Published Writ, a small protocol for passing authority between agents and getting back a signed account of what was done with it.

It started from one question. What's the smallest thing MCP, A2A, and OAuth still can't express cleanly? I tried to build the same scenario on each of them, step by step. None gives you an object anyone can verify offline that binds a chain of delegation, where each hop can narrow what the next is allowed to do without calling back to the issuer, to a signed receipt from each hop saying what it did under exactly which link.

Writ is four signed JSON objects. A writ grants bounded authority. A call carries the chain with the request. A tally is the signed receipt of what a hop did. A revoke stops new work down the chain. In the demo, an agent holding a travel writ with a spending cap hands the agent that charges the card a narrower cap of its own, and the receipts come back up nested, so the original delegator can verify who did what under which link with nothing but the objects themselves.

Six candidate architectures and a kill round came before the spec. The repo has the research, the v0.1 spec, a Go reference implementation, a second implementation in Python written only from the spec, a conformance corpus, a three-agent demo, and CI that keeps the two implementations agreeing.

Several drafts and papers from this year cover pieces of the same gap. The README names them and says what Writ borrowed. Apache 2.0.