{"schema":"xyz.agent-network.v1","mode":"authenticated_request_response","requestTypes":["request_capability","request_quote","check_availability","request_partner","request_service"],"authentication":{"scheme":"xyz-p256-v1","handshake":"HTTPS-hosted agentIdentity with ECDSA P-256 public JWK","signedHeaders":["X-XYZ-Agent-Id","X-XYZ-Timestamp","X-XYZ-Nonce","X-XYZ-Signature"],"replayWindowSeconds":300},"bilateralTrust":{"states":["discovered","identity_verified","allowlisted","capabilities_known","inbound_ready","bilateral_ready"],"outboundRequirement":"protected_private_key_custody","consentEnvelope":"xyz.agent-consent.v1","receipt":"xyz.agent-exchange-receipt.v1","controls":{"rateLimitPerMinute":60,"maxPayloadBytes":32768,"idempotency":"signed requestId or deterministic body digest","revocation":"XYZ_AGENT_REVOKED_IDS"}},"rules":["Authenticated identity proves who sent a request; it does not bypass the company origin allowlist or the Authority Map.","request_capability may be answered automatically from public xYz capability data.","Quote, availability, partner, service, procurement, booking, spending, pricing, contract, or other externally consequential requests remain ask_first and return approval_required until explicit approval exists.","Every consequential request carries a consent envelope describing scope, constraints, expiry, and required authority.","Every authenticated exchange receives an audit receipt with a request digest and decision.","No third-party response may be fabricated or represented as real without an authenticated exchange."]}