SEP-3318: Verifiable Conversation Handles - #3318
ryan-s-roberts wants to merge 5 commits into
Conversation
Standards Track draft for MAC-bound conversation identity, co-presented to Security IG and Agents WG. Seeking sponsor. Co-authored-by: Cursor <[email protected]>
Matches SEP process: file and header use the pull request number. Co-authored-by: Cursor <[email protected]>
Satisfy markdown format check and render-seps by formatting the SEP and regenerating docs/seps artifacts via npm run generate:seps. Co-authored-by: Cursor <[email protected]>
Mintlify rejects <https://...> as JSX. Convert References to markdown links and simplify the Foundry table cell that broke nested backticks. Co-authored-by: Cursor <[email protected]>
Awaiting Sponsor; Transports WG + Agents WG; seq-first framing; gate exchange on association; drop conversationId response mirror; cite transports-wg#36 and SEP-1655 prior art. Co-authored-by: Cursor <[email protected]>
|
Docs / Status note (hybrid remediation): Status is now Awaiting Sponsor (not Draft). CI’s Normative tightening called out for reviewers: §4.4 exchange is now explicitly gated on §2.3 association + retention; response |
|
Sessions / Conversation IDs is covered in the Transports WG Roadmap as not planned:
There is currently a problem statement here that summarizes the problems: modelcontextprotocol/transports-wg#47 My 2c is that this SEP doesn't address those problems, or make a clear case for why conversation ids belong in the protocol other than "lots of other places have them". |
|
Let me park this while I take modelcontextprotocol/transports-wg#47 into account |
|
Yes this is far too complex for reasonable adoption outside of my use cases. Closing |
Summary
Standards Track SEP (Awaiting Sponsor) for a client-carried, server-minted, sequenced conversation identifier in
_meta(io.modelcontextprotocol/conversation-handle).seq) is the main protocol contribution — ACLs alone cannot recover “is this the current handle?”Venues
Prior art cited: SEP-1655 (why not cookie+MAC), SEP-1685, discussion #2894, SEP-2822 → #36.
Behaviour notes (review remediation)
seq; opaque commitments are LWW by seqEvidence of work (human-owned)
Operational origin: Plasm / conversation-scoped memory + IFC needs — not a cold speculative write-up.
AI disclosure (AI_POLICY.md)
This PR’s SEP prose and supporting edits were produced with Cursor agent assistance (drafting, restructuring, formatting, CI fixes). Design choices, Quint model, conformance suite, and reference implementation were directed and reviewed by the author (@ryan-s-roberts). Extent: substantial documentation/editing assistance; not unattended generation.
Seeking sponsor
Looking for a Core Maintainer / Maintainer sponsor. Transports WG (#36) is the natural product venue; Security IG for threat review; Agents WG for memory/orchestration.
CC: @kurtisvg (transports-wg#36) @SamMorrowDrums @olaservo @PederHP @ostefano @CaitieM20 @LucaButBoring @pja-ant