A signed A2A v1.0 manifest at /.well-known/agent-card.json describing what the install is, what protocols it speaks (A2A and MCP), its capability tags, and how to authenticate. Signed with EdDSA so peers can verify the publisher.
The card is how other agents discover Heidi: capabilities like memory, knowledge_graph, and cross_source_recall, plus the endpoints and the bearer scheme, in one fetch.
Discovery posture is configurable: public by default for bootstrapping, or authenticated for installs that do not want an open manifest.