Server definition
- Hash
- sha256:0c59d90259a2fc4073f81d4dd3bd556df98d36358f47bdf18c7d23ae1a681f1d
- What it is
- What a remote MCP server returned when asked what it offers: 15 tools
The blob, as servednamed by its sha256
{
"instructions": "Mnemom is the trust plane for the agentic internet. Live, cryptographic trust signals for AI agents and the sites they act on; everything here is signed and independently verifiable against our public keys, and nothing is fabricated.\n\nNew here? Call get_started (zero-auth, no args) for the surface map and auth guide. Two things you can do right now, no account: scan_trust(url) grades any website's agent-trust-readiness (signed scorecard + shareable permalink), and get_reputation(agent_id) / verify_reputation return any registered agent's signed, public Trust Rating. (An agent's risk history is authenticated — get_risk_history needs a Bearer/API-key credential.)\n\nAuthenticate (Bearer JWT or X-Mnemom-Api-Key) to claim and manage your own agents — alignment cards, protection posture, and a verifiable Trust Rating that travels.\n\nWe deliberately keep integrity- and alignment-internal detail owner-private; the public, signed proof rides in get_reputation.integrity_ratio. Read-only canonical surfaces (the open rubric, value catalog, /for-agents manifesto, signed cards, llms.txt) are exposed as MCP resources.\n\nVerify, don't trust — two DISTINCT paths, don't conflate them. verify_scan does in-band Ed25519 signature verification of a website scorecard against mnemom://iitr/jwks (a verified:true/false verdict + tamper detection). verify_reputation returns a Merkle-root + hash-chain attestation that the rating derives from an unbroken, append-only checkpoint chain (hash_chain_valid), plus a pointer to a signed integrity certificate — a chain-integrity attestation, NOT an in-band signature check. Public keys at mnemom://jwks and mnemom://iitr/jwks.",
"tools": [
{
"description": "Claim a verifiable identity — bind an agent to your organization so its trust and accountability record is provably yours. Requires the agent's possession proof (`hash_proof`). Re-claiming an agent you already own keeps its original claim date but files it under the organization you pass (`org_id`; if omitted, your personal organization), which can change the organization that owns and bills it.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Agent identifier (e.g. smolt-abc123)",
"type": "string"
},
"hash_proof": {
"description": "Agent possession proof — either the live birth token (`mnbt_…`) whose row pins this agent's hash, or the full 64-hex SHA-256 digest of `${apiKey}|${agentName}` (or `${apiKey}` for an unnamed singleton agent).",
"minLength": 16,
"type": "string"
},
"org_id": {
"description": "Optional. The organization to claim the agent into (e.g. `org-...` or `pers-...`). The caller must be a member of this org (role floor: member). If omitted, the agent is claimed into the caller's personal org.",
"type": "string"
}
},
"required": [
"agent_id",
"hash_proof"
],
"type": "object"
},
"name": "claim_agent",
"outputSchema": {
"properties": {
"agent_id": {
"type": "string"
},
"claimed": {
"type": "boolean"
},
"claimed_at": {
"format": "date-time",
"type": "string"
},
"org_id": {
"description": "The organization the agent was claimed into (echoes the resolved org — the supplied `org_id`, or the caller's personal org when omitted).",
"type": "string"
}
},
"required": [
"claimed",
"agent_id",
"org_id",
"claimed_at"
],
"type": "object"
}
},
{
"description": "Look up an agent's public identity and trust state by ID — the accountable record other agents and humans can rely on.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Agent identifier (e.g. smolt-abc123)",
"type": "string"
}
},
"required": [
"agent_id"
],
"type": "object"
},
"name": "get_agent",
"outputSchema": {
"additionalProperties": false,
"description": "An agent's identity and trust state, reduced to the fields the trust loop needs. Personal data (owner email address, user identifiers), internal commercial identifiers (billing account) and key-material-derived values (bound-key proof hash, key prefix) are REMOVED at the MCP boundary and are never returned to an MCP client — see the Mnemom privacy policy at https://www.mnemom.ai/privacy. Which fields are present depends on authorization: read `caller` to know which projection you received.",
"properties": {
"agent_hash": {
"description": "The canonical public identity hash (first 16 hex chars) used as the gateway lookup key and as the input to verify_agent_binding. Owner projection only. Not a credential and not reversible to one.",
