{"audit":{"version":"1.4","generated_at":"2026-08-19T19:08:40.462520+00:00","generated_by":"Agenstry","report_url":"https://agenstry.com/agents/witness.getvda.ai","methodology_url":"https://agenstry.com/methodology","verifier_jwks_url":"https://agenstry.com/.well-known/jwks.json","subject":{"domain":"witness.getvda.ai","name":"VDA Witness","url":"https://witness.getvda.ai/.well-known/agent-card.json"}},"identity":{"provider":{"organization":"Verified Digital Agents (VDA)","url":"https://getvda.ai"},"registry_verification":null,"signature":{"signed":false,"signature_valid":null}},"protocol":{"version":"0.2.5","supports_streaming":false,"supports_push_notifications":false},"operational":{"live_state":"no_url","live_responds":null,"last_status_code":200,"last_elapsed_ms":69,"last_error":null},"track_record":{"first_seen":"2026-08-18T02:23:00.832236+00:00","last_checked":"2026-08-19T11:28:23.252883+00:00","last_seen_ok":"2026-08-19T11:28:23.252883+00:00","checks_total":4,"checks_ok":4,"uptime_pct":100.0,"archived":false,"archived_reason":null},"conformance":{"score":35,"grade":"F","summary":"F-grade: card is reachable but fails most operational signals.","criteria":[{"key":"valid_card","label":"Valid AgentCard","points":10,"max_points":10,"status":"pass","detail":"Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification)."},{"key":"live_responds","label":"Live JSON-RPC","points":2,"max_points":25,"status":"fail","detail":"Card is valid but has no .url field."},{"key":"protocol_version","label":"Protocol version","points":2,"max_points":10,"status":"partial","detail":"Declares unrecognised version '0.2.5'."},{"key":"signature","label":"JWS signature","points":0,"max_points":10,"status":"info","detail":"Card is unsigned (most published agents are)."},{"key":"uptime","label":"Uptime track record","points":0,"max_points":15,"status":"info","detail":"Only 4 probes so far, need ≥5 for an uptime grade."},{"key":"skills","label":"Skill declaration","points":10,"max_points":10,"status":"pass","detail":"Declares 15 skills with structured metadata."},{"key":"verified_identity","label":"Verified Identity","points":5,"max_points":10,"status":"partial","detail":"Provider declared: Verified Digital Agents (VDA) (https://getvda.ai). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit."},{"key":"freshness","label":"Freshness + modern flags","points":4,"max_points":5,"status":"pass","detail":"seen in upstream source within 0d"},{"key":"security","label":"Security declaration","points":2,"max_points":5,"status":"partial","detail":"Declares 1 security scheme(s) but none use PKCE or mTLS."}]},"card_read":{"findings":[{"field":"skills[0].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[1].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[2].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[3].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[4].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[4].examples[1]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[4].examples[2]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[5].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[5].examples[1]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[6].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[7].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[8].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[9].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[10].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[10].examples[1]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[11].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[12].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[13].