanchored; an empty string stays rejected, since""is not a URI and a field that looks populated but resolves to nothing is worse in a trust record than an absent one.
Changed
-
BREAKING: TRACE v0.2 changes the EAT profile URI to
tag:agentrust-io.com,2026:trace-v0.2(wastag:agentrust.io,2026:trace-v0.1).agentrust.iowas never a domain this project controlled; it resolves to third-party parked addresses. RFC 4151 permits a tag URI only where the minting authority controlled the named domain on the stated date, so the v0.1 identifier was invalid rather than merely misspelled: it asserted authority over a name someone else could stand up a conflicting definition at.Cutover, not coexistence. A v0.2 verifier requires the new URI and rejects the old one; it does not accept both. Dual acceptance would keep the invalid identifier live indefinitely, which is the thing being fixed. Records already issued under v0.1 stay verifiable against
spec/trace-v0.1.mdand the publishedagentrust-trace0.4.x releases, which remain on PyPI. They are v0.1 records and are read as such.Nothing else in the record format changed. No field was added, removed, or re-typed, so migration for a producer is the profile string and a dependency bump.
Moved together:
spec/trace-v0.2.md(new, with a "Changes from v0.1" section),spec/trace-v0.1.md(retained, marked superseded), the rootschema/trace-claim.jsonconst, the packagedagentrust_trace/schema/trace-v0.2.json, theeat_profileLiteralinmodels.py, the AGT adapter,validate.py's schema resource, the four platform example records, and the docs. -
Other
agentrust.ioURLs moved toagentrust-io.com: the registry and verifier hosts in the AGT adapter and the schema$id.
Fixed
verify_record()now enforces the profile cutover this changelog already declares. The entry above states that a v0.2 verifier "requires the new URI and rejects the old one; it does not accept both" — butverify_record()never readeat_profile, so a record carrying the v0.1 identifier, a future version, a foreign tag, or no profile at all verified exactly as a v0.2 record, provided its signature checked out. A valid signature over semantics this build does not implement is not evidence, so the profile is now checked first, before any cryptographic work: anything other thanTRACE_PROFILE_V0_2(newly exported) raisesValueError, with a message that says why when the profile is the superseded v0.1 identifier. Same shape as the revocation fix above: an already-merged spec requirement (spec/trace-v0.2.mdsection 2) that the reference implementation did not carry out.docs/verification.mdstep 4 notes the check is now built in. No normative text, schema, or record field changed.