"type": "string"
},
"aip_enforcement_mode": {
"enum": [
"observe",
"enforce",
"nudge"
],
"type": [
"string",
"null"
]
},
"avatar_url": {
"type": [
"string",
"null"
]
},
"caller": {
"description": "Which projection THIS response is. `org_member` receives the owner field set; `anonymous`/`authenticated` receive the reduced public set (id, name, claimed, created_at, last_seen, status, avatar_url, caller). Read this instead of inferring why a field is absent.",
"enum": [
"anonymous",
"authenticated",
"org_member"
],
"type": "string"
},
"claimed": {
"description": "Whether a human or organization has claimed accountability for this agent. On the owner projection this is derived from the ownership column; the owning user's identifier itself is not returned.",
"type": "boolean"
},
"claimed_at": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"containment_status": {
"description": "Containment state of the agent.",
"enum": [
"active",
"paused",
"killed"
],
"type": [
"string",
"null"
]
},
"created_at": {
"format": "date-time",
"type": "string"
},
"groups": {
"description": "Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows.",
"items": {
"properties": {
"color": {
"description": "Group color (hex, e.g. `#0d9488`); `null` when unset.",
"type": [
"string",
"null"
]
},
"id": {
"type": "string"
},
"name": {
"type": "string"
}
},
"required": [
"id",
"name",
"color"
],
"type": "object"
},
"type": "array"
},
"id": {
"description": "Agent identifier (e.g. smolt-abc123).",
"type": "string"
},
"last_seen": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"name": {
"description": "Agent name (2-32 chars, alphanumeric + hyphens).",
"type": [
"string",
"null"
]
},
"org_id": {
"description": "The agent's organization binding. Required as an input by the org-scoped tools (fleet listing, posture assignment). Identifies an organization, not a person.",
"type": [
"string",
"null"
]
},
"public": {
"description": "Whether the agent's identity record is publicly discoverable. Distinct from Trust Rating visibility, which is always public.",
"type": "boolean"
},
"status": {
"description": "Derived from last_seen (active = seen within the last hour).",
"enum": [
"active",
"offline"
],
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
}
},
{
"description": "Look up an AI agent's published Trust Rating — Mnemom's portable reliability signal for autonomous software, computed from the agent's own verified activity record. Returns the rating plus the technical factors behind it. Free, public, read-only: ratings are public by default, unless the agent's owner has opted out.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Agent identifier (e.g. smolt-abc123)",
"type": "string"
}
},
"required": [
"agent_id"
],
"type": "object"
},
"name": "get_reputation",
"outputSchema": {
"$defs": {
"ReputationScore": {
"description": "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000.",
"properties": {
"a2a_trust_extension": {
"description": "A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).",
"properties": {
"badge_url": {
"format": "uri",
"type": "string"
},
"confidence": {
"type": "string"
},
"extension_uri": {
"type": "string"
},
"grade": {
"type": "string"
},
"last_updated": {
"format": "date-time",
"type": "string"
},
"methodology_url": {
"format": "uri",
"type": "string"
},
"provider": {
"type": "string"
},
"score": {
"type": "number"
},
"verified_url": {
"format": "uri",
"type": "string"
}
},
"type": "object"
},
"agent_id": {
"type": "string"
},
"agent_name": {
"type": [
"string",
"null"
]
},
"checkpoint_accounting": {
"description": "Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.",
"properties": {
"analyzed": {
"description": "Checkpoints that counted toward the score (drives the X/50 eligibility gauge).",
"type": "integer"
},
"excluded": {
"properties": {
"insufficient_thinking": {
"description": "Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).",
"type": "integer"
},
"quarantined": {
"description": "Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.",
"type": "integer"
},
"synthetic": {
"description": "Synthetic (`ic-synthetic-*`) checkpoints.",
"type": "integer"
}
},
"required": [
"synthetic",
"insufficient_thinking",
"quarantined"
],
"type": "object"
},
"re_evaluated": {
"description": "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed.",
"properties": {
"corrected_clear": {
"description": "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`).",
