{"uid":"cap_KSVfXcer80GL1WAZ2cbZM","slug":"holoweave-url-witness-signed-url-evidence-7346609d","name":"Holoweave URL Witness — Signed URL Evidence","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/url-witness","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"url-witness","evidence":{"url":"https://example.com/terms","bytes":1256,"status":200,"headers":{"etag":"\"abc\"","last-modified":"Tue, 26 Aug 2026 10:00:00 GMT"},"fetched_at":"2026-08-27T09:00:00Z","body_sha256":"9f2b…"}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NIFMH2KQv1zpY7fadizi_","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a public URL and returns a cryptographically signed, timestamped attestation of its HTTP status, response headers, and SHA-256 body hash, with optional change detection against a previously pinned hash.","exampleAgentPrompt":"Fetch https://example.com/terms and give me a signed, timestamped witness record — status, headers, and SHA-256 of the body — so I can prove what it contained today; also check whether the body hash has changed from 9f2b4a3c... that I pinned last month.","exampleUseCases":[{"title":"Terms-of-service change detection","prompt":"Witness https://acmecorp.com/legal/terms-of-service right now and tell me whether the body hash has changed from d4f8e1b2c9a0... that I pinned three months ago — I need a signed attestation I can keep as evidence."},{"title":"Price list integrity snapshot","prompt":"Fetch https://supplier.io/catalog/prices.json and give me a signed, timestamped attestation of its current status, headers, and SHA-256 so I have a tamper-evident record of today's pricing."},{"title":"Robots.txt monitoring for crawler compliance","prompt":"Witness https://target-site.com/robots.txt and check whether the content has changed since I last pinned it with hash a3c7f29d...; I need the signed result to confirm my crawler's permissions haven't been quietly revoked."}],"resultDescription":"A JSON object containing an ed25519 signature (algorithm, base64 value, and key ID) and an attestation block with the verdict ('pass'), the URL fetched, HTTP status, selected response headers (e.g. ETag, Last-Modified), byte count, fetch timestamp, and SHA-256 body hash. If expect_sha256 was supplied, the attestation also includes UNCHANGED or CHANGED, all signed with the service's public key.","failureModes":["Private or loopback host supplied — request refused","URL returns a non-200 status — attested but verdict reflects the actual status","Network timeout fetching the target URL — error returned","Invalid or malformed URL — validation error before fetch","expect_sha256 format invalid — parameter rejected"],"whenToPreferThis":"Choose this endpoint when you need a cryptographically signed, independently witnessed record of what a public URL served at a specific moment — especially for compliance, audit trails, or automated change detection on terms pages, robots.txt, price lists, or research sources. It is preferable over plain HTTP fetching when you need non-repudiable proof of content, and over generic monitoring services when you need a verifiable ed25519 attestation you can store and later validate with a known public key.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T22:26:57.527Z","isFirstParty":false}