{"agent_host":"demo.agent-desk.us","generated_at":"2026-09-20T03:09:12.551710+00:00","environment":"production","verified":true,"decision":"PASS","gates":[{"gate":1,"title":"Reachable agent endpoint (A2A + MCP)","status":"PASS","detail":"A2A: card valid; MCP: initialize + tools/list succeeded","evidence":{"agent_card":"https://demo.agent-desk.us/.well-known/agent-card.json","card_sha256":"4b781ead45b87848844c0ee5cd32cd3d883bd2b6919a9831556196b302b44018","skills":["get_business_info","get_hours","get_menu_or_services"],"mcp_url":"https://demo.agent-desk.us/mcp","mcp_tools":["get_business_info","get_hours","get_menu_or_services"]}},{"gate":2,"title":"Public HTTPS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","evidence":{"tls_version":"TLSv1.3","leaf_sha256":"f7c5974bb4f4a34db4f7a8fdf827fd245ef6a081983630935a249ad0ae207db8","issuer":"CN=YE1,O=Let's Encrypt,C=US","not_after":"2026-12-19T00:24:37+00:00"}},{"gate":3,"title":"Owned MLH domain","status":"PASS","detail":"host is under BASE_DOMAIN, serves valid public TLS, and ANS validated control of its DNS (ACME DNS-01)","evidence":{"base_domain":"agent-desk.us","agent_host":"demo.agent-desk.us"}},{"gate":4,"title":"Production ANS registration ACTIVE","status":"PASS","detail":"GoDaddy production ANS reports ACTIVE (live lookup)","evidence":{"agent_id":"afc8a8dd-b268-4484-b892-8660646ef815","ans_name":"ans://v1.0.0.demo.agent-desk.us","ans_status":"ACTIVE","environment":"production","checked_at":"2026-09-20T03:09:11.635368+00:00"}},{"gate":5,"title":"Verification evidence","status":"PASS","detail":"all mandatory checks passed","evidence":{"checks_passed":11,"checks_total":15}}],"verification":{"agent_host":"demo.agent-desk.us","generated_at":"2026-09-20T03:09:12.551710Z","ans":{"agent_id":"afc8a8dd-b268-4484-b892-8660646ef815","ans_name":"ans://v1.0.0.demo.agent-desk.us","status":"ACTIVE","environment":"production","declared_endpoints":[{"protocol":"A2A","url":"https://demo.agent-desk.us/a2a","transports":["JSON-RPC"],"metadata_url":"https://demo.agent-desk.us/.well-known/agent-card.json"},{"protocol":"MCP","url":"https://demo.agent-desk.us/mcp","transports":["STREAMABLE-HTTP"],"metadata_url":"https://demo.agent-desk.us/.well-known/mcp.json"}],"checked_at":"2026-09-20T03:09:11.635368Z","source":"GoDaddy ANS public discovery API (live)"},"endpoint_checks":[{"protocol":"A2A","url":"https://demo.agent-desk.us/a2a","status":"PASS","detail":"card valid"},{"protocol":"MCP","url":"https://demo.agent-desk.us/mcp","status":"PASS","detail":"initialize + tools/list succeeded"}],"identity_certificate":null,"tls":{"status":"PASS","detail":"hostname and chain verified against the public WebPKI","version":"TLSv1.3","cipher":"TLS_AES_128_GCM_SHA256","hostname_verified":true,"leaf_sha256":"f7c5974bb4f4a34db4f7a8fdf827fd245ef6a081983630935a249ad0ae207db8","issuer":"CN=YE1,O=Let's Encrypt,C=US","subject":"CN=demo.agent-desk.us","san":["DNS:demo.agent-desk.us"],"not_after":"2026-12-19T00:24:37Z"},"a2a":{"status":"PASS","detail":"card valid","card_url":"https://demo.agent-desk.us/.well-known/agent-card.json","card_valid":true,"card_sha256":"4b781ead45b87848844c0ee5cd32cd3d883bd2b6919a9831556196b302b44018","name":"Hokie Bean Cafe (demo)","version":"1.0.0","protocol_versions":["1.0"],"skills":["get_business_info","get_hours","get_menu_or_services"],"rpc_url":"https://demo.agent-desk.us/a2a","signed":false,"drift":false},"mcp":{"status":"PASS","detail":"initialize + tools/list succeeded","url":"https://demo.agent-desk.us/mcp","handshake":true,"protocol_version":"2025-03-26","server_name":"agent-desk-business-agent","tools":["get_business_info","get_hours","get_menu_or_services"],"probe_tool":"get_hours","probe_ok":true},"checks":[{"id":"ans_status_active","label":"ANS lifecycle is ACTIVE (live)","status":"PASS","detail":"registry reports ACTIVE","mandatory":true,"evidence":{"agent_id":"afc8a8dd-b268-4484-b892-8660646ef815","ans_name":"ans://v1.0.0.demo.agent-desk.us"}},{"id":"canonical_agent_host","label":"Canonical agent host","status":"PASS","detail":"registry agentHost and ANS name match the requested host","mandatory":true,"evidence":{"expected":"demo.agent-desk.us","observed":"demo.agent-desk.us"}},{"id":"supported_protocol","label":"Supports A2A or MCP","status":"PASS","detail":"A2A, MCP","mandatory":true,"evidence":{}},{"id":"endpoints_https","label":"Endpoints are HTTPS with valid TLS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","mandatory":true,"evidence":{"tls_version":"TLSv1.3","leaf_sha256":"f7c5974bb4f4a34db4f7a8fdf827fd245ef6a081983630935a249ad0ae207db8"}},{"id":"endpoint_host_binding","label":"Endpoints are on the registered host","status":"PASS","detail":"every endpoint/metadata URL is on the registered agentHost","mandatory":true,"evidence":{}},{"id":"endpoint_network_policy","label":"Endpoints pass outbound network policy","status":"PASS","detail":"https/443, public DNS name, every resolved address globally routable","mandatory":true,"evidence":{}},{"id":"ans_record_consistency","label":"Registry detail and transparency log agree","status":"PASS","detail":"search hit, agent detail and transparency-log badge are consistent","mandatory":true,"evidence":{"badge_status":"ACTIVE"}},{"id":"identity_certificate_retrieved","label":"Identity certificate retrieved from ANS","status":"INCOMPLETE","detail":"no ANS credential configured: the certificate API is authenticated","mandatory":false,"evidence":{}},{"id":"identity_certificate_binding","label":"Identity certificate validity and binding","status":"INCOMPLETE","detail":"no ANS credential configured: the certificate API is authenticated","mandatory":false,"evidence":{}},{"id":"identity_chain_trust_anchor","label":"Identity certificate chains to the ANS trust anchor","status":"INCOMPLETE","detail":"no ANS credential configured: the certificate API is authenticated","mandatory":false,"evidence":{}},{"id":"metadata_fetch","label":"Protocol metadata fetched within limits","status":"PASS","detail":"fetched with time/size/content-type limits","mandatory":true,"evidence":{}},{"id":"metadata_schema","label":"Metadata parses and matches the registration","status":"PASS","detail":"parsed as data; interface matches the registration","mandatory":true,"evidence":{}},{"id":"metadata_integrity","label":"Metadata signature / hash","status":"INCOMPLETE","detail":"neither ANS nor the card provides a hash/signature to verify","mandatory":false,"evidence":{}},{"id":"card_hash_drift","label":"Agent Card hash is stable (drift watch)","status":"PASS","detail":"matches the last verified hash","mandatory":true,"evidence":{"card_sha256":"4b781ead45b87848844c0ee5cd32cd3d883bd2b6919a9831556196b302b44018"}},{"id":"local_blocklist","label":"Not on the local blocklist","status":"PASS","detail":"no local block","mandatory":true,"evidence":{}}],"verified":true,"decision":"PASS","reasons":["INCOMPLETE: Identity certificate retrieved from ANS — no ANS credential configured: the certificate API is authenticated","INCOMPLETE: Identity certificate validity and binding — no ANS credential configured: the certificate API is authenticated","INCOMPLETE: Identity certificate chains to the ANS trust anchor — no ANS credential configured: the certificate API is authenticated","INCOMPLETE: Metadata signature / hash — neither ANS nor the card provides a hash/signature to verify"]},"notes":["Statuses are derived from live checks only; INCOMPLETE means 'could not be proven', never 'assumed fine'.","An ANS identity identifies an agent; it does not make the agent's output trusted."],"cached":false}