{"audit":{"version":"1.5","generated_at":"2026-10-03T05:43:54.366194+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/hookpulse.net","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"hookpulse.net","name":"HookPulse","url":"https://hookpulse.net/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"HookPulse","url":"https://hookpulse.net"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":null,"supports_streaming":true,"supports_push_notifications":false},"operational":{"live_state":"live","live_responds":true,"last_status_code":200,"last_elapsed_ms":210,"last_error":null},"track_record":{"first_seen":"2026-09-30T23:33:08.862947+00:00","last_checked":"2026-10-03T03:59:09.329649+00:00","last_seen_ok":"2026-10-03T03:59:09.329649+00:00","checks_total":10,"checks_ok":10,"uptime_pct":100.0,"uptime_window_days":30,"uptime_probes":1,"archived":false,"archived_reason":null},"conformance":{"score":55,"grade":"D","summary":"D-grade: significant issues, auth-gated, partially broken, or stale.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":25,"max_points":25,"status":"pass","detail":"Endpoint responds to a negotiated A2A SendMessage probe (answers in ~441 ms)."},{"key":"protocol_version","label":"Protocol version","points":0,"max_points":10,"status":"fail","detail":"No protocolVersion in card."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 1 probe so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 24 skills with structured metadata. 24 skills without tags — optional in 0.x, REQUIRED once you move the card to v1.0."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: HookPulse (https://hookpulse.net). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":5,"max_points":5,"status":"pass","detail":"declares 1 modern capability flag(s) (x402); seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":0,"max_points":5,"status":"info","detail":"Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated."}]},"card_read":{"findings":[],"clean":true,"source_url":"https://hookpulse.net/.well-known/agent-card.json"},"skills":[{"id":"list_environments","name":"list_environments","description":"Saved environments owned by the current account or guest; empty without a session.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes"},{"id":"create_environment","name":"create_environment","description":"Register a device UUID before discovery and collector selection. Registers one device (maximum 25 per owner), creating a guest if needed. The UUID is the one-hour discovery capability; it is not a telemetry credential. Choose passos.posix or passos.powershell for the TARGET terminal. The checks only display allowlisted system facts and install nothing.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/ambientes"},{"id":"get_environment","name":"get_environment","description":"Read the detected environment and compatible measurements.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes/:id"},{"id":"create_device_input","name":"create_device_input","description":"Create or rotate an authenticated collector channel for this device. Ownership is checked before the app asks the input central. The server chooses the channel id and authenticates batches only against a hash of the collector credential. The whole setup this call returns — credential included — is also saved, encrypted with a key only the input central holds and bound to that credential, so the owner can read it again with GET /api/ambientes/:id/inputs/:collector/setup. The credential does not expire: a device that stays off for weeks reconnects with it. It stops working only when a new configuration rotates it or the channel is removed. A repeated call for the same collector rotates the credential, replaces the saved setup and replaces `monitoring` with the list sent — that is how the monitored scope is edited — so the configuration on the device stops authenticating until it is replaced; a paused channel stays paused. DNS selects the receiver; it never authenticates the device.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/ambientes/:id/inputs"},{"id":"list_device_inputs","name":"list_device_inputs","description":"List this device's collector channels, their state and their live numbers.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes/:id/inputs"},{"id":"get_device_input_setup","name":"get_device_input_setup","description":"The saved setup of one collector channel: the configuration in use, its files and steps. Returns the setup generated last for this channel — the one whose credential is accepted now — exactly as POST /api/ambientes/:id/inputs returned it, so the files can be copied or installed again without rotating the credential. It carries the credential: only the device owner gets it, one channel per request, never cached; list routes never include it. 404 `setup_not_saved` when the channel was generated before setups were saved, or was removed; 409 `setup_unreadable` when the input central can no longer open it. In both cases generate a new setup with POST /api/ambientes/:id/inputs.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes/:id/inputs/:collector/setup"},{"id":"list_device_input_history","name":"list_device_input_history","description":"The batches this collector sent, newest first — filtered and paginated on the server. Every batch the input central received for this channel, as it arrived: when, the protocol, the result (`stored`; `rejected` by the receiver, with the reason; or `discarded` while the channel was paused, when its data is not kept), the answer given to the collector, the size, and how many series and samples it carried. The central keeps the newest batches of each channel up to the limits in `limits` (count, bytes and days); older ones leave as new ones arrive, and removing the channel deletes them. `q` searches metric names — host and service names for NCPA — by opening the batches newest first within a time budget: `search.complete` says whether all candidates were read, and repeating the call continues faster. Open one batch with GET /api/ambientes/:id/inputs/:collector/history/:batch.