Draft-01.1 · Open specification · In production with beta pilots

Every agent message.
Carries its own trust.

ARSIA is an open, transport-agnostic envelope protocol. Identity, compliance requirements, human oversight and audit travel inside every message between AI agents. Not bolted on. Built in.

$ pip install arsia-protocol

Animation: agents send envelopes to other agents. Each envelope is signed as it leaves and verified on arrival. Some pause for human approval before they continue, a few fail verification and are rejected, and every delivery adds a record to the audit trail.

The core idea

One envelope.
Everything it takes to be trusted.

Every message between agents is wrapped in a structured, signed envelope. The envelope is the protocol: no sidecar, no middleware, no separate policy file.

TLS · the connection

Moved encryption out of the application and into the transport.

Applications stopped encrypting data themselves. Every connection became secure by default.

ARSIA · the message

Moves compliance out of documentation and into every message.

The difference between telling an agent to be careful with data, and never letting a non-compliant message through.

envelope.json · wire version 1.0generated with the SDK

{  "v": "1.0",  "id": "106b18b4-5da7-4493-8f4d-f6afedaad83c",  "ts": "2026-09-28T17:51:07.905Z",  "expires_at": "2026-09-28T17:56:07.905Z",  "intent": "request",  "from": "agent:acme.advisor",  "to": "agent:acme.executor",  "capabilities": ["com.acme.trade.execute"],  "compliance": {    "profile": "MIFID-II",    "retention_days": 1827,    "data_residency": "EU",    "human_oversight": "required_before_execution",    "audit_required": true,    "pii_involved": true,    "legal_basis": "contract"  },  "payload": {    "type": "com.acme.trade.execute",    "args": { "portfolio_id": "PF-2847" }  },  "security": {    "alg": "EdDSA",    "kid": "agent:acme.advisor#key-1",    "sig": "9-Iwmpk98fw-h-PQUa…UUeCA"  }}
Header & intent

Every message says what it is. A wire version, a unique id, a timestamp, an expiry, and one of six intents: request, response, event, error, pending_approval or approval_decision.

Message intents

Six intents.
Every interaction covered.

From a request to its result, including the moment a human has to decide. Oversight is not a side channel: it is part of the conversation.

trade request · MIFID-II

  • request

    Ask another agent to act. Carries capabilities, payload and compliance requirements.

  • response

    Deliver the result, correlated to the request, under the same compliance context.

  • event

    A one-way notification. No response expected.

  • error

    Structured errors: 14 standard codes with HTTP status mapping and retry guidance.

  • pending_approval

    The agent pauses and asks a human before a high-risk action. EU AI Act Art. 14.

  • approval_decision

    The reviewer approves or denies, with a written justification.

Capabilities

Everything you need.
Nothing you don’t.

Deliberately opinionated about what belongs in the envelope, and deliberately minimal about everything else. Each capability is specified, schema-validated and covered by test vectors.

01

Cryptographic identity

Every agent has a verifiable key and every message is signed. Ed25519 by default, ES256 also supported, with keys published for discovery.

02

Compliance profiles

Seven profiles for GDPR, the EU AI Act, MiFID II, DORA, the DSA and the Common Agricultural Policy. Each sets retention, residency, oversight and audit.

03

Audit trail

Records of who did what, when and under which profile, generated from the messages themselves. Retention follows the profile.

04

Human oversight

Before execution, after execution, or within 24 hours. The mode travels in the envelope; your runtime enforces the gate.

05

Two-layer validation

L1 checks structure against JSON Schema 2020-12. L2 checks semantics: cross-field rules, timestamps, capabilities and profile integrity.

06

Payload encryption

Compact JWE with ECDH-ES and A256GCM. Intermediaries can route the envelope without reading what it carries.

07

Data residency

Declare where data may be processed, at the message level. MIFID-II, DORA and PAC-AGRICULTURE default to the EU.

08

Capability system

Agents declare what they offer and request what they need. A receiver acts only on capabilities it has granted.

09

Transport agnostic

HTTP, WebSocket, queues or files. The envelope carries its own guarantees, alongside any agent framework.

Architecture

Above MCP and A2A. Complements, doesn’t compete.