"type": "integer"
},
"corrected_non_clear": {
"description": "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation.",
"type": "integer"
},
"resolved_no_correction": {
"description": "Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.",
"type": "integer"
}
},
"required": [
"corrected_clear",
"corrected_non_clear",
"resolved_no_correction"
],
"type": "object"
},
"total": {
"description": "All checkpoints recorded for the agent.",
"type": "integer"
}
},
"required": [
"total",
"analyzed",
"excluded"
],
"type": [
"object",
"null"
]
},
"checkpoint_count": {
"type": "integer"
},
"claimed": {
"type": "boolean"
},
"components": {
"items": {
"properties": {
"factors": {
"type": "array"
},
"key": {
"enum": [
"integrity_ratio",
"compliance",
"drift_stability",
"trace_completeness",
"coherence_compatibility"
],
"type": "string"
},
"label": {
"type": "string"
},
"score": {
"type": "number"
},
"weight": {
"type": "number"
},
"weighted_score": {
"type": "number"
}
},
"required": [
"key",
"score",
"weight",
"weighted_score"
],
"type": "object"
},
"type": "array"
},
"computed_at": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"confidence": {
"enum": [
"insufficient",
"low",
"medium",
"high"
],
"type": "string"
},
"grade": {
"description": "AAA–D or NR.",
"type": [
"string",
"null"
]
},
"is_eligible": {
"type": "boolean"
},
"next_compute_at": {
"description": "Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.",
"format": "date-time",
"type": [
"string",
"null"
]
},
"score": {
"maximum": 1000,
"minimum": 0,
"type": [
"integer",
"null"
]
},
"tier": {
"type": [
"string",
"null"
]
},
"trend_30d": {
"type": [
"number",
"null"
]
},
"visibility": {
"description": "Reputation-publication axis — whether this agent's Trust Rating is published. Every registered agent's reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word \"public\" but govern different things.",
"enum": [
"public",
"private"
],
"type": "string"
}
},
"required": [
"agent_id",
"score",
"grade",
"is_eligible",
"checkpoint_count",
"confidence",
"components",
"visibility"
],
"type": "object"
}
},
"description": "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000.",
"properties": {
"a2a_trust_extension": {
"description": "A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).",
"properties": {
"badge_url": {
"format": "uri",
"type": "string"
},
"confidence": {
"type": "string"
},
"extension_uri": {
"type": "string"
},
"grade": {
"type": "string"
},
"last_updated": {
"format": "date-time",
"type": "string"
},
"methodology_url": {
"format": "uri",
"type": "string"
},
"provider": {
"type": "string"
},
"score": {
"type": "number"
},
"verified_url": {
"format": "uri",
"type": "string"
}
},
"type": "object"
},
"agent_id": {
"type": "string"
},
"agent_name": {
"type": [
"string",
"null"
]
},
"checkpoint_accounting": {
"description": "Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.",
"properties": {
"analyzed": {
"description": "Checkpoints that counted toward the score (drives the X/50 eligibility gauge).",
"type": "integer"
},
"excluded": {
"properties": {
"insufficient_thinking": {
"description": "Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).",
"type": "integer"
},
"quarantined": {
"description": "Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.",
"type": "integer"
},
"synthetic": {
"description": "Synthetic (`ic-synthetic-*`) checkpoints.",
"type": "integer"
}
},
"required": [
"synthetic",
"insufficient_thinking",
"quarantined"
],
"type": "object"
},
"re_evaluated": {
"description": "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed.",
"properties": {
"corrected_clear": {
"description": "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`).",
"type": "integer"
},
"corrected_non_clear": {
"description": "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation.",
"type": "integer"
},
"resolved_no_correction": {
"description": "Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.",
"type": "integer"
}
},
"required": [
"corrected_clear",
"corrected_non_clear",
"resolved_no_correction"
],
"type": "object"
},
"total": {
"description": "All checkpoints recorded for the agent.",
"type": "integer"
}
},
"required": [
"total",
"analyzed",
"excluded"
],
"type": [
"object",
"null"
]
},
"checkpoint_count": {
"type": "integer"
},
"claimed": {
"type": "boolean"
},
"components": {
"items": {
"properties": {
"factors": {
"type": "array"
},
"key": {
"enum": [
"integrity_ratio",
"compliance",
"drift_stability",
"trace_completeness",
"coherence_compatibility"
],