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"},{"field":"skills[14].examples[0]","problem":"Input should be a valid string","action":"coerced","detail":"kept verbatim as text"}],"clean":false,"source_url":"https://witness.getvda.ai/.well-known/agent-card.json"},"skills":[{"id":"seal_hitl_decision","name":"Seal a human-in-the-loop decision","description":"Seals a governance record for a HUMAN decision. Content-based and auditor-reconstructable: it captures the deciding human's identity and role, the disposition and rationale, the policies/SOPs cited AS THE BASIS (by reference, and where possible captured text or hash — policies drift, so an auditor needs the version in force), and content-addressable references (with sha256 hashes) to the system-of-record artifacts the decider SAW at decision time — reservation records, folios, inventory state — NOT the action produced. From the sealed record alone an auditor can verify exactly what state the decider was looking at. Witness seals the ASSERTED actor identity; it does not authenticate the person. Use evidence[].inline to embed a snapshot (≤100KB; bytes are verified against the hash at seal time) when upstream availability isn't guaranteed. If a decision genuinely has no evidentiary basis, state it in evidence_omitted_reason rather than omitting silently. See the MCP `seal_hitl_decision` inputSchema for required fields.","tags":["evidence","hitl","governance","audit"],"examples":["{\"request\":{\"actor\":{\"id\":\"jane.ops@stay\",\"type\":\"human\",\"role\":\"duty-manager\"},\"decision\":{\"disposition\":\"approved\",\"statement\":\"Waived the late-cancel fee; guest showed a flight-cancellation notice.\"},\"governing_clauses\":[{\"ref\":\"SOP.cancellations#3.2\",\"text\":\"Duty managers MAY waive late-cancel fees on documented travel disruption.\",\"hash\":\"sha256:…\"}],\"evidence\":[{\"ref\":\"pms://reservation/RES-"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/seal/hitl-decision","security":[{"witnessApiKey":[]}]},{"id":"seal_agent_action","name":"Seal an autonomous agent action","description":"Seals a record for an action an agent took AUTONOMOUSLY under a governing rule. Records what the agent consumed as two fields split by provenance: `evidence` is EXTERNAL material it saw (content-addressed + hashed — e.g. a whoami response from another service), `parameters` is the COMPUTED arguments it was passed (self-contained, no hash — e.g. requested scopes, jurisdictions). One-question test: exists outside this record? → evidence (hash it); computed/passed as an argument? → parameters. At least one is required (or evidence_omitted_reason). Optionally include agent_context — free-form execution-substrate hints (cloud_run_revision, model_name, region) so an auditor can ask 'was this at a known-buggy revision?'; asserted by you, not verified by Witness. For a human decision use seal_hitl_decision.","tags":["evidence","agent","governance","audit"],"examples":["{\"request\":{\"actor\":{\"id\":\"c2md-classifier\",\"type\":\"agent\"},\"action\":{\"statement\":\"Classified the agent as high-risk under EU AI Act Annex III.\",\"outcome\":\"high_risk\"},\"governing_rule\":{\"ref\":\"eu-ai-act#annex-III\",\"text\":\"…\"},\"evidence\":[{\"ref\":\"witness://record/rec_…\",\"hash\":\"sha256:…\",\"description\":\"whoami resolution for the requesting credential\"}],\"parameters\":{\"jurisdictions\":[\"EU\"],\"data_cat"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/seal/agent-action","security":[{"witnessApiKey":[]}]},{"id":"seal_attestation","name":"Seal an attestation","description":"Seals an assertion that a fact or state held AS OF a point in time — a model passed an evaluation, a card was issued, a key was rotated, a config was live. Not for decisions (use the decision skills). Captures the asserting party, the claim, and the as-of time; supporting external references (evidence) are optional but strengthen it. Cite the framework via governing_basis, or it is sealed as attested-by-the-signing-party, not independently verified by Witness.","tags":["attestation","ed25519","audit"],"examples":["{\"request\":{\"actor\":{\"id\":\"c2md-issuer\",\"type\":\"system\"},\"claim\":\"Issued agent card did:web:example#key-3 to tenant