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes/:id/inputs/:collector/history"},{"id":"get_device_input_batch","name":"get_device_input_batch","description":"One received batch, decoded: its series with labels and values, or its NCPA checks. Remote Write (1.0 and 2.0), OTLP (protobuf or JSON) and NRDP become the same shape: `series` (`name`, `labels`, `points` as `[milliseconds, value]`, and `type`/`unit`/`help` when the collector sent them; OTLP points also carry `resource`, an index into `resources`) or `checks` for NCPA (`host`, `service`, `state` 0–3, `output`, `perfdata`). A value JSON cannot hold comes as a string: `\"NaN\"`, `\"+Inf\"`, `\"-Inf\"` or `\"stale\"`. Very large batches keep the first 5,000 series (`truncated`). `newer`/`older` are the neighbouring batch ids, for moving through the history.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/ambientes/:id/inputs/:collector/history/:batch"},{"id":"delete_device_input","name":"delete_device_input","description":"Revokes and removes one collector channel from a device. The input central removes only a channel of the same owner. This stops new authenticated input and removes the channel from the device list — also for a channel whose device was already deleted. It does not uninstall or stop the collector on the device (`uninstall.remove` in GET /api/ambientes/:id/inputs is the command for that), and stored measurements remain subject to their retention policy.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"DELETE /api/ambientes/:id/inputs/:collector"},{"id":"set_device_input_active","name":"set_device_input_active","description":"Pauses or resumes one collector channel. Pausing keeps the channel, its credential and its configuration: batches the collector sends while paused are accepted and discarded, so nothing is stored or measured and the collector does not retry in a loop. Resuming stores the next batch again. The input central changes only a channel of the same owner, including one whose device was already deleted.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"PATCH /api/ambientes/:id/inputs/:collector"},{"id":"list_input_fleet","name":"list_input_fleet","description":"Every collector channel of the caller, with state and live numbers, in one response. One call for the whole fleet — one query to the time-series store for all channels, never one per device. It is the same function the dashboard subscribes to over the socket (`/api/inputs/serie`), where the input central then pushes `inputs.updated` and `inputs.removed` events; integrators get the same data here without the socket.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/inputs/serie"},{"id":"report_environment","name":"report_environment","description":"Preview or save the allowlisted discovery report for one device. Send terminal and saidas (step id to pasted output), initially with conferir:true. Preview returns normalized dados, additional passos and pronto without writing. Omit conferir to save when complete. Only allowlisted facts are saved, never raw commands. First report wins within one hour; identical retries do not rewrite. The discovery never creates a legacy measurement, sends a reading, installs software or creates a schedule. With Accept: text/plain the receipt is only `ok`.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/ambientes/:id/relatorio"},{"id":"list_collections","name":"list_collections","description":"Lists your measurements with commands adapted to each saved device environment. Two views of the same thing: `coletas` is one entry per measurement, `equipamentos` is one per machine with a SINGLE command that does all of its measurements and a SINGLE cron line. Use the device one unless you really want a single measurement on its own. Commands are generated only from a detected environment. Legacy collections without one keep their readings, but comandos.agora/agenda are null until a compatible environment is provided. Curl, wget and Python 3 follow the detected capabilities; Windows disk uses PowerShell. comandos.agora is a readable multiline block; run the whole block together. A separate cron line is offered only when crontab exists. Unsupported formats are never guessed.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/coletas"},{"id":"create_collection","name":"create_collection","description":"Adds compatible measurements to a previously detected device. First create /api/ambientes and submit its environment report. Reference that ambiente_id here; its saved name and group are authoritative. Same device+measurement returns the existing stream instead of duplicating it. A profile adds only compatible measurements. Up to 200 collections per owner. The signed collection id writes only its own measurement stream.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/coletas"},{"id":"get_collection_series","name":"get_collection_series","description":"The latest readings of one device, for the screen that draws it. Authorised by YOUR session, never by the symbol in the crontab. A device that is not yours answers 404 exactly like one that does not exist — telling the two apart would confirm to a stranger that the id exists — 401 is only for sending no credential at all, which tells the caller what they already know. When the ingest origin cannot be read the answer is 503, not an empty series: a screen must say \"I could not read now\", never let you believe your machine stopped. Readings are reused for up to 60 seconds. Poll no faster than once per minute in steady use; `poll_after_sec` is the minimum wait for this response. During the first minute after registration an empty series may be checked every 5 seconds. Do not overlap requests. On 429 or 503, respect `Retry-After` and `retry_after_sec`, increase the delay after repeated failures, and keep the last successful reading. Changing n does not bypass reuse or capacity limits.