"type": "string"
},
"label": {
"type": "string"
},
"score": {
"type": "number"
},
"weight": {
"type": "number"
},
"weighted_score": {
"type": "number"
}
},
"required": [
"key",
"score",
"weight",
"weighted_score"
],
"type": "object"
},
"type": "array"
},
"computed_at": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"confidence": {
"enum": [
"insufficient",
"low",
"medium",
"high"
],
"type": "string"
},
"grade": {
"description": "AAA–D or NR.",
"type": [
"string",
"null"
]
},
"is_eligible": {
"type": "boolean"
},
"next_compute_at": {
"description": "Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.",
"format": "date-time",
"type": [
"string",
"null"
]
},
"score": {
"maximum": 1000,
"minimum": 0,
"type": [
"integer",
"null"
]
},
"tier": {
"type": [
"string",
"null"
]
},
"trend_30d": {
"type": [
"number",
"null"
]
},
"visibility": {
"description": "Reputation-publication axis — whether this agent's Trust Rating is published. Every registered agent's reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word \"public\" but govern different things.",
"enum": [
"public",
"private"
],
"type": "string"
}
},
"required": [
"agent_id",
"score",
"grade",
"is_eligible",
"checkpoint_count",
"confidence",
"components",
"visibility"
],
"type": "object"
}
},
{
"description": "Get an embeddable Trust Rating badge for an agent — returns the badge image URL plus ready-to-paste Markdown and HTML snippets for a README or agent card.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Agent identifier (e.g. smolt-abc123)",
"type": "string"
}
},
"required": [
"agent_id"
],
"type": "object"
},
"name": "get_reputation_badge",
"outputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "The agent the badge is for (echoed from the request).",
"type": "string"
},
"badge_url": {
"description": "Canonical SVG Trust Rating badge image URL (always on api.mnemom.ai).",
"format": "uri",
"type": "string"
},
"html_embed": {
"description": "Paste-ready HTML badge snippet.",
"type": "string"
},
"markdown_embed": {
"description": "Paste-ready Markdown badge snippet.",
"type": "string"
},
"profile_url": {
"description": "Human-readable reputation profile page (on www.mnemom.ai).",
"format": "uri",
"type": "string"
},
"verified_url": {
"description": "Public cryptographic verification URL for the rating.",
"format": "uri",
"type": "string"
}
},
"required": [
"agent_id",
"badge_url",
"verified_url",
"profile_url",
"markdown_embed",
"html_embed"
],
"type": "object"
}
},
{
"description": "Zero-auth, no-args orientation: who Mnemom is, the surface map, how to authenticate and what it unlocks, and the tools to try right now (scan_trust and the reputation lookups).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"token": {
"description": "Optional Dojo try-me invite token. When supplied and valid, returns the token-gated dojo briefing manifest (the same content as GET /v1/dojo/try-me/resolve); omit for public orientation.",
"type": "string"
}
},
"type": "object"
},
"name": "get_started",
"outputSchema": {
"additionalProperties": false,
"properties": {
"authenticate": {
"additionalProperties": false,
"description": "How to authenticate and what auth unlocks.",
"properties": {
"discovery": {
"format": "uri",
"type": "string"
},
"headless": {
"additionalProperties": false,
"description": "The headless/cloud write-auth fallback (MNE-1392): when your host has no local browser and the standard OAuth redirect can't complete, drive the RFC 8628 Device Authorization Grant yourself.",
"properties": {
"discovery": {
"format": "uri",
"type": "string"
},
"grant_type": {
"type": "string"
},
"note": {
"type": "string"
},
"steps": {
"items": {
"type": "string"
},
"type": "array"
},
"use": {
"type": "string"
},
"when": {
"type": "string"
}
},
"required": [
"when",
"use",
"grant_type",
"discovery",
"steps"
],
"type": "object"
},
"methods": {
"items": {
"type": "string"
},
"type": "array"
},
"unlocks": {
"items": {
"type": "string"
},
"type": "array"
}
},
"required": [
"methods",
"unlocks",
"discovery",
"headless"
],
"type": "object"
},
"developer_path": {
"additionalProperties": false,
"description": "The developer hero on-ramp: the npx one-liner plus the intent-named MCP prompt-skills (try-me, onboard_an_agent, become_sovereign). Advertisement only — no functional dependency on those prompts existing yet.",
"properties": {
"narrative": {
"type": "string"
},
"note": {
"type": "string"
},
"npx": {
"additionalProperties": false,
"properties": {
"command": {
"type": "string"
},
"what": {
"type": "string"
}
},
"required": [
