{"uid":"cap_mcLZtuhZPsoNUxbKKKHXf","slug":"agent-card-witness-ai-agent-identity-verification-21654892","name":"Agent Card Witness — AI Agent Identity Verification","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/agent-card-witness","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"agent-card-witness","evidence":{"url":"https://agent.example.com/.well-known/agent-card.json","card":{"name":"Recipe Agent","skills":{"plan-week":"91ac…","find-recipe":"7de0…"},"version":"1.0.0","interfaces":[{"url":"https://agent.example.com/a2a","transport":"JSONRPC"}],"signatures":[],"card_digest":"4c1a…","skill_count":2},"status":200,"comparison":{"unchanged":true,"expect_digest":"4c1a…"}}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ONHD6wsYZ49usQjzpdzzG","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches, verifies, and cryptographically attests to an AI agent's published agent card, detecting changes in card content or skills since a previous check.","exampleAgentPrompt":"Can you fetch and verify the agent card for https://agent.example.com and give me a signed attestation of its current contents — I want to know if the card digest has changed from 4c1a… that I saw last week.","exampleUseCases":[{"title":"First-time agent card verification","prompt":"Go check the agent card published at https://recipe-bot.example.com and give me a signed witness attestation of its current contents, including the card digest and skill list, so I can pin this as my baseline."},{"title":"Detecting skills removed from a known agent","prompt":"I pinned this agent's skills last month — the skill map was {\"plan-week\":\"91ac…\",\"find-recipe\":\"7de0…\"}. Can you re-check https://recipe-bot.example.com now and tell me if any skills were added, removed, or changed?"},{"title":"Continuous agent integrity monitoring","prompt":"I need to confirm that the agent at https://partner-agent.mycompany.com still has the same card I approved — its digest was 4c1a…. Fetch it and give me a signed UNCHANGED or CHANGED verdict."}],"resultDescription":"A signed JSON attestation containing: an ed25519 signature (algorithm, base64 value, key ID), and an attestation body with verdict ('pass'/'fail'), the fetched card URL, card metadata (name, version, interfaces, skill IDs with digests, skill count, card digest), HTTP status, and optionally a comparison result (unchanged/changed vs. the expected digest or skill map).","failureModes":["Agent card URL is unreachable or returns non-200 status — attestation includes the HTTP status and a failed verdict","Card JSON is malformed or missing required fields — witness returns an error evidence block","Expected digest provided but card has changed — verdict is CHANGED rather than UNCHANGED","Invalid or non-HTTPS URL provided — request rejected with validation error","Agent card host is behind a bot-blocking rule — fetch may fail or return unexpected content","Payment of $0.01 USDC not provided or rejected — 402 Payment Required response"],"whenToPreferThis":"Use this endpoint when you need an independent, cryptographically signed third-party attestation of an AI agent's published identity card — especially for auditing, trust establishment, or change-detection workflows. Prefer it over fetching the agent card yourself when you need tamper-evident proof, when you want to detect capability drift across time using digest comparison, or when downstream systems require a signed witness record rather than a raw HTTP fetch.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-16T02:27:42.417Z","isFirstParty":false}