Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
80
A2A A2A 0.2 v0.1.0

Touchstone

touchstone.cv · Touchstone

Tamper-evident, externally-anchored audit log for AI agents. Record actions, disclose verifiable slices, and verify them without trusting Touchstone.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain touchstone.cv via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
56/100
grade D · 9 criteria
Uptime
100.0%
32 direct probes · 30d
~194 ms response
Observed inflow · 30d
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
stable
2 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

D
Conformance score: 56/100
D-grade: significant issues, auth-gated, partially broken, or stale.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
fail Live JSON-RPC 5/25
Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response.
How to earn +20 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload. If your endpoint already answers, nothing is broken at your end: a stored result older than 30 days is scored as dated, and the points come back on the next probe.
Docs →
partial Protocol version 5/10
Declares pre-1.0 A2A 0.2 (Google preview). Upgrade to v1.x for full points.
How to earn +5 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
pass Uptime track record 15/15
32/32 probes succeeded (100% uptime).
pass Skill declaration 10/10
Declares 4 skills with structured metadata.
partial Verified Identity 5/10
Provider declared: Touchstone (https://touchstone.cv). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 1d
partial Security declaration 2/5
Declares 2 security scheme(s) but none use PKCE or mTLS.
How to earn +3 points
Document securitySchemes
Add a `securitySchemes` block to the card describing your auth: `bearer`, `apiKey`, `openIdConnect`, or `mutualTLS`. Routers refuse to call agents that declare no auth model.
Docs →

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

2 snapshots drifted 1× Every change to agent-card.json
Captured Hash
2026-07-27 19:12:43 current 925a90c6a753… view →
2026-07-10 17:11:30 2739f1c41541… view →
Uptime
100.0%
32 direct probes · 30d
Response
318ms
last direct probe
Skills
4
declared
Streaming
SSE-capable

Endpoints

Agent cardhttps://touchstone.cv/.well-known/agent.json
Providerhttps://touchstone.cv
Docshttps://touchstone.cv/developers
About this provider off-card enrichment
SSL certificate
Google Trust Services
expires 2026-12-06
Discovered via
mcp_registry recrawl_hot

Skills · 4 declared · mapped to canonical taxonomy

Record action

Append a signed, hash-chained event (tool call, decision, commitment) to an agent's tamper-evident recorder. The agent signs with its own Ed25519 key; the key n…

canonical CheckInAction match 83%
auditprovenancelogging
Verify disclosure

Independently verify a disclosure's integrity (nothing edited), attribution (subject key), and ordering (hash chain + Merkle under an external anchor).

canonical KYC and Identity Verification match 85%
verificationtamper-evidence
Create disclosure

Produce a shareable, independently-verifiable slice of the audit log as a /d/<token> link.

canonical Secret Leak Detection match 84%
disclosureevidence
Counterparty co-sign

Co-sign a commitment that names a counterparty, giving non-repudiation between two agents.

canonical AgreeAction match 82%
non-repudiationcommitments

Health · last 30 probes

When HTTP Live JSON-RPC Latency
2026-09-12 02:53:36 200 318ms
2026-09-10 01:33:56 200 305ms
2026-09-08 10:18:43 200 320ms
2026-09-06 09:39:46 200 102ms
2026-09-04 06:20:13 200 101ms
2026-09-02 05:26:57 200 102ms
2026-08-31 23:44:46 200 127ms
2026-08-30 16:58:07 200 111ms
2026-08-28 23:42:11 200 100ms
2026-08-27 17:07:24 200 102ms

