Full Mission Lifecycle (End-to-End)
The complete mission lifecycle in a four-party deployment, from PS discovery to resource access. The mission is approved with a person token attached for the resource it named; the agent presents that person token at the resource's authorization endpoint; mission_s256 flows person token → resource token → auth token, one digest the whole way.
The agent fetches PS well-known metadata to discover the endpoints it needs.
mission_endpoint is where the agent proposes missions, and where it later POSTs updates and its completion proposal at {mission_endpoint}/{mission_s256}.
person_token_endpoint is REQUIRED in -11: every PS MUST publish one and MUST issue person tokens from it.
auth_token_endpoint was called token_endpoint before -11.
mission_control_endpoint is the control plane — where parties other than the owning agent read and manage missions. Its operations are left to a companion specification.
Step 1: Discover PS metadata
Description (Markdown)
# Analyze Q2 Customer Feedback Read customer feedback records and produce a summary report with sentiment analysis and key themes.
Blob Members
The blob is what the digest covers. approver lives here and nowhere else — no token carries it.
Mission Identifier
eyJhcHByb3ZlciI6Imh0dHBzOi8vcHMuZXhhbXBsZSIsImFnZW50IjoiYWF1dGg6bG9jYWxAYWdlbnQuZXhhbXBsZSIsImFwcHJvdmVkX2F0IjoiMjAyNi0wNC0xNFQxNzoxNDo1NFoiLCJleHBpcmVzX2F0IjoiMjAyNi0wNS0xNFQxNzoxNDo1NFoiLCJkZXNjcmlwdGlvbiI6IiMgQW5hbHl6ZSBRMiBDdXN0b21lciBGZWVkYmFja1xuXG5SZWFkIGN1c3RvbWVyIGZlZWRiYWNrIHJlY29yZHMgYW5kIHByb2R1Y2UgYSBzdW1tYXJ5IHJlcG9ydCB3aXRoIHNlbnRpbWVudCBhbmFseXNpcyBhbmQga2V5IHRoZW1lcy4iLCJhcHByb3ZlZF90b29scyI6W3sibmFtZSI6IkZlZWRiYWNrUmVhZGVyIiwiZGVzY3JpcHRpb24iOiJSZWFkIGN1c3RvbWVyIGZlZWRiYWNrIHJlY29yZHMifSx7Im5hbWUiOiJSZXBvcnRXcml0ZXIiLCJkZXNjcmlwdGlvbiI6IldyaXRlIHRoZSBzdW1tYXJ5IHJlcG9ydCB0byB0aGUgc2hhcmVkIGRyaXZlIn1dLCJhcHByb3ZlZF9yZXNvdXJjZXMiOlsiaHR0cHM6Ly9hcGkuZXhhbXBsZSJdfQ
7SGTFsuKCcpYJwGRkVBi8vOc1Ssm7NdgnVaAruK87Rg
s256 is not a blob member. It is BASE64URL(SHA-256()) of the bytes mission decodes to, returned alongside it so the agent can verify the digest covers an unambiguous byte sequence. It travels as the mission_s256 claim of person, resource and auth tokens.
Approved Tools
Read customer feedback records
Write the summary report to the shared drive
PS Capabilities
7SGTFsuKCcpYJwGRkVBi8vOc1Ssm7NdgnVaAruK87Rg
s256 = BASE64URL(SHA-256(bytes)). The PS returns the same bytes base64url-encoded as the `mission` member, so the agent can recompute the digest itself.
7SGTFsuKCcpYJwGRkVBi8vOc1Ssm7NdgnVaAruK87Rg
The agent asks for a person token with mission_s256; the PS verifies the mission exists, is active and belongs to this agent, then puts the value in the token.
7SGTFsuKCcpYJwGRkVBi8vOc1Ssm7NdgnVaAruK87Rg
REQUIRED when the person token carried one — a resource MUST NOT omit it. presented_jti names the exact token it was copied from.
7SGTFsuKCcpYJwGRkVBi8vOc1Ssm7NdgnVaAruK87Rg
The resource reads the mission only here. It never arrives as a header and is never agent-asserted.
ps.example