"command",
"what"
],
"type": "object"
},
"prompt_skills": {
"items": {
"additionalProperties": false,
"properties": {
"name": {
"type": "string"
},
"what": {
"type": "string"
}
},
"required": [
"name",
"what"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"narrative",
"npx",
"prompt_skills",
"note"
],
"type": "object"
},
"doctrine": {
"type": "string"
},
"showcase_agent": {
"additionalProperties": false,
"description": "A real Mnemom-owned agent the try_now reputation reads target, so the loop runs verbatim.",
"properties": {
"agent_id": {
"type": "string"
},
"why": {
"type": "string"
}
},
"required": [
"agent_id",
"why"
],
"type": "object"
},
"skill_path": {
"additionalProperties": false,
"description": "The two-step on-ramp to declaring and advertising capabilities as A2A skills in a signed, portable AgentCard.",
"properties": {
"narrative": {
"type": "string"
},
"steps": {
"items": {
"additionalProperties": false,
"properties": {
"auth": {
"enum": [
"none",
"required"
],
"type": "string"
},
"step": {
"type": "integer"
},
"tool": {
"type": "string"
},
"what": {
"type": "string"
}
},
"required": [
"step",
"tool",
"auth",
"what"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"narrative",
"steps"
],
"type": "object"
},
"sovereignty_path": {
"additionalProperties": false,
"description": "The five-step on-ramp to becoming a sovereign, accountable agent, composed from existing tools. Walked end to end by the become_sovereign MCP prompt.",
"properties": {
"narrative": {
"type": "string"
},
"prompt": {
"description": "The MCP prompt that walks this journey.",
"type": "string"
},
"steps": {
"items": {
"additionalProperties": false,
"properties": {
"auth": {
"enum": [
"none",
"required"
],
"type": "string"
},
"step": {
"type": "integer"
},
"tool": {
"type": "string"
},
"what": {
"type": "string"
}
},
"required": [
"step",
"tool",
"auth",
"what"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"narrative",
"prompt",
"steps"
],
"type": "object"
},
"surface_map": {
"additionalProperties": true,
"description": "Stable links to the canonical read-only surfaces.",
"type": "object"
},
"try_now": {
"description": "Zero-auth value tools to call right now.",
"items": {
"additionalProperties": false,
"properties": {
"args": {
"additionalProperties": true,
"type": "object"
},
"tool": {
"type": "string"
},
"what": {
"type": "string"
}
},
"required": [
"tool",
"what"
],
"type": "object"
},
"type": "array"
},
"value_prop": {
"description": "What Mnemom does for an agent.",
"type": "string"
},
"verify": {
"description": "How to verify signed artifacts in-band (verify, don't trust).",
"type": "string"
},
"visibility_model": {
"additionalProperties": false,
"description": "Disambiguates the two axes that share the word 'public': reputation-publication visibility (public by standard) vs identity-record visibility (agent.public), plus the caller-context self-description.",
"properties": {
"caller_context": {
"type": "string"
},
"identity_record_visibility": {
"type": "string"
},
"note": {
"type": "string"
},
"reputation_visibility": {
"type": "string"
}
},
"required": [
"note",
"reputation_visibility",
"identity_record_visibility",
"caller_context"
],
"type": "object"
},
"what_we_keep_private_and_why": {
"type": "string"
},
"who": {
"description": "One-line positioning.",
"type": "string"
}
},
"required": [
"who",
"value_prop",
"try_now",
"authenticate",
"skill_path",
"sovereignty_path",
"developer_path",
"surface_map",
"showcase_agent",
"visibility_model",
"what_we_keep_private_and_why",
"verify",
"doctrine"
],
"type": "object"
}
},
{
"description": "List the agents your account owns, with pagination (`limit`, `offset`). Read-only.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"limit": {
"default": 50,
"description": "How many agents to return, 1-100.",
"maximum": 100,
"minimum": 1,
"type": "integer"
},
"offset": {
"default": 0,
"description": "How many agents to skip, for pagination.",
"maximum": 100000,
"minimum": 0,
"type": "integer"
}
},
"type": "object"
},
"name": "list_agents",
"outputSchema": {
"$defs": {
"AgentMcpRecord": {
"additionalProperties": false,
"description": "An agent's identity and trust state, reduced to the fields the trust loop needs. Personal data (owner email address, user identifiers), internal commercial identifiers (billing account) and key-material-derived values (bound-key proof hash, key prefix) are REMOVED at the MCP boundary and are never returned to an MCP client — see the Mnemom privacy policy at https://www.mnemom.ai/privacy. Which fields are present depends on authorization: read `caller` to know which projection you received.",