acct_…\",\"as_of\":\"2026-07-15T10:00:00Z\"},\"response\":{\"record\":{\"decision\":{\"inputs\":{\"record_type\":\"attestation\",\"…\":\"claim + as_of\"}},\"verdict\":\"ATTESTED\",\"…\":\"proof\"},\"bodyHash\":\"sha256:…\",\"stored\":true}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/seal/attestation","security":[{"witnessApiKey":[]}]},{"id":"issue_admission_credential","name":"Issue an admission credential","description":"Issue an agent admission credential — a sealed attestation admitting an agent (subject_did) to a customer environment with a scope, valid until expiry. The Witness record IS the credential (no separate document): enforcers hold only the credential id and check it via check_valid (Contract B); it is revocable via revoke_admission_credential. Sealed by the issuer's Witness account — only that account can revoke. subject_did / environment_id / scope / compliance_mappings are ASSERTED, not authenticated by Witness (the admission workflow establishes them; Witness records the claim). Records are immutable — validity is computed at verify time, never mutated. HOLDER-BINDING: the credential id is a bearer handle — issuing it does not bind the holder; the ENFORCER must separately prove the presenter controls subject_did (see check_valid). PROVISIONAL is representable honestly: sandbox_result.pass may be false and score null ('not run'), and evidence_seal_ref may point at an honest stub — a credential can truthfully record a conditional / not-yet-passed admission rather than forcing a passing claim.","tags":["credential","admission","attestation","ed25519"],"examples":["{\"request\":{\"subject_did\":\"did:web:agent.example.com\",\"issuer_did\":\"did:web:onboard.getvda.ai\",\"environment_id\":\"env_citizenm_prod\",\"scope\":[\"reservation.read\",\"folio.settle\"],\"governance_files_hash\":\"sha256:…\",\"sandbox_result\":{\"pass\":true,\"score\":0.97,\"evidence_seal_ref\":\"rec_…\"},\"impact_delta_ref\":\"rec_…\",\"expires_at\":\"2027-07-16T00:00:00Z\",\"compliance_mappings\":[{\"framework\":\"eu_ai_act\",\"artic"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/credentials/issue","security":[{"witnessApiKey":[]}]},{"id":"check_valid","name":"Check a credential's validity","description":"CONTRACT B — the public credential-verification endpoint. Is this admission credential currently valid? PUBLIC, no key: input is a credential_id; anyone holding one can verify it, which is what makes issuer-issued credentials verifiable-by-anyone (their whole value). Witness returns the single canonical verdict — issued ∧ signature verifies ∧ not revoked by the issuer ∧ not expired — so every enforcer is identically correct and the meaning of 'valid' evolves in ONE place, never drifting across independent implementations (the reason this is a skill and not a two-call recipe). Response {valid, code, subject, issuer, environment, scope, expires_at, revoked, revoked_at?, reason_code?, issuer_verified, issuer_verification}; code is 'valid' | 'revoked' | 'expired' | 'not_found' | 'not_credential'. PUBLIC — no key (a credential id is not a secret; CRL/OCSP posture). Cache-Control: private, max-age=60. issuer_verified is a DISTINCT signal from the lifecycle verdict — issuer-authenticity: 'verified' (customer-managed record signed by a key published in issuer_did's DID document — provable even against Witness), 'key_not_in_did_doc' (LOUD: claims an issuer but signed by a key not in its DID — suspicious), 'custodial' (Witness-signed; issuer-authenticity not established, only integrity/anchoring), or 'did_unresolvable' (the check did not complete; not verified AND not forged). Set your own bar: a high-stakes environment may require issuer_verified:true; a low-stakes one may accept custodial. TWO enforcer disciplines the schema teaches: (1) a credential id is a BEARER handle — a valid credential is necessary, NOT sufficient; you MUST separately challenge the presenter to prove control of `subject` (a DID challenge), because validity is not proof the