{"agent_host":"desk.agent-desk.us","generated_at":"2026-09-20T04:20:04.384668+00:00","environment":"production","verified":true,"decision":"PASS","gates":[{"gate":1,"title":"Reachable agent endpoint (A2A + MCP)","status":"PASS","detail":"A2A: card valid; MCP: initialize + tools/list succeeded","evidence":{"agent_card":"https://desk.agent-desk.us/.well-known/agent-card.json","card_sha256":"58f435023ad321aa26a9b68d2665ea66b5b1e7940396babb2e13aeb467ec77aa","skills":["find_agent","verify_agent","about_agent_desk"],"mcp_url":"https://desk.agent-desk.us/mcp","mcp_tools":["find_agent","verify_agent","about_agent_desk"]}},{"gate":2,"title":"Public HTTPS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","evidence":{"tls_version":"TLSv1.3","leaf_sha256":"ab85ee13b3382d547f4ca658e35ef36564427d4d1374ece5d396af3948c56264","issuer":"CN=YE1,O=Let's Encrypt,C=US","not_after":"2026-12-19T00:24:38+00:00"}},{"gate":3,"title":"Owned MLH domain","status":"PASS","detail":"host is under BASE_DOMAIN, serves valid public TLS, and ANS validated control of its DNS (ACME DNS-01)","evidence":{"base_domain":"agent-desk.us","agent_host":"desk.agent-desk.us"}},{"gate":4,"title":"Production ANS registration ACTIVE","status":"PASS","detail":"GoDaddy production ANS reports ACTIVE (live lookup)","evidence":{"agent_id":"284ab9b7-6ed4-422c-bfae-66e07932cb28","ans_name":"ans://v1.0.0.desk.agent-desk.us","ans_status":"ACTIVE","environment":"production","checked_at":"2026-09-20T04:20:02.193636+00:00"}},{"gate":5,"title":"Verification evidence","status":"PASS","detail":"all mandatory checks passed","evidence":{"checks_passed":15,"checks_total":15,"identity_sha256":"b4a95f468d52d4d0f1e53a4e148336d8e0f72dd9c8942264ea95bf19bfcef92e"}}],"verification":{"agent_host":"desk.agent-desk.us","generated_at":"2026-09-20T04:20:04.384668Z","ans":{"agent_id":"284ab9b7-6ed4-422c-bfae-66e07932cb28","ans_name":"ans://v1.0.0.desk.agent-desk.us","status":"ACTIVE","environment":"production","declared_endpoints":[{"protocol":"A2A","url":"https://desk.agent-desk.us/a2a","transports":["JSON-RPC"],"metadata_url":"https://desk.agent-desk.us/.well-known/agent-card.json"},{"protocol":"MCP","url":"https://desk.agent-desk.us/mcp","transports":["STREAMABLE-HTTP"],"metadata_url":"https://desk.agent-desk.us/.well-known/mcp.json"}],"checked_at":"2026-09-20T04:20:02.193636Z","source":"GoDaddy ANS public discovery API (live)"},"endpoint_checks":[{"protocol":"A2A","url":"https://desk.agent-desk.us/a2a","status":"PASS","detail":"card valid"},{"protocol":"MCP","url":"https://desk.agent-desk.us/mcp","status":"PASS","detail":"initialize + tools/list succeeded"}],"identity_certificate":{"issuer":"CN=GoDaddy Private ANS Issuing CA - PR1v1,O=GoDaddy.com,C=US","subject":"CN=desk.agent-desk.us","san":["DNS:desk.agent-desk.us","URI:ans://v1.0.0.desk.agent-desk.us"],"serial":"1A0BC869A7400FF662861CFECFDE6000197","sha256":"b4a95f468d52d4d0f1e53a4e148336d8e0f72dd9c8942264ea95bf19bfcef92e","valid_from":"2026-09-20T01:55:33Z","valid_to":"2027-09-20T01:55:33Z","chain_status":"PASS","chain_reason":"chain verifies to the provisioned ANS trust anchor","binding_status":"PASS","binding_reason":"validity window, host and ANS name binding verified; fingerprint matches the transparency-log attestation"},"tls":{"status":"PASS","detail":"hostname and chain verified against the public WebPKI","version":"TLSv1.3","cipher":"TLS_AES_128_GCM_SHA256","hostname_verified":true,"leaf_sha256":"ab85ee13b3382d547f4ca658e35ef36564427d4d1374ece5d396af3948c56264","issuer":"CN=YE1,O=Let's Encrypt,C=US","subject":"CN=desk.agent-desk.us","san":["DNS:desk.agent-desk.us"],"not_after":"2026-12-19T00:24:38Z"},"a2a":{"status":"PASS","detail":"card valid","card_url":"https://desk.agent-desk.us/.well-known/agent-card.json","card_valid":true,"card_sha256":"58f435023ad321aa26a9b68d2665ea66b5b1e7940396babb2e13aeb467ec77aa","name":"Agent