"properties": {
"agent_hash": {
"description": "The canonical public identity hash (first 16 hex chars) used as the gateway lookup key and as the input to verify_agent_binding. Owner projection only. Not a credential and not reversible to one.",
"type": "string"
},
"aip_enforcement_mode": {
"enum": [
"observe",
"enforce",
"nudge"
],
"type": [
"string",
"null"
]
},
"avatar_url": {
"type": [
"string",
"null"
]
},
"caller": {
"description": "Which projection THIS response is. `org_member` receives the owner field set; `anonymous`/`authenticated` receive the reduced public set (id, name, claimed, created_at, last_seen, status, avatar_url, caller). Read this instead of inferring why a field is absent.",
"enum": [
"anonymous",
"authenticated",
"org_member"
],
"type": "string"
},
"claimed": {
"description": "Whether a human or organization has claimed accountability for this agent. On the owner projection this is derived from the ownership column; the owning user's identifier itself is not returned.",
"type": "boolean"
},
"claimed_at": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"containment_status": {
"description": "Containment state of the agent.",
"enum": [
"active",
"paused",
"killed"
],
"type": [
"string",
"null"
]
},
"created_at": {
"format": "date-time",
"type": "string"
},
"groups": {
"description": "Active groups this agent belongs to, name-ordered; `[]` when none. Present on org-fleet rows.",
"items": {
"properties": {
"color": {
"description": "Group color (hex, e.g. `#0d9488`); `null` when unset.",
"type": [
"string",
"null"
]
},
"id": {
"type": "string"
},
"name": {
"type": "string"
}
},
"required": [
"id",
"name",
"color"
],
"type": "object"
},
"type": "array"
},
"id": {
"description": "Agent identifier (e.g. smolt-abc123).",
"type": "string"
},
"last_seen": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"name": {
"description": "Agent name (2-32 chars, alphanumeric + hyphens).",
"type": [
"string",
"null"
]
},
"org_id": {
"description": "The agent's organization binding. Required as an input by the org-scoped tools (fleet listing, posture assignment). Identifies an organization, not a person.",
"type": [
"string",
"null"
]
},
"public": {
"description": "Whether the agent's identity record is publicly discoverable. Distinct from Trust Rating visibility, which is always public.",
"type": "boolean"
},
"status": {
"description": "Derived from last_seen (active = seen within the last hour).",
"enum": [
"active",
"offline"
],
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"agents": {
"description": "The caller's agents, reduced to the MCP trust-loop field set.",
"items": {
"$ref": "#/$defs/AgentMcpRecord"
},
"type": "array"
},
"scope": {
"description": "Echoes the resolved listing scope.",
"enum": [
"active",
"all"
],
"type": "string"
}
},
"required": [
"agents",
"scope"
],
"type": "object"
}
},
{
"description": "Dry-run an alignment card: shows the card that would result after merging with the platform, organization and team policies above it, plus any conflicts. Nothing is saved.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"audit": {
"additionalProperties": false,
"description": "How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)",
"properties": {
"query_endpoint": {
"description": "HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false.",
"maxLength": 300,
"type": "string"
},
"queryable": {
"default": false,
"description": "Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint.",
"type": "boolean"
},
"retention_days": {
"description": "How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum.",
"maximum": 3650,
"minimum": 0,
"type": "integer"
},
"tamper_evidence": {
"description": "Tamper-evidence scheme applied to the retained records.",
"enum": [
"append_only",
"signed",
"merkle"
],
"type": "string"
}
},
"required": [
"retention_days",
"queryable"
],
"type": "object"
},
"autonomy": {
"additionalProperties": false,
"description": "What the agent may do on its own authority. Required.",
"properties": {
"bounded_actions": {
"description": "Action names the agent may take within its bounds — e.g. [\"send_email\", \"create_ticket\"]. At least one required. Action identifiers only, not descriptions.",
"items": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"minItems": 1,
"type": "array"
},
"escalation_triggers": {
"description": "Conditions that route to a human instead of acting.",
"items": {