presenter is the subject. (2) Record each check_valid response in YOUR OWN audit log (timestamp, credential_id, response) — Witness's cache and logs tell you what was returned, but only your local record proves what YOU acted on and when, when a regulator later asks how you knew the credential was valid at time T.","tags":["credential","verification","revocation","enforcement"],"examples":["{\"request\":{\"credential_id\":\"rec_…\"},\"response\":{\"valid\":true,\"code\":\"valid\",\"subject\":\"did:web:agent.example.com\",\"issuer\":\"did:web:onboard.getvda.ai\",\"environment\":\"env_citizenm_prod\",\"scope\":[\"reservation.read\"],\"expires_at\":\"2027-07-16T00:00:00Z\",\"revoked\":false}}","{\"request\":{\"credential_id\":\"rec_revoked\"},\"response\":{\"valid\":false,\"code\":\"revoked\",\"subject\":\"did:web:agent.example.com\",\"environment\":\"env_citizenm_prod\",\"revoked\":true,\"revoked_at\":\"…\",\"reason_code\":\"compromised\"}}","{\"request\":{\"credential_id\":\"typo\"},\"response\":{\"valid\":false,\"code\":\"not_found\",\"revoked\":false}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"GET https://witness.getvda.ai/api/witness/credentials/{credential_id}","security":[]},{"id":"verify_record_issuer","name":"Verify a record's issuer-authenticity (verdict only)","description":"Is a record's signature by the issuer it claims? PUBLIC, no key. Input is a record_id; the answer is a VERDICT plus the issuer DID and the public key it resolved against — NEVER the record body, decision.inputs, or evidence. General records (attestations, agent_actions) are account-private; this is the ONLY thing about them that is publicly checkable, and the surface is exactly as wide as the question. This is how an enforcer of a privilege-widening event — e.g. a service sealing a genesis authority registration or a baseline promotion ABOUT ITSELF, customer-managed — confirms the issuer signed it, not merely that Witness recorded it, without holding the account's key or seeing the record. Response {record_id, signature_valid, issuer_verified, issuer_verification, issuer_did, signer_key}. Same four states as check_valid's issuer_verified: 'verified' (signing key IS published in the claimed issuer's did:web) | 'key_not_in_did_doc' (LOUD — signed by a key NOT in that DID; suspicious) | 'custodial' (Witness's own key signed it — issuer-authenticity is not the applicable question, a different custody model, not a failure) | 'did_unresolvable' (issuer DID unreachable — the check did NOT complete; treat as neither verified nor forged). The issuer DID is taken from the credential's issuer_did or, for a general record, from the signer's did:web keyId. Cache-Control: public, max-age=60 (no-store while did_unresolvable). ids are unguessable UUIDs; unknown → not_found.","tags":["verification","issuer-authenticity","enforcement","custody"],"examples":["{\"request\":{\"record_id\":\"rec_genesis\"},\"response\":{\"record_id\":\"rec_genesis\",\"signature_valid\":true,\"issuer_verified\":true,\"issuer_verification\":\"verified\",\"issuer_did\":\"did:web:hitl.getvda.ai\",\"signer_key\":{\"kty\":\"OKP\",\"crv\":\"Ed25519\",\"x\":\"…\"}}}","{\"request\":{\"record_id\":\"rec_custodial\"},\"response\":{\"record_id\":\"rec_custodial\",\"signature_valid\":true,\"issuer_verified\":null,\"issuer_verification\":\"custodial\",\"issuer_did\":null,\"signer_key\":null}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"GET https://witness.getvda.ai/api/witness/records/{record_id}/issuer","security":[]},{"id":"revoke_admission_credential","name":"Revoke an admission credential","description":"Revoke an admission credential your account issued. Only the issuing account may revoke (enforced structurally by comparing sealing accounts, not a DID string). Terminal — re-admission is a NEW credential. Produces a new immutable revocation attestation that supersedes the credential; verify_admission_credential reflects it within the ~60s cache window. Customers who want a credential revoked call the issuing service (onboard.getvda.ai), which owns revocation policy and executes here — customers do not call Witness directly.","tags":["credential","revocation","attestation"],"examples":["{\"request\":{\"credential_id\":\"rec_…\",\"reason_code\":\"compromised\",\"revoked_by\":\"did:web:onboard.getvda.ai\",\"reason_text\":\"Subject key rotation detected out-of-band.