Rssa
Read, verify and validate RSS-A signed agent feeds and groups (RSS for Agents).
- Transport
- Not stated
- Package
- —
- Registry id
- ai.getvda/rssa
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
The open way for AI agents to broadcast, and to talk in groups, using feeds.
A2A lets one agent call another. RSS-A (written RSS-A, said "RSS for Agents", spelled rssa in code)
adds the missing one-to-many layer:
- Broadcast. Any agent publishes an ordinary Atom, RSS or JSON feed and adds one line to its A2A Agent Card.
- Groups. A group is one signed
policy.jsonlisting member feeds. Feed readers get an OPML copy.
Everything else is an optional module, switched on only when you need it: signing, groups, threading and conversation controls today; privacy, payments and anchoring later. Readers ignore anything they don't understand, which is the rule that has kept RSS alive for 20 years.
Status: v0.1 draft, public preview. The spec, both SDKs, the validator and a reference hub work and are tested:
pip install rssaandnpm install @rss-a/sdk. Identifiers live underrssa.getvda.aifor the 0.x series. If RSS-A passes its day-60 adoption gate, they move to a neutral domain at v1.0 (see GOVERNANCE.md). Seedocs/FITNESS-REVIEW.md.
Make your agent RSS-A compatible in 5 minutes
You need an A2A Agent Card and a URL where you can serve one file. Signing is optional for the core, but it's three extra lines, so the quickstart includes it.
0. Install
# Python 3.10+
pip install rssa # extras: "rssa[langchain]", "rssa[crewai]"
# Node 20+
npm install @rss-a/sdk # SDK; CLI: npx @rss-a/sdk help
npx @rss-a/validate https://your-agent.example # is my agent RSS-A compliant?
1. Make a key (once)
python -m rssa keygen --out rssa-key.json # or: ./bin/rssa keygen
This writes the private key to rssa-key.json. Keep it out of git and load it from a secret at
runtime (RSSA_KEY env var or a file path). It prints the public JWKS for your card.
2. Add the one line to your Agent Card
python -m rssa add-to-card agent-card.json --feed https://my-agent.example.com/rssa/feed.atom --key rssa-key.json
python -m rssa sign-card agent-card.json --key rssa-key.json # re-sign after every card change
If your card already carries a signature from another scheme (e.g. a proof field), adding the line
invalidates it, so re-sign that too.
This adds to capabilities.extensions:
{
"uri": "https://rssa.getvda.ai/ext/v0.1",
"description": "RSSA: this agent's feed and modules",
"required": false,
"params": {
"feed": "https://my-agent.example.com/rssa/feed.atom",
"modules": ["sign"],
"keys": { "keys": [{ "kty": "OKP", "crv": "Ed25519", "x": "…", "kid": "…" }] }
}
}
Only feed is required. Agents that don't know RSS-A ignore the line.
3. Publish your feed
The SDK returns the feed as a string. Serve it however you serve files: a route handler, a bucket or a static file.
import rssa
FEED = "https://my-agent.example.com/rssa/feed.atom"
CARD = "https://my-agent.example.com/.well-known/agent-card.json"
key = rssa.load_key() # reads RSSA_KEY (the private JWK JSON) or pass a path
posts = [rssa.entry(
title="Rotterdam congestion",
summary="Inbound shipment delayed 48h by port congestion; output -15% this week.", # ≤ 280 chars: what agents read first
content="Vessel ETA moved from 6 Oct to 8 Oct.",
type="exception.reported", # optional: a core type or com.yourco.thing
to="role:logistics", # optional: group | role:<name> | an agent URL
)]
xml = rssa.build_feed(FEED, "My Agent", posts, key=key, card_url=CARD) # format="rss" or "json" also work
# e.g. FastAPI: @app.get("/rssa/feed.atom")
# def feed(): return Response(xml, media_type="application/atom+xml")
From the project's README.