Desk","version":"1.0.0","protocol_versions":["1.0"],"skills":["find_agent","verify_agent","about_agent_desk"],"rpc_url":"https://desk.agent-desk.us/a2a","signed":true,"drift":false},"mcp":{"status":"PASS","detail":"initialize + tools/list succeeded","url":"https://desk.agent-desk.us/mcp","handshake":true,"protocol_version":"2025-03-26","server_name":"agent-desk","tools":["find_agent","verify_agent","about_agent_desk"],"probe_tool":"about_agent_desk","probe_ok":true},"checks":[{"id":"ans_status_active","label":"ANS lifecycle is ACTIVE (live)","status":"PASS","detail":"registry reports ACTIVE","mandatory":true,"evidence":{"agent_id":"284ab9b7-6ed4-422c-bfae-66e07932cb28","ans_name":"ans://v1.0.0.desk.agent-desk.us"}},{"id":"canonical_agent_host","label":"Canonical agent host","status":"PASS","detail":"registry agentHost and ANS name match the requested host","mandatory":true,"evidence":{"expected":"desk.agent-desk.us","observed":"desk.agent-desk.us"}},{"id":"supported_protocol","label":"Supports A2A or MCP","status":"PASS","detail":"A2A, MCP","mandatory":true,"evidence":{}},{"id":"endpoints_https","label":"Endpoints are HTTPS with valid TLS","status":"PASS","detail":"hostname and chain verified against the public WebPKI","mandatory":true,"evidence":{"tls_version":"TLSv1.3","leaf_sha256":"ab85ee13b3382d547f4ca658e35ef36564427d4d1374ece5d396af3948c56264"}},{"id":"endpoint_host_binding","label":"Endpoints are on the registered host","status":"PASS","detail":"every endpoint/metadata URL is on the registered agentHost","mandatory":true,"evidence":{}},{"id":"endpoint_network_policy","label":"Endpoints pass outbound network policy","status":"PASS","detail":"https/443, public DNS name, every resolved address globally routable","mandatory":true,"evidence":{}},{"id":"ans_record_consistency","label":"Registry detail and transparency log agree","status":"PASS","detail":"search hit, agent detail and transparency-log badge are consistent","mandatory":true,"evidence":{"badge_status":"ACTIVE"}},{"id":"identity_certificate_retrieved","label":"Identity certificate retrieved from ANS","status":"PASS","detail":"retrieved from the official certificate-management API","mandatory":false,"evidence":{"sha256":"b4a95f468d52d4d0f1e53a4e148336d8e0f72dd9c8942264ea95bf19bfcef92e"}},{"id":"identity_certificate_binding","label":"Identity certificate validity and binding","status":"PASS","detail":"validity window, host and ANS name binding verified; fingerprint matches the transparency-log attestation","mandatory":false,"evidence":{}},{"id":"identity_chain_trust_anchor","label":"Identity certificate chains to the ANS trust anchor","status":"PASS","detail":"chain verifies to the provisioned ANS trust anchor","mandatory":false,"evidence":{}},{"id":"metadata_fetch","label":"Protocol metadata fetched within limits","status":"PASS","detail":"fetched with time/size/content-type limits","mandatory":true,"evidence":{}},{"id":"metadata_schema","label":"Metadata parses and matches the registration","status":"PASS","detail":"parsed as data; interface matches the registration","mandatory":true,"evidence":{}},{"id":"metadata_integrity","label":"Metadata signature / hash","status":"PASS","detail":"card is signed by the key in the ANS-issued identity certificate","mandatory":false,"evidence":{"identity_sha256":"b4a95f468d52d4d0f1e53a4e148336d8e0f72dd9c8942264ea95bf19bfcef92e"}},{"id":"card_hash_drift","label":"Agent Card hash is stable (drift watch)","status":"PASS","detail":"matches the last verified hash","mandatory":true,"evidence":{"card_sha256":"58f435023ad321aa26a9b68d2665ea66b5b1e7940396babb2e13aeb467ec77aa"}},{"id":"local_blocklist","label":"Not on the local blocklist","status":"PASS","detail":"no local block","mandatory":true,"evidence":{}}],"verified":true,"decision":"PASS","reasons":[]},"notes":["Statuses are derived from live checks only; INCOMPLETE means 'could not be proven', never 'assumed fine'.","An ANS identity identifies an agent; it does not make the agent's output trusted."],"cached":false}