{"domain":"authority.webmesh.ai","count":1,"changes":[{"captured_at":"2026-09-24T17:33:46","card_hash":"7576b2c21e24bbf0e8d944aed347c6dde2abd6511484eacf718d698ee9d62d2c","previous_card_hash":null,"diff":{"skills_added":[{"id":"get_policy","name":"Get Policy","description":"Return the current spending policy (max_per_trip, currency, allowed_merchants, categories).","tags":["mandate","policy"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"request_mandate","name":"Issue Mandate","description":"Issue a signed AP2 mandate with DPoP key binding (jkt). Requires a compact EdDSA JWS (request_jws) signed by the caller's ANS identity key, binding subject_ans, quote_id, total, currency, merchant_ans, scope_hint, and traveler_dpop_jwk. Freshness window: 300 s. Replay protection: jti must be unique. JWKS fetched from the caller's ANS JWKS endpoint.","tags":["mandate","authorization","dpop","requester-signature"],"inputModes":["application/json"],"outputModes":["application/json"]}],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"name","before":null,"after":"Spending Authority"},{"field":"description","before":null,"after":"The human's spending policy as a machine-verifiable instrument. Approves once and issues narrowly scoped RFC 9421 AP2 mandates with DPoP key binding (jkt). Stubbed Auth0 consent for the demo; mandate is the wire artifact the Supplier verifies and the Auditor checks."},{"field":"version","before":null,"after":"1.0.4"},{"field":"protocolVersion","before":null,"after":"1.0"},{"field":"url","before":null,"after":"https://authority.webmesh.ai"},{"field":"documentationUrl","before":null,"after":"https://agent.webmesh.ai"},{"field":"supportedInterfaces","before":null,"after":[{"protocolBinding":"jsonrpc","protocolVersion":"1.0","url":"https://authority.webmesh.ai"}]},{"field":"securitySchemes","before":null,"after":{"ansIdentityCert":{"description":"ANS Identity Certificate issued by the ANS Registration Authority. The agent presents this cert during the TLS handshake; clients verify against the chain advertised in the Trust Card's keys[].x5c. See https://authority.webmesh.ai/.well-known/ans/trust-card.json","type":"mutualTLS"},"httpMessageSignatures":{"description":"RFC 9421 HTTP Message Signatures over response components, using the Ed25519 key advertised in the Trust Card. Public key directory at https://authority.webmesh.ai/.well-known/http-message-signatures-directory","scheme":"signature","type":"http"},"noAuth":{"description":"This agent is publicly accessible with no authentication required. All skills are available to any caller.","type":"noAuth"},"requesterSignature":{"alg":"EdDSA","boundArgs":["subject_ans","quote_id","total","currency","merchant_ans","scope_hint","traveler_dpop_jwk"],"denialCodes":["REQUEST_NOT_SIGNED","BAD_SIGNATURE","STALE_REQUEST","REPLAYED_REQUEST","SUBJECT_MISMATCH","ARGS_MISMATCH","IDENTITY_UNVERIFIED","INSUFFICIENT_FUNDS"],"description":"Caller must include request_jws: a compact JWS (alg=EdDSA) signed with the caller's ANS identity Ed25519 key. Payload must bind: subject_ans, quote_id, total, currency, merchant_ans, scope_hint, traveler_dpop_jwk. Freshness: iat within 300 s of server time. Replay protection: jti stored per-request for 2x the freshness window; reuse is denied. JWKS discovery: authority resolves the caller's public key from {caller_host}/.well-known/jwks.json (internal loopback when GOVWARE_JWKS_INTERNAL_{SUBDOMAIN} is set). Denial codes: REQUEST_NOT_SIGNED, BAD_SIGNATURE, STALE_REQUEST, REPLAYED_REQUEST, SUBJECT_MISMATCH, ARGS_MISMATCH, IDENTITY_UNVERIFIED, INSUFFICIENT_FUNDS.","format":"compact-jws","freshnessSecs":300,"in":"toolArgument","jwksDiscovery":"caller-ans-jwks","name":"request_jws","replayProtection":"jti-dedup","type":"requesterJws"}}},{"field":"capabilities","before":null,"after":{"extendedAgentCard":false,"extensions":[{"description":"MCP server exposing request_mandate and get_policy over streamable-HTTP.","params":{"discoveryUrl":"https://authority.webmesh.ai/.well-known/mcp.json","endpoint":"https://authority.webmesh.ai/mcp","protocolVersion":"2025-03-26","transport":"streamable-http"},"required":false,"uri":"https://modelcontextprotocol.io"},{"description":"Identity and interoperability stack: ANS Trust Card (x5c chain + stapled SCITT receipt), DNS-AID SVCB with DNSSEC and DANE TLSA, DNSid organizational accountability, ARD / AI-Catalog discovery, and Web Bot Auth (RFC 9421 HTTP Message Signatures) outbound request signing.","params":{"agentFacts":"https://authority.webmesh.ai/agentfacts.json","ard":"https://authority.webmesh.ai/.well-known/ard.json","httpMessageSignaturesDirectory":"https://authority.webmesh.ai/.well-known/http-message-signatures-directory","identityAnchors":["ans-x509","did:web","dns-aid","dnssec","dane-tlsa","dnsid"],"outboundSigning":"web-bot-auth","trustCard":"https://authority.webmesh.ai/.well-known/ans/trust-card.json"},"required":false,"uri":"https://webmesh.ai/ext/ans-trust-stack/v1"}],"pushNotifications":false,"streaming":false}},{"field":"provider","before":null,"after":{"did":"did:web:authority.webmesh.ai","organization":"Webmesh","url":"https://webmesh.ai"}}],"other_changed":true,"is_empty":false,"human_summary":"added 2 skills · name ∅ → Spending Authority · description ∅ → The human's spending policy as a machine · version ∅ → 1.0.4 · protocolVersion ∅ → 1.0 · url ∅ → https://authority.webmesh.ai · documentationUrl ∅ → https://agent.webmesh.ai · supportedInterfaces ∅ → https://authority.webmesh.ai (jsonrpc) · securitySchemes ∅ → ansIdentityCert, httpMessageSignatures,  · capabilities ∅ → extendedAgentCard, extensions, pushNotif · provider ∅ → Webmesh"}}]}