{"uid":"cap_f7SzMcyU7JsMDoR4VOGUI","slug":"wba-thumbprint-validator-80fb9b8b","name":"WBA Thumbprint Validator","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/wba-thumbprint","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"fail","endpoint":"wba-thumbprint","evidence":{"keys_found":1,"published_thumbprints":["poqkLGiymh_W0uP6PZFw-dvez3QJT5SolqXBCW38r0U"]},"findings":[{"code":"KEYID_IS_KID_NOT_THUMBPRINT","detail":"keyid matches the kid of key 0 but NOT its RFC 7638 thumbprint.","severity":"blocking"}]}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_nxQLSbVfO6mOFlY3MnM4c","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates that a given keyid matches the RFC 7638 thumbprint of a key published in an agent's JWKS key directory","exampleAgentPrompt":"Check whether my keyid 'abc123' actually matches one of the keys published at https://myagent.example.com/.well-known/http-message-signatures-directory — I want to confirm the RFC 7638 thumbprint lines up before I send signed requests.","exampleUseCases":[{"title":"Pre-flight key consistency check","prompt":"Before my agent starts signing requests, verify that the keyid 'agt-key-01' matches a key published at https://agent.myplatform.io/.well-known/http-message-signatures-directory so I know the thumbprint is correct."},{"title":"Debugging rejected signature keyid","prompt":"My HTTP message signatures keep getting rejected — can you check if keyid 'ed25519-prod-2024' corresponds to any key in my JWKS at https://api.myservice.com/.well-known/http-message-signatures-directory?"},{"title":"Validating Signature-Input keyid from incoming request","prompt":"I received a Signature-Input header of 'sig1=(\"@method\" \"@path\");keyid=\"agent-key-7\";created=1700000000' — can you check whether that keyid is a valid RFC 7638 thumbprint for something published at https://partner-agent.example.com/.well-known/http-message-signatures-directory?"}],"resultDescription":"Returns whether the provided keyid matches the RFC 7638 thumbprint of any key found at the specified JWKS key directory, allowing the caller to confirm key identity consistency before or during HTTP message signature workflows.","failureModes":["Key directory URL is unreachable or returns non-200 — validation cannot proceed","No key in the JWKS matches the provided keyid thumbprint — returns mismatch","Malformed keyid or JWKS document — parsing error returned","key_directory is not a valid HTTPS URI — rejected at input validation","Neither keyid nor signature_input provided — required field missing error"],"whenToPreferThis":"Use this endpoint when you need to confirm that a keyid used in HTTP message signatures (RFC 9421 / WBA) actually corresponds to a key the agent has published in its JWKS directory. This is specifically useful before initiating signed API calls, when debugging signature rejections, or when onboarding a new agent identity and verifying that key material is consistent. Prefer this over full signature verification when you only need to validate key identity, not an actual signature.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:27:55.339Z","isFirstParty":false}