Skip to content

[meta] Coordinate RFC 9421 webhook signing migration — adoption telemetry + threshold + ownership #4205

Description

@EvgenyAndroid

Context

The AdCP 3.0 release notes specify migrating from HMAC-SHA256 to RFC 9421
webhook signing, with HMAC deprecated and removed in 4.0. Two downstream
artifacts exist — PR #3064 (docs, @benminer) and #3360 (grade tooling,
@bokelley) — but there is no explicit coordination point for the migration
itself: no adoption telemetry, no "migration complete enough" threshold, and
no DRI for cross-cutting decisions.

This issue proposes establishing that coordination point before 4.0 removes
the HMAC opt-in.

Three concrete asks

1. Adoption telemetry
Directory-wide tracking of JWKS publication with adcp_use: "webhook-signing"
purpose keys. Today's data is anecdotal. Needs instrumentation — either in the
AdCP directory itself or as a contributed probe (see companion issue for a
concrete offer).

2. Adoption threshold
What fraction of active agents constitutes "migration complete enough" before
HMAC opt-in is removed in 4.0? Without a number on record, the deprecation
deadline is ad hoc. Suggested starting point: ≥80% of directory-listed agents
publishing valid JWKS with webhook-signing keys (webhook migration affects all
agent-to-agent comms, so coverage needs to be broad before removal).

Note: this threshold may differ from domain-specific work like Track A.0
(see companion issue). The webhook migration affects all agent-to-agent comms;
domain-scoped work like signals payments can ship into smaller subsets. WG
should set both numbers, not assume one threshold serves both.

3. Explicit coordination owner
PR #3064 and #3360 are downstream artifacts, not a coordination point. The
migration needs a DRI for decisions that cross docs, tooling, and schema
(algorithm choice, key publication format, deprecation timeline). @benminer
flagging you as closest current owner; happy to discuss whether you want this
role or want to delegate.

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    claude-triagedIssue has been triaged by the Claude Code triage routine. Remove to re-triage.governanceIssue concerns the governance protocol domainrfcProtocol change — auto-adds to roadmap board

    Type

    No type

    Projects

    Status
    No status

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions