| PASS | ANS lifecycle is ACTIVE (live) | registry reports ACTIVE |
| PASS | Canonical agent host | registry agentHost and ANS name match the requested host |
| PASS | Supports A2A or MCP | A2A, MCP |
| PASS | Endpoints are HTTPS with valid TLS | hostname and chain verified against the public WebPKI |
| PASS | Endpoints are on the registered host | every endpoint/metadata URL is on the registered agentHost |
| PASS | Endpoints pass outbound network policy | https/443, public DNS name, every resolved address globally routable |
| PASS | Registry detail and transparency log agree | search hit, agent detail and transparency-log badge are consistent |
| INCOMPLETE | Identity certificate retrieved from ANS (optional) | no ANS credential configured: the certificate API is authenticated |
| INCOMPLETE | Identity certificate validity and binding (optional) | no ANS credential configured: the certificate API is authenticated |
| INCOMPLETE | Identity certificate chains to the ANS trust anchor (optional) | no ANS credential configured: the certificate API is authenticated |
| PASS | Protocol metadata fetched within limits | fetched with time/size/content-type limits |
| PASS | Metadata parses and matches the registration | parsed as data; interface matches the registration |
| INCOMPLETE | Metadata signature / hash (optional) | neither ANS nor the card provides a hash/signature to verify |
| PASS | Agent Card hash is stable (drift watch) | matches the last verified hash |
| PASS | Not on the local blocklist | no local block |