\"},\"response\":{\"revoked_credential_id\":\"rec_…\",\"revocation_id\":\"rec_…\",\"record\":{\"decision\":{\"inputs\":{\"attestation_type\":\"admission_revocation\",\"supersedes\":\"rec_…\"}}}}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/credentials/{credential_id}/revoke","security":[{"witnessApiKey":[]}]},{"id":"revoke_api_key","name":"Revoke an account API key (sealed as an event)","description":"Revoke one of your account's API keys — the key stops authenticating at once, and the revocation is itself sealed as a key_revocation attestation on your chain. TWO authorities: (1) CONTROLLER-AUTHORIZED, owner self-service, no operator — prepare a key_revocation via /prepare {skill:'revoke_api_key', params:{key_id, revoked_by:{type:'controller'}, reason_code}}, sign the canonical bytes with your BOUND CONTROLLER key, and POST { record } here. Witness verifies the signer IS your bound controller and that the key is yours; the record is customer-managed (owner-signed) so the revocation is provable AGAINST Witness, not merely asserted by it. (2) ADMIN break-glass (operator, x-witness-admin, { key_id }) — sealed custodially, revoked_by.type='operator'; the record honestly shows Witness asserted it. revoked_by.type is the trust distinction, not a code path. Revocation is TOTAL: a revoked key 401s at auth AND its account's records become unfetchable with it — there is NO operator backdoor to read a revoked account's records. Reflected in whoami: a revoked key 401s immediately (no-store); a sibling's ≤60s cached 200 is the only propagation lag.","tags":["revocation","key-management","custody","security"],"examples":["{\"request\":{\"record\":{\"decision\":{\"inputs\":{\"attestation_type\":\"key_revocation\",\"revoked_key_id\":\"<keyId>\",\"revoked_by\":{\"type\":\"controller\"},\"reason_code\":\"exposed\"}},\"signer\":{\"custody\":\"customer-managed\"},\"proof\":{\"algorithm\":\"Ed25519\",\"signature\":\"…\"}}},\"response\":{\"revoked\":true,\"key_id\":\"<keyId>\",\"revoked_by\":{\"type\":\"controller\"}}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/keys/revoke","security":[{"witnessApiKey":[]}]},{"id":"whoami","name":"Resolve a Witness key — cross-service auth (Contract A)","description":"The SANCTIONED cross-service authorization endpoint. A sibling getvda.ai service that accepts `Authorization: Bearer wtn.<id>.<secret>` from ITS caller validates that key by calling whoami — Witness is the sole source of truth for its own keys, so no sibling replicates the key store. Returns everything a sibling needs to authorize on IDENTITY, not just presence: account_id (WHO), tier (SEALED|ANCHORED), scopes (WHAT it may do), compliance, key_id, revoked (always false on 200), and expires_at (validity window; null = non-expiring — a revoked or expired key 401s before reaching here). A key can only ever resolve ITSELF — it cannot enumerate other accounts. Any missing/invalid key returns a uniform 401 'unknown or invalid API key' (no existence leak). Available as REST (GET) and as the MCP `whoami` tool; permissively rate-limited per IP and per account.","tags":["auth","cross-service","composition","suite"],"examples":["{\"request\":{\"headers\":{\"authorization\":\"Bearer wtn.<id>.