Skip to content
Back to Auth Posture

Card snapshot

auth-posture.rowb.app · 2026-09-28 10:16:53 UTC · c2a70d0dfb5b00a72adedf1710ee6ccb662e7df39ad9a5195fecc8d3b6d97ba5

This is a frozen copy of the agent's agent-card.json as we observed it at the timestamp above. We capture a new snapshot every time the card's content hash changes. Useful for: forensic drift analysis, verifying downstream callers see the right version, reproducing routing decisions made historically.

{
  "name": "Auth Posture",
  "description": "One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.",
  "supportedInterfaces": [
    {
      "url": "https://auth-posture.rowb.app/mcp",
      "protocolBinding": "MCP",
      "protocolVersion": "1.0"
    },
    {
      "url": "https://auth-posture.rowb.app",
      "protocolBinding": "REST",
      "protocolVersion": "1.0"
    }
  ],
  "provider": {
    "organization": "rowb.app",
    "url": "https://rowb.app"
  },
  "version": "1.0.0",
  "documentationUrl": "https://auth-posture.rowb.app/llms.txt",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "extendedAgentCard": false
  },
  "defaultInputModes": [
    "application/json",
    "text/plain"
  ],
  "defaultOutputModes": [
    "application/json",
    "text/plain"
  ],
  "skills": [
    {
      "id": "audit-domain",
      "name": "Audit domain email posture",
      "description": "Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous 3/day). MCP tool: audit_domain.",
      "tags": [
        "email",
        "mx",
        "spf",
        "dmarc",
        "dkim",
        "disposable"
      ]
    }
  ],
  "mcpUrl": "https://auth-posture.rowb.app/mcp"
}