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/coletas/:id/serie"},{"id":"update_collection","name":"update_collection","description":"Renames one measurement, or stops and resumes reading it. The id never changes: it is the write symbol already sitting in a crontab, and renaming on a screen must not send anyone back to the machine to edit a line. Send only what you are changing; anything omitted stays as it is. `ativa:false` takes the measurement out of the fleet read — it keeps its history and its commands, stops costing a query, and comes back with `ativa:true`. It does NOT silence the machine: the symbol is signed and stands on its own at the ingest origin, so a device keeps sending until you remove its cron line. The answer is the collection as it now stands — draw the screen from it, not from a local copy.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"PATCH /api/coletas/:id"},{"id":"delete_collection","name":"delete_collection","description":"Removes one measurement and frees that slot on the device. What disappears is the OWNERSHIP: your list, the authority to read that series, and the unique slot that measurement holds on that environment — so you can add it again later. Readings already stored at the ingest origin stay there until their own retention. The machine keeps sending: the symbol is signed and stands on its own there, which is why the answer carries `remover`, the command that takes the line out of the crontab. Use `ativa:false` instead when you only want to stop looking.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"DELETE /api/coletas/:id"},{"id":"update_environment","name":"update_environment","description":"Renames a device, and its measurements along with it. One machine has one name. The measurements carry a copy of it, so renaming here renames them too — leaving the old name on them would show the same machine twice in a list that groups by device. Its collector channels take the new name and group too in `GET /api/coletas` (`inputs[]`), and the group decides which dashboard tab the device is under. Send only what changes; what you omit stays. The detected environment is never rewritten: it is evidence of what that machine reported.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"PATCH /api/ambientes/:id"},{"id":"delete_environment","name":"delete_environment","description":"Removes a device and every measurement on it, in one call. One call, not one per measurement — the same reason `GET /api/coletas/serie` exists. What goes away is the ownership: your list, the authority to read those series, and the slots those measurements held, so the device can be registered again. Readings already stored at the ingest origin stay there until their own retention, and the machine keeps sending: the symbols are signed and stand on their own there. That is why the answer carries `remover`, one command per measurement that had a cron line. The device's collector channels are revoked first; if the input central cannot confirm that, nothing is deleted (503) and the call can be repeated, so no channel is left receiving data without a device.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"DELETE /api/ambientes/:id"},{"id":"api_index","name":"api_index","description":"Full index of the HookPulse API.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/"},{"id":"health","name":"health","description":"Liveness.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/health"},{"id":"create_guest","name":"create_guest","description":"Creates a guest token hp_… Keep the token: without it there is no way back to the monitors, unless you have already tied them to an e-mail.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/guest"},{"id":"list_endpoints","name":"list_endpoints","description":"Lists the guest's/session's endpoints.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"GET /api/endpoints"},{"id":"create_endpoint","name":"create_endpoint","description":"Creates a dead-man endpoint. Use cron+tz+grace_sec for a real schedule (mutually exclusive with interval_sec) or interval_sec for plain silence detection. max_duration_sec alerts when a run opened by /in/:id/start hangs. May return 402 x402 when it leaves the free tier. This response is the only one that shows the monitor's `token` and the `templates` — keep them. The second monitor, or an interval below the free minimum, answers **402 with `accepts[]`**: pay and repeat. A miss alerts at most once per 24h — or per `alert_repeat_sec`, or per interval, whichever is longer. Send `cron`+`tz`+`grace_sec` instead of `interval_sec` for a real schedule: a 03:00 backup is late at 03:01:30, not 24 hours later. `max_duration_sec` catches the other failure: a run that starts and hangs, which plain silence detection only notices at the next scheduled time.","tags":[],"examples":[],"inputModes":[],"outputModes":[],"endpoint":"POST /api/endpoints"}],"provenance":[{"source":"cdp_discovery","first_seen":"2026-09-30T23:33:08.862947+00:00"},{"source":"recrawl_warm","first_seen":"2026-10-03T03:59:09.329649+00:00"}],"recent_probes":[{"fetched_at":"2026-10-03T03:59:09.329649+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":210,"live_responds":true}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-10-03T05:43:54.371113+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/hookpulse.net/evidence","dispute_url":"https://agenstry.com/agents/hookpulse.net/dispute"},"verification_history":[]}