{"uid":"cap_cKzAXdS7fe10c6yszq2Le","slug":"autobus-jwk-set-witness-keys-witness-bd52971a","name":"autobus — JWK Set Witness (keys-witness)","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/keys-witness","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"keys-witness","evidence":{"url":"https://www.googleapis.com/oauth2/v3/certs","keys":[{"alg":"RS256","kid":"a1b2…","kty":"RSA","index":0,"thumbprint":"3f9c…"}],"kinds":{"RSA":4},"status":200,"fetched_at":"2026-08-27T09:00:00Z","keys_found":4,"set_digest":"6dc8…"}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QZZAvx0NqxHUGUYtKcLG1","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a JWK Set URL, verifies RFC 7638 key thumbprints and RFC 9421 Ed25519 signatures, and returns a signed attestation of the results with optional change detection against a prior digest or pinned thumbprints.","exampleAgentPrompt":"My bot keeps getting 401s — can you fetch the JWK Set at https://www.googleapis.com/oauth2/v3/certs and give me a signed attestation of which keys are there, their RFC 7638 thumbprints, and whether any have rotated since digest 6dc8abcd?","exampleUseCases":[{"title":"Debugging rejected signed bot requests","prompt":"My HTTP-signed bot request keeps getting rejected. Can you check the JWK Set at https://auth.example.com/.well-known/http-message-signatures-directory, list all the keys and their thumbprints, and tell me whether the key IDs are valid RFC 7638 thumbprints?"},{"title":"Pinned key rotation detection","prompt":"I pinned the JWK Set at https://login.microsoftonline.com/common/discovery/v2.0/keys last week with digest abc123. Can you check it again and tell me if any keys were added or removed since then?"},{"title":"Third-party signed attestation for compliance","prompt":"For our audit log, I need an independent signed attestation confirming exactly which keys are published at https://accounts.google.com/.well-known/openid-configuration/jwks right now — including their thumbprints, how many keys were found, and when they were fetched."}],"resultDescription":"A signed attestation object containing: the verdict (pass/fail), the endpoint name, evidence including the fetched URL, array of keys with algorithm, kid, key type, index, and RFC 7638 thumbprint, key type counts, HTTP status, fetch timestamp, keys found count, and a set_digest. If expect_digest or expect_thumbprints were provided, also returns UNCHANGED or ROTATED with added/removed key details. The attestation itself is signed with an Ed25519 key identified by a dated key_id.","failureModes":["JWK Set URL is unreachable or returns non-200 — verdict reflects HTTP status","URL is not HTTPS — likely rejected at input validation","JWK Set returns malformed JSON or invalid JWK structure — attestation may report parse failure","expect_digest provided but format does not match — comparison may fail","Payment not included or insufficient — HTTP 402 returned before any check is performed","Rate limiting or network timeout fetching the remote JWK Set — transient failure"],"whenToPreferThis":"Choose this endpoint when you need an independent, cryptographically signed third-party attestation of what keys a JWK Set URL actually publishes — not just your own fetch. Especially useful for debugging HTTP message signature auth failures (RFC 9421), verifying RFC 7638 thumbprint correctness, detecting key rotation between runs, or producing compliance audit evidence that you did not self-report. Prefer over rolling your own fetch when you need tamper-evident signed proof with a published key and dated attestation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T23:27:33.152Z","isFirstParty":false}