Problem
ACP Registry entries describe how to distribute and launch an agent, but not whether the agent supports multiple isolated local accounts. ACP authentication methods are discovered only after the process launches, which is too late for a host to select the configuration environment that isolates an account.
As a result, ACP hosts must maintain private per-agent metadata or expose only agent-managed shared authentication.
Proposal
Add an optional, agent-publisher-owned account-profile capability to Registry entries. It should be descriptive rather than a generic credential store.
Possible fields:
{
"account_profile": {
"isolation": "environment",
"environment": [
{ "name": "EXAMPLE_CONFIG_HOME", "path": "profile_root" }
],
"authentication": "acp_auth_methods"
}
}
The exact schema is open for discussion. It should be able to express at least:
- whether separate local profiles are supported;
- the pre-launch environment mapping required to select one;
- whether the agent's normal ACP authentication methods operate within that profile; and
- whether profile data is safe for a host to create and delete.
Constraints
- Do not standardize storage of API keys or OAuth tokens in the Registry.
- Do not require hosts to infer paths from executable behavior.
- Do not imply that an arbitrary
HOME override provides safe isolation.
- Maintain compatibility for existing entries without profile metadata.
Motivation
Editors can then present a trustworthy multi-account switcher for agents whose publishers explicitly support it, while still showing agent-managed authentication for all other Registry agents.
Problem
ACP Registry entries describe how to distribute and launch an agent, but not whether the agent supports multiple isolated local accounts. ACP authentication methods are discovered only after the process launches, which is too late for a host to select the configuration environment that isolates an account.
As a result, ACP hosts must maintain private per-agent metadata or expose only agent-managed shared authentication.
Proposal
Add an optional, agent-publisher-owned account-profile capability to Registry entries. It should be descriptive rather than a generic credential store.
Possible fields:
{ "account_profile": { "isolation": "environment", "environment": [ { "name": "EXAMPLE_CONFIG_HOME", "path": "profile_root" } ], "authentication": "acp_auth_methods" } }The exact schema is open for discussion. It should be able to express at least:
Constraints
HOMEoverride provides safe isolation.Motivation
Editors can then present a trustworthy multi-account switcher for agents whose publishers explicitly support it, while still showing agent-managed authentication for all other Registry agents.