"additionalProperties": false,
"properties": {
"action": {
"description": "What to do when the condition holds.",
"enum": [
"escalate",
"deny",
"log"
],
"type": "string"
},
"condition": {
"description": "The condition, as a short expression or slug (e.g. \"amount > 1000\"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"condition",
"action",
"reason"
],
"type": "object"
},
"maxItems": 32,
"type": "array"
},
"forbidden_actions": {
"description": "Action names the agent must never take. Must be disjoint from `bounded_actions`.",
"items": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
}
},
"required": [
"bounded_actions"
],
"type": "object"
},
"autonomy_mode": {
"description": "Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"card_version": {
"description": "Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`.",
"maxLength": 40,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$",
"type": "string"
},
"integrity_mode": {
"description": "Master switch for the values pipeline. Required. Same four states as `autonomy_mode`.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"principal": {
"additionalProperties": false,
"description": "Whose authority this agent acts under. Required.",
"properties": {
"escalation_contact": {
"description": "Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX (\"oncall-sre\", \"[email protected]\"), never an individual's personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"identifier": {
"description": "Who the principal is. Use a ROLE or ORGANIZATION name (\"support-team\", \"Acme Corp Finance\"), NOT an individual's name, email address or phone number. Pass \"unspecified\" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"relationship": {
"description": "How the agent relates to that principal.",
"enum": [
"delegated_authority",
"advisory",
"autonomous"
],
"type": "string"
},
"type": {
"description": "The kind of principal the agent answers to.",
"enum": [
"human",
"organization",
"agent",
"unspecified"
],
"type": "string"
}
},
"required": [
"type",
"relationship",
"identifier"
],
"type": "object"
},
"values": {
"additionalProperties": false,
"description": "The values this agent declares it is bound by. Required.",
"properties": {
"declared": {
"description": "Value catalog IDs — e.g. [\"honesty\", \"no_harm\", \"privacy\"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)",
"items": {
"maxLength": 64,
"minLength": 1,
"type": "string"
},
"maxItems": 32,
"minItems": 1,
"type": "array"
}
},
"required": [
"declared"
],
"type": "object"
}
},
"required": [
"agent_id",
"card_version",
"autonomy_mode",
"integrity_mode",
"principal",
"values",
"autonomy",
"audit"
],
"type": "object"
},
"name": "preview_compose_alignment_by_agent",
"outputSchema": {
"additionalProperties": false,
"properties": {
"composition_valid": {
"description": "True when the composed card is coherence-valid.",
"type": "boolean"
},
"conflicts_count": {
"description": "Total number of conflicts detected (0 = none).",
"type": "integer"
},
"full_report": {
"description": "Optional pointer to the full /v1 conflict report (method + path).",
"oneOf": [
{
"type": "null"
},
{
"additionalProperties": false,
"properties": {
"method": {
"type": "string"
},
"note": {
"type": "string"
},
"path": {
"type": "string"
}
},
"required": [
"method",
"path",
"note"
],
"type": "object"
}
]
},
"ok": {
"description": "True when composition succeeded (no blocking conflicts).",
"type": "boolean"
},
"summary": {
"description": "One-line human-readable summary of composition status.",
"type": "string"
}
},
"required": [
"ok",
"composition_valid",
"conflicts_count",
"summary"
],
"type": "object"
}
},
{
"description": "Dry-run a protection card: shows the card that would result after merging with the platform, organization and team policies above it, plus any conflicts. Nothing is saved, and no publish grant is needed.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"card_version": {
"description": "Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`.",
"maxLength": 40,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$",
"type": "string"
},
"mode": {
"description": "Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"protected_surface": {
"additionalProperties": false,
"description": "The assets and operations this agent must protect. Omit to accept the composed default (empty surface).",
"properties": {
"assets": {
"description": "The assets under protection.",
"items": {
"additionalProperties": false,
"properties": {
"kind": {