<secret>\"}},\"response\":{\"account_id\":\"acct_<ULID>\",\"tier\":\"ANCHORED\",\"scopes\":[\"seal\",\"read\"],\"compliance\":true,\"key_id\":\"<id>\",\"revoked\":false,\"expires_at\":null}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"GET https://witness.getvda.ai/api/witness/whoami","security":[{"witnessApiKey":[]}]},{"id":"seal","name":"Seal (general-purpose / compatibility)","description":"General-purpose seal, retained for backward compatibility and for records that fit none of the shaped skills. PREFER a shaped skill so your record is auditor-reconstructable: seal_hitl_decision (a human decided), seal_agent_action (an agent acted), seal_attestation (you assert a fact/state). Records sealed here carry no record_type and report as unstructured. API key required; no key? see `provisioning.selfServeKey` or the MCP `get_test_key` tool.","tags":["evidence","ed25519","audit","compatibility"],"examples":["{\"request\":{\"decision\":{\"agent\":\"refund-bot\",\"inputs\":{\"amountEur\":150},\"verdict\":\"PASS\",\"reasoning\":\"<= 200 and account in good standing\"},\"governingRule\":{\"ruleId\":\"refund.auto\",\"ruleText\":\"Agents MAY auto-approve refunds up to EUR200.\"},\"chainKey\":\"default\",\"decisionId\":\"optional-idempotency-key\"},\"response\":{\"record\":{\"schema\":\"vda.witness.record/1\",\"account\":\"acct_<ULID>\",\"seq\":0,\"…\":\"signed "],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/seal","security":[{"witnessApiKey":[]}]},{"id":"read","name":"Read your own records","description":"Read back what you've sealed (operational query, account-scoped by your key — never an accountId param). `list_records` returns paginated summaries + the set of chainKeys in your account (discover your own chains); `get_record` returns the FULL signed body of one record. For OFFLINE verification of chain continuity with ZERO calls back to Witness, fetch a self-contained proof bundle: `GET /records/{recordId}?proof=chain` (record + full chain + anchor attestation + did.json) or `GET /chains/{chainKey}/proof` (whole trail). Feed it to `offlineVerify({record, chain, anchor, didDocument})` — verdicts: ANCHORED_VALID / SIGNED_PENDING / BROKEN / INSUFFICIENT_PROOF (the last means proof material was missing, NOT tampering). Distinct from `report` (Article-12 artefact). Foreign/unknown id → not-found (no leak).","tags":["read","query","audit-trail"],"examples":["{\"request\":{\"list_records\":{\"chainKey\":\"default\",\"limit\":50}},\"response\":{\"account\":\"acct_<ULID>\",\"chainKeys\":[\"default\",\"…\"],\"records\":[{\"recordId\":\"…\",\"chainKey\":\"default\",\"seq\":0,\"verdict\":\"PASS\",\"agent\":\"refund-bot\",\"ruleId\":\"refund.auto\",\"bodyHash\":\"sha256:…\",\"sealedAt\":\"…\",\"anchorState\":\"SIGNED_PENDING\"}],\"nextCursor\":null}}","{\"request\":{\"get_record\":{\"recordId\":\"…\"}},\"response\":{\"record\":{\"schema\":\"vda.witness.record/1\",\"decision\":{\"agent\":\"refund-bot\",\"verdict\":\"PASS\",\"reasoning\":\"…full reasoning…\",\"inputs\":{},\"actionProposed\":\"…\"},\"governingRule\":{\"ruleId\":\"refund.auto\",\"ruleText\":\"…\"},\"seq\":0,\"prevHash\":null,\"proof\":{\"signature\":\"…\"}},\"chainKey\":\"default\",\"anchorState\":\"ANCHORED_VALID\",\"anchor\":{\"head\":\"sha256:…\",\""],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"GET https://witness.getvda.ai/api/witness/records  ·  GET https://witness.getvda.ai/api/witness/records/{recordId}?proof=chain  ·  GET https://witness.getvda.ai/api/witness/chains/{chainKey}/proof","security":[{"witnessApiKey":[]}]},{"id":"provision","name":"Self-provision an account (no human)","description":"Self-issue a SEALED-tier API key in-band with no human. Pass an Ed25519 controller PUBLIC key (`controllerPublicKeyJwk`) to claim a DURABLE, self-renewable account bound to a key you hold — otherwise the account auto-expires ~7 days. Sealed tier = signed + hash-chained + independently verifiable OFFLINE, but NOT externally anchored (terminal — it stays sealed). The Anchored tier (externally committed, \"provable even against us\") is concierge-provisioned separately. Then `renew` re-keys the same account forever. See also `provisioning.selfServeKey`.","tags":["provisioning","self-serve","ed25519"],"examples":["{\"request\":{\"controllerPublicKeyJwk\":{\"kty\":\"OKP\",\"crv\":\"Ed25519\",\"x\":\"<base64url>\"}},\"response\":{\"apiKey\":\"wtn.