@techreport{farley-acta-signed-receipts-02, number = {draft-farley-acta-signed-receipts-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-farley-acta-signed-receipts/02/}, author = {Tom Farley}, title = {{Signed Decision Receipts for Machine-to-Machine Access Control}}, pagetotal = 31, year = 2026, month = jun, day = 28, abstract = {This document defines a portable, cryptographically signed receipt format for recording machine-to-machine access control decisions. Each receipt captures the identity of the decision maker, the tool or resource being accessed, the policy evaluation result, and a timestamp — all signed with Ed25519 {[}RFC8032{]} and serialized using deterministic JSON canonicalization {[}RFC8785{]}. The format is designed for environments where AI agents invoke tools on behalf of human operators, particularly the Model Context Protocol (MCP) ecosystem. Receipts are independently verifiable without contacting the issuer, enabling offline audit, regulatory compliance, and cross-organizational trust federation.}, }