{"audit":{"version":"1.3","generated_at":"2026-07-21T09:00:12.414982+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/deropay.derod.org","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"deropay.derod.org","name":"DeroPay Documentation","url":"https://deropay.derod.org/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"DERO Project","url":"https://derod.org"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":null,"supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"wrong_response","live_responds":false,"last_status_code":200,"last_elapsed_ms":68,"last_error":null},"track_record":{"first_seen":"2026-07-20T07:15:22.688452+00:00","last_checked":"2026-07-21T06:32:55.001288+00:00","last_seen_ok":"2026-07-21T06:32:55.001288+00:00","checks_total":3,"checks_ok":3,"uptime_pct":100.0,"archived":false,"archived_reason":null},"conformance":{"score":37,"grade":"F","summary":"F-grade: card is reachable but fails most operational signals.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Schema-validated A2A AgentCard returned by the well-known endpoint."},{"key":"live_responds","label":"Live JSON-RPC","points":5,"max_points":25,"status":"fail","detail":"Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response."},{"key":"protocol_version","label":"Protocol version","points":0,"max_points":10,"status":"fail","detail":"No protocolVersion in card."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 3 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 4 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: DERO Project (https://derod.org). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":5,"max_points":5,"status":"pass","detail":"declares 1 modern capability flag(s) (x402); seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":2,"max_points":5,"status":"partial","detail":"Declares 1 security scheme(s) but none use PKCE or mTLS."}]},"skills":[{"id":"integrate_dero_payments","name":"Integrate DERO-native payments","description":"Add DERO payment processing to a web application — invoice generation, payment monitoring, settlement, and reconciliation against on-chain state.","tags":["payments","dero","integration","next-js"],"examples":["Add DeroPay to a Next.js checkout flow.","How does DeroPay detect a paid invoice?","What is the settlement model for DeroPay?"],"inputModes":[],"outputModes":[]},{"id":"implement_dero_auth","name":"Implement DeroAuth wallet login","description":"Wire challenge/sign/verify wallet authentication using the `dero-auth` package. Covers Schnorr signatures on BN256, custom generator point, Keccak-256 hashing, and Bech32 address encoding.","tags":["auth","wallet-login","schnorr","cryptography"],"examples":["Implement Sign In with DERO on my web app.","How does DeroAuth verify a wallet signature server-side?","What is the challenge/sign/verify flow?"],"inputModes":[],"outputModes":[]},{"id":"gate_with_x402","name":"Gate routes with HTTP 402 (x402)","description":"Use DeroPay's x402 guard to charge per-request access to API routes and resources, denominated in DERO and settled on-chain.","tags":["x402","http-402","pay-per-request","api-gating"],"examples":["Add an x402 guard to a Next.js API route.","How does x402 settle payment on-chain?","What headers does the x402 challenge response include?"],"inputModes":[],"outputModes":[]},{"id":"search_deropay_docs","name":"Search and navigate DeroPay documentation","description":"Full-text search across the DeroPay docs corpus — payments, auth, escrow, x402. Every page has a `.md` mirror for direct agent ingestion.","tags":["docs","search","navigation"],"examples":["Find docs on the DeroPay escrow contract.","List DeroAuth cryptography references.","How do I test DeroPay against a local simulator?"],"inputModes":[],"outputModes":[]}],"provenance":[{"source":"github_code","first_seen":"2026-07-20T07:15:22.688452+00:00"},{"source":"manifests","first_seen":"2026-07-20T18:18:30.180126+00:00"}],"recent_probes":[{"fetched_at":"2026-07-21T06:32:55.001288+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":68,"live_responds":false},{"fetched_at":"2026-07-20T18:18:30.180126+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":25,"live_responds":false},{"fetched_at":"2026-07-20T07:15:22.688452+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":190,"live_responds":false}],"catalog_attestation":null,"verification_history":[],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vYWdlbnN0cnkuY29tLy53ZWxsLWtub3duL2p3a3MuanNvbiIsImtpZCI6ImFnZW50ZmluZGVyLWVzMjU2LTEiLCJ0eXAiOiJKT1NFIn0","signature":"2kaa-Yh260KkAH2XbUFMyt3PijhjhFn9RXiNJEgQGBl-XRKT74KyoFfEwxPoWTt2VpFz8AdGbfhY7oKRJhqWKg"}]}