Card snapshot
auditor.webmesh.ai
·
2026-09-23 10:38:38 UTC
·
d45ad44607d4300a81baacbf771c659fedf48ca3507cdd3cf1eea19d42476d79
This is a frozen copy of the agent's agent-card.json as we observed it at the timestamp above. We capture a new snapshot every time the card's content hash changes. Useful for: forensic drift analysis, verifying downstream callers see the right version, reproducing routing decisions made historically.
{
"capabilities": {
"extendedAgentCard": false,
"extensions": [
{
"description": "MCP server exposing audit_transaction over streamable-HTTP.",
"params": {
"discoveryUrl": "https://auditor.webmesh.ai/.well-known/mcp.json",
"endpoint": "https://auditor.webmesh.ai/mcp",
"protocolVersion": "2025-03-26",
"transport": "streamable-http"
},
"required": false,
"uri": "https://modelcontextprotocol.io"
},
{
"description": "Identity and interoperability stack: ANS Trust Card (x5c chain + stapled SCITT receipt), DNS-AID SVCB with DNSSEC and DANE TLSA, DNSid organizational accountability, ARD / AI-Catalog discovery, and Web Bot Auth (RFC 9421 HTTP Message Signatures) outbound request signing.",
"params": {
"agentFacts": "https://auditor.webmesh.ai/agentfacts.json",
"ard": "https://auditor.webmesh.ai/.well-known/ard.json",
"httpMessageSignaturesDirectory": "https://auditor.webmesh.ai/.well-known/http-message-signatures-directory",
"identityAnchors": [
"ans-x509",
"did:web",
"dns-aid",
"dnssec",
"dane-tlsa",
"dnsid"
],
"outboundSigning": "web-bot-auth",
"trustCard": "https://auditor.webmesh.ai/.well-known/ans/trust-card.json"
},
"required": false,
"uri": "https://webmesh.ai/ext/ans-trust-stack/v1"
}
],
"pushNotifications": false,
"streaming": false
},
"defaultInputModes": [
"text/plain",
"application/json"
],
"defaultOutputModes": [
"application/json",
"text/plain"
],
"description": "Independently verifies any transaction from public evidence and produces a signed verdict. Runs 10 checks: identity chain x3 (ANS -> cert -> SCITT), mandate signature, DPoP binding, scope, amount, time window, SCITT receipt, and on-chain EIP-3009 settlement (eth_getTransactionReceipt on Base Sepolia public RPC). No privileged access.",
"documentationUrl": "https://agent.webmesh.ai",
"name": "Auditor Agent",
"protocolVersion": "1.0",
"provider": {
"did": "did:web:auditor.webmesh.ai",
"organization": "Webmesh",
"url": "https://webmesh.ai"
},
"securityRequirements": [
{
"noAuth": []
}
],
"securitySchemes": {
"ansIdentityCert": {
"description": "ANS Identity Certificate issued by the ANS Registration Authority. The agent presents this cert during the TLS handshake; clients verify against the chain advertised in the Trust Card's keys[].x5c. See https://auditor.webmesh.ai/.well-known/ans/trust-card.json",
"type": "mutualTLS"
},
"httpMessageSignatures": {
"description": "RFC 9421 HTTP Message Signatures over response components, using the Ed25519 key advertised in the Trust Card. Public key directory at https://auditor.webmesh.ai/.well-known/http-message-signatures-directory",
"scheme": "signature",
"type": "http"
},
"noAuth": {
"description": "This agent is publicly accessible with no authentication required. All skills are available to any caller.",
"type": "noAuth"
}
},
"signatures": [
{
"header": {
"kid": "9C4kWauHaoCU2szkbq4owfOGT_nFReTQ3dN_FsPWnEA"
},
"protected": "eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYXVkaXRvci53ZWJtZXNoLmFpLy53ZWxsLWtub3duL2Fucy90cnVzdC1jYXJkLmpzb24iLCJraWQiOiI5QzRrV2F1SGFvQ1Uyc3prYnE0b3dmT0dUX25GUmVUUTNkTl9Gc1BXbkVBIiwidHlwIjoiYWdlbnQtY2FyZCtqd3MifQ",
"signature": "AFcjqVVpjiIo6LBEqHSyQOD9uMSK1qGZa74TPipLBpjrq7K1hWhTWi5tbXVRczMA91Mh_rod-yuBM3JpBmR9fA"
}
],
"skills": [
{
"description": "Verify evidence bundle; produce signed audit report. 10 checks: identity chain, mandate sig, DPoP, scope, amount, time window, SCITT, on-chain settlement.",
"examples": [
"Audit booking T-1042"
],
"id": "audit_transaction",
"inputModes": [
"application/json"
],
"name": "Audit Transaction",
"outputModes": [
"application/json"
],
"securityRequirements": [
{
"noAuth": []
}
],
"tags": [
"audit",
"verification",
"compliance",
"eip3009",
"settlement"
]
}
],
"supportedInterfaces": [
{
"protocolBinding": "jsonrpc",
"protocolVersion": "1.0",
"url": "https://auditor.webmesh.ai"
}
],
"url": "https://auditor.webmesh.ai",
"version": "1.0.4",
"x-discovery": {
"ans_name": "ans://v1.0.4.auditor.webmesh.ai",
"ans_registered": "prod",
"dns_aid_svcb": "auditor.webmesh.ai IN SVCB 1 . alpn=a2a,h2",
"tl_badge": "https://transparency.ans.godaddy.com/v1/agents/feaf658f-4684-47c7-a8e1-bfcc745dcb27",
"trust_index": {
"auth": "sso-key",
"score_field": "scores.trustScore",
"score_url": "https://api.godaddy.com/v1/ans/registered-agents?query=auditor.webmesh.ai"
}
},
"x-identity": {
"ans": {
"transparencyLog": "https://transparency.ans.godaddy.com/v1/agents/feaf658f-4684-47c7-a8e1-bfcc745dcb27",
"trustCard": "https://auditor.webmesh.ai/.well-known/ans/trust-card.json",
"uri": "ans://v1.0.4.auditor.webmesh.ai"
},
"wimse": {
"jwksUri": "https://auditor.webmesh.ai/.well-known/jwks.json",
"signingAlgs": [
"EdDSA"
],
"spiffeId": "spiffe://webmesh.ai/agents/auditor",
"supportedProfiles": [
"urn:ietf:params:wimse:agent-delegation-chain"
]
}
},
"x-security-note": "This agent is publicly accessible with no authentication required (noAuth). The ansIdentityCert scheme (mutual TLS, ANS private CA) is declared for future ANS-to-ANS production calls but is not currently enforced. The card accurately describes what is enforced."
}