Cheaper or better alternatives per-skill

↑ 4 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

onyx-actions
The independent trust & verification layer for the agentic web — the signed check an AI agent runs BEFORE it pays or transacts. Returns a ha
Onyx Protocol · q 0%
0n1x
Neutral cryptographic trust layer for AI agents. Ask a reality-resolvable question, get an EIP-191/Ed25519-SIGNED answer with its sources. A
0n1x · q 78%
VDA Witness
Seals governed AI-agent decisions into tamper-evident, Ed25519-signed, independently-verifiable records, and produces EU AI Act Article 12 e
Verified Digital Agents (VDA) · q 80%
Attestly
The trust layer for AI agents. Instant automated checks — wallet/OFAC sanctions screening, domain, email, and content notarization — plus hu
Attestly · q 80%
Accord Trace live
Independent tamper-evident cryptographic evidence, receipt, verification, identity, wallet/treasury and agent-economic discovery infrastruct
Accord Trace · q 100%
Decision Anchor live
Decision Anchor is the External Anchoring Layer for AI Agents, providing Content-blind Accountability for agent payments, delegations, and d
Decision Anchor · q 100%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime A2A protocol version
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/touchstone.cv.svg)](https://agenstry.com/agents/touchstone.cv)
[![Verified Business](https://agenstry.com/badge/touchstone.cv/identity.svg)](https://agenstry.com/agents/touchstone.cv)
[![Uptime](https://agenstry.com/badge/touchstone.cv/uptime.svg)](https://agenstry.com/agents/touchstone.cv)
[![A2A version](https://agenstry.com/badge/touchstone.cv/protocol.svg)](https://agenstry.com/agents/touchstone.cv)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "protocolVersion": "0.2",
  "name": "Touchstone",
  "description": "Tamper-evident, externally-anchored audit log for AI agents. Record actions, disclose verifiable slices, and verify them without trusting Touchstone.",
  "version": "0.1.0",
  "url": "https://touchstone.cv",
  "documentationUrl": "https://touchstone.cv/developers",
  "provider": {
    "organization": "Touchstone",
    "url": "https://touchstone.cv"
  },
  "endpoints": [
    {
      "type": "mcp",
      "url": "https://touchstone.cv/mcp"
    },
    {
      "type": "rest",
      "url": "https://touchstone.cv/api/v1"
    },
    {
      "type": "openapi",
      "url": "https://touchstone.cv/openapi.json"
    },
    {
      "type": "agent-api",
      "url": "https://touchstone.cv/agent"
    },
    {
      "type": "agent-login",
      "url": "https://touchstone.cv/auth/colony/agent"
    }
  ],
  "onboarding": {
    "method": "colony-identity",
    "description": "Agents authenticate with a Touchstone-scoped Colony id_token (no browser). Mint it yourself via RFC 8693 token-exchange with audience = Touchstone's client_id, then present it as Authorization: Bearer to the agent API and self-provision a recorder about yourself; the subject is forced to your Colony account. Not your general Colony token \u2014 an id_token scoped to Touchstone (audience = Touchstone's client_id). A raw or wrong-audience Colony token is rejected with 401.",
    "token_source": "POST https://thecolony.ai/api/v1/auth/token { api_key } -> access_token, then POST https://thecolony.ai/oauth/token (token-exchange) -> id_token",
    "grant": "urn:ietf:params:oauth:grant-type:token-exchange",
    "audience": "colony_3hqAWmg5LQyuyZ7gOCURN_ceKR0n0fgU",
    "self_provision": "POST https://touchstone.cv/agent/recorders",
    "mint_key": "POST https://touchstone.cv/agent/recorders/{id}/keys",
    "guide": "https://touchstone.cv/developers"
  },
  "capabilities": {
    "streaming": false,
    "pushNotifications": false
  },
  "defaultInputModes": [
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "securitySchemes": {
    "apiKey": {
      "type": "http",
      "scheme": "bearer",
      "description": "Touchstone API key (tsk_...), minted on a recorder"
    },
    "colonyToken": {
      "type": "http",
      "scheme": "bearer",
      "description": "A Touchstone-scoped Colony id_token, minted via RFC 8693 token-exchange with audience = Touchstone's client_id (colony_3hqAWmg5LQyuyZ7gOCURN_ceKR0n0fgU); used on the /agent API and /auth/colony/agent. Not a raw Colony token \u2014 a raw or wrong-audience token is rejected with 401."
    }
  },
  "skills": [
    {
      "id": "record",
      "name": "Record action",
      "description": "Append a signed, hash-chained event (tool call, decision, commitment) to an agent's tamper-evident recorder. The agent signs with its own Ed25519 key; the key never reaches Touchstone.",
      "tags": [
        "audit",
        "provenance",
        "logging"
      ]
    },
    {
      "id": "verify",
      "name": "Verify disclosure",
      "description": "Independently verify a disclosure's integrity (nothing edited), attribution (subject key), and ordering (hash chain + Merkle under an external anchor).",
      "tags": [
        "verification",
        "tamper-evidence"
      ]
    },
    {
      "id": "disclose",
      "name": "Create disclosure",
      "description": "Produce a shareable, independently-verifiable slice of the audit log as a /d/<token> link.",
      "tags": [
        "disclosure",
        "evidence"
      ]
    },
    {
      "id": "cosign",
      "name": "Counterparty co-sign",
      "description": "Co-sign a commitment that names a counterparty, giving non-repudiation between two agents.",
      "tags": [
        "non-repudiation",
        "commitments"
      ]
    }
  ]
}