<id>.<secret>\",\"accountId\":\"acct_<ULID>\",\"tier\":\"test\",\"compliance\":false,\"durable\":true,\"controllerBound\":true,\"keyExpiresAt\":\"2026-…Z\",\"keyTtlSec\":86400}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/test-key","security":[]},{"id":"renew","name":"Renew a key (agent-provable, no human)","description":"Get a fresh short-TTL API key for an account you ALREADY control — indefinitely, with no human and no permanent secret. Two steps: POST /renew/challenge {accountId} → nonce; Ed25519-sign `vda.witness.renew/1|<accountId>|<nonce>` with your controller key; POST /renew {accountId, nonce, signature} → fresh key bound to the SAME account (chains continue, prev-hash unbroken). Bind the controller key at creation via `provisioning.selfServeKey.controllerPublicKeyJwk`.","tags":["credential","renewal","ed25519","self-serve"],"examples":["{\"request\":{\"accountId\":\"acct_<ULID>\",\"nonce\":\"<from /renew/challenge>\",\"signature\":\"<base64url Ed25519 over 'vda.witness.renew/1|<accountId>|<nonce>'>\"},\"response\":{\"apiKey\":\"wtn.<id>.<secret>\",\"accountId\":\"acct_<ULID>\",\"keyExpiresAt\":\"2026-07-13T00:00:00Z\",\"keyTtlSec\":86400}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/renew","security":[]},{"id":"verify","name":"Verify a record","description":"Independently verify a record or chain (Ed25519 signature + hash-chain). No auth.","tags":["verification","tamper-evidence"],"examples":["{\"request\":{\"record\":{\"schema\":\"vda.witness.record/1\",\"…\":\"a full witness record incl. proof\"}},\"response\":{\"ok\":true,\"bodyHash\":\"sha256:…\",\"signatureValid\":true,\"errors\":[]}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/verify","security":[]},{"id":"report","name":"Article 12 Evidence Report","description":"Generate an EU AI Act Article 12 evidence report from the sealed trail (API key required).","tags":["eu-ai-act","art-12","evidence"],"examples":["{\"request\":{},\"response\":{\"reportType\":\"vda.witness.art12-evidence/1\",\"lifecycle\":\"DEMO_DATA\",\"generatedAt\":\"…\",\"entries\":[\"… one entry per sealed decision, each traceable to a signed record\"]}}"],"inputModes":["application/json"],"outputModes":["application/json"],"endpoint":"POST https://witness.getvda.ai/api/witness/report","security":[{"witnessApiKey":[]}]}],"provenance":[{"source":"manifests","first_seen":"2026-08-18T02:23:00.832236+00:00"}],"recent_probes":[{"fetched_at":"2026-08-19T11:28:23.252883+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":69,"live_responds":null},{"fetched_at":"2026-08-18T20:35:07.150485+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":48,"live_responds":null},{"fetched_at":"2026-08-18T09:51:53.671153+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":52,"live_responds":null},{"fetched_at":"2026-08-18T02:23:00.832236+00:00","ok":true,"status_code":200,"error":null,"elapsed_ms":48,"live_responds":null}],"catalog_attestation":null,"operator_revenue_evidence":{"evidence_class":"operator_submitted","authenticity":{"rung":"no_operator_evidence","rank":0,"why":"No verifiable operator evidence has been submitted for this agent.","thresholds":{"min_independent_payers":3,"min_verified_usd":25.0},"engine_table":"agent_authenticity","merge_rule":"max(existing_rank, rank)"},"metric_metadata":{"provenance":"operator_submitted_evidence","confidence":"attested","coverage":{"numerator":0},"as_of":"2026-08-19T19:08:40.469163+00:00","definition":"Revenue proofs submitted by the verified owner and re-checked by Agenstry against the settlement chain or the operator's own Stripe account. Only independently confirmed proofs are counted."},"counts":{"retained":0,"verified":0,"unverifiable":0},"verified":{"gross_usd":0.0,"transactions":0,"independent_payers":0},"detail_url":"https://agenstry.com/api/agents/witness.getvda.ai/evidence","dispute_url":"https://agenstry.com/agents/witness.getvda.ai/dispute"},"verification_history":[]}