MCP connects agents to tools. A2A connects agents to each other. ARSIA is the trust layer for both: identity, requirements and evidence, carried in the message itself.

5 + 1 architecture

One Core foundation and five domain primitives: Actions, Routing, State, Identity, Assets.

Zero coupling

Works with any agent framework. No required runtime, no vendor lock-in, no mandatory infrastructure.

Three conformance levels

Core: envelope, signing, discovery. Compliance: adds profiles, audit and oversight. Full: all five primitives and encryption.

where ARSIA sitsillustrative
Your agentsany framework, any model
ARSIA Protocolidentity · compliance · oversight · audit
MCPtool and data access
A2Aagent-to-agent tasks
Transport & infrastructureHTTP · WebSocket · queues · cloud

a request passes down the stack, the reply comes back up

Compliance profiles

EU-first.
Built for everywhere.

Seven profiles ship with Draft-01.1, covering Europe’s major regulatory frameworks. A profile is a JSON object, so the same mechanism extends to any jurisdiction.

Draft-01.1 compliance profile defaults
ProfileRegulationRetentionHuman oversightAuditResidency
GDPR-STANDARDGDPR Art. 5, 6, 9, 17, 30Set by operatorNot requiredNot required—
EU-AI-ACT-HIGH-RISKAI Act Art. 12–14, 17, 26180 daysBefore executionRequired—
EU-AI-ACT-LIMITED-RISKAI Act Art. 5090 daysNot requiredRequired—
MIFID-IIMiFID II Art. 16(7), Reg. 2017/5651827 days5 yearsBefore executionRequiredEU
DORADORA Art. 5, 17, 19, 281827 days5 yearsWithin 24 hoursRequiredEU
DSA-VLOPDSA Art. 15, 34, 37, 40, 42730 days2 yearsWithin 24 hoursRequired—
PAC-AGRICULTUREReg. (EU) 2021/21161096 days3 yearsAfter executionRequiredEU

Draft-01.1 profile defaults. A profile encodes requirements in the message; selecting one does not by itself establish legal compliance for your system. Explore the profiles →

Same mechanism, other jurisdictions

  • HIPAA · US healthcare
  • SOX · US finance
  • SOC 2
  • LGPD · Brazil
  • PIPL · China
  • APPI · Japan
  • POPIA · South Africa
  • PDPA · Singapore
  • CCPA · California
  • NIST AI RMF
  • ISO/IEC 42001
  • Your framework

Build

From pip install to a signed envelope.

The Python SDK implements Draft-01.1: envelopes, signing, two-layer validation, compliance profiles, encryption and command-line tools.

  1. 01
    Install

    pip install arsia-protocol, Python 3.12 or later. Add [cli] for the arsia command.

  2. 02
    Create an envelope

    Typed constructors for every intent. Set sender, receiver, capabilities and payload.

  3. 03
    Apply a profile

    Name a profile and apply_profile fills in its retention, residency and oversight defaults.

  4. 04
    Sign, verify, validate

    Generate an Ed25519 key, sign, then check the signature and both validation layers.

quickstart.py
from arsia_protocol import (
    apply_profile, create_request, generate_ed25519_keypair,
    sign_message, validate_envelope, verify_message,
)

private_key, public_key = generate_ed25519_keypair()

envelope = create_request(
    from_agent="agent:acme.advisor",
    to_agent="agent:acme.executor",
    payload_type="com.acme.trade.execute",
    capabilities=["com.acme.trade.execute"],
    args={"portfolio_id": "PF-2847"},
    compliance={"profile": "MIFID-II"},
)
envelope = apply_profile(envelope)  # retention, residency, oversight

signed = sign_message(
    envelope, private_key, "agent:acme.advisor#key-1"
)
assert verify_message(signed, public_key)
assert validate_envelope(signed) == []
print("signed, verified, valid")

terminal

  1. $ pip install arsia-protocol
  2. $ python quickstart.py
  3. signed, verified, valid

Community & governance

Built in the open.
Shaped with standards bodies.

The specification is open, the SDK is on PyPI, and the work takes part where agent standards and European AI rules are being written.

Contact

Building with ARSIA?

Implementing the protocol, feedback on the specification, or interest in the beta pilot programme. We’d like to hear from you.

Based in
Portugal, EU

Please before sending your message.

Esc