"description": "Asset class — e.g. \"repo\", \"database\", \"bucket\".",
"maxLength": 64,
"minLength": 1,
"type": "string"
},
"label": {
"description": "Short human-readable name for the asset.",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"selector": {
"description": "Which instance — e.g. \"mnemom/mnemom-api\". A resource identifier only: no credentials, no connection strings, no personal data.",
"maxLength": 256,
"minLength": 1,
"type": "string"
}
},
"required": [
"kind",
"selector"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
},
"escalation_required": {
"description": "Operations that require human approval before the agent may proceed.",
"items": {
"additionalProperties": false,
"properties": {
"applies_to": {
"description": "Asset identities this entry applies to. Omit to apply to every protected asset.",
"items": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"pattern": {
"description": "Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"pattern"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
},
"forbidden_operations": {
"description": "Operations the agent must never perform on the protected assets.",
"items": {
"additionalProperties": false,
"properties": {
"applies_to": {
"description": "Asset identities this entry applies to. Omit to apply to every protected asset.",
"items": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"pattern": {
"description": "Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"severity": {
"description": "How serious a violation of this entry is.",
"enum": [
"low",
"medium",
"high",
"critical"
],
"type": "string"
}
},
"required": [
"pattern"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
}
},
"type": "object"
},
"screen_surfaces": {
"additionalProperties": false,
"description": "Which traffic surfaces are screened. Required, with all four flags set.",
"properties": {
"incoming": {
"description": "Screen prompts arriving at the agent.",
"type": "boolean"
},
"outgoing": {
"description": "Screen the agent's outbound messages.",
"type": "boolean"
},
"tool_calls": {
"description": "Screen the tool calls the agent makes.",
"type": "boolean"
},
"tool_responses": {
"description": "Screen tool responses returned to the agent.",
"type": "boolean"
}
},
"required": [
"incoming",
"outgoing",
"tool_calls",
"tool_responses"
],
"type": "object"
},
"thresholds": {
"additionalProperties": false,
"description": "Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. Required. Send the full set: a publish replaces the agent's current card rather than patching it.",
"properties": {
"block": {
"description": "Score at or above which the request is refused.",
"maximum": 1,
"minimum": 0,
"type": "number"
},
"quarantine": {
"description": "Score at or above which the request is held for review.",
"maximum": 1,
"minimum": 0,
"type": "number"
},
"warn": {
"description": "Score at or above which the request is flagged.",
"maximum": 1,
"minimum": 0,
"type": "number"
}
},
"required": [
"warn",
"quarantine",
"block"
],
"type": "object"
},
"trusted_sources": {
"additionalProperties": false,
"description": "Sources exempt from screening. Required, with all three lists present; send empty lists to trust nothing extra. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.",
"properties": {
"agent_ids": {
"description": "Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form.",
"items": {
"maxLength": 64,
"minLength": 8,
"pattern": "^mnm-[A-Za-z0-9-]{4,}$",
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"domains": {
"description": "Trusted DNS names, optionally with `:port`. No wildcards.",
"items": {
"maxLength": 253,
"minLength": 3,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"ip_ranges": {
"description": "Trusted CIDR ranges (e.g. `10.0.0.0/8`).",
"items": {
"maxLength": 43,
"minLength": 4,
"type": "string"
},
"maxItems": 64,
"type": "array"
}
},
"required": [
"domains",
"agent_ids",
"ip_ranges"
],
"type": "object"
}
},
"required": [
"agent_id",
"card_version",
"mode",
"thresholds",
"screen_surfaces",
"trusted_sources"
],
"type": "object"
},
"name": "preview_compose_protection_by_agent",
"outputSchema": {
"additionalProperties": false,
"properties": {
"composition_valid": {
"description": "True when the composed card is valid.",
"type": "boolean"
},
"conflicts_count": {
"description": "Total number of conflicts detected (0 = none).",
"type": "integer"
},
"full_report": {
"description": "Optional pointer to the full /v1 conflict report (method + path).",
"oneOf": [
{
"type": "null"
},
{
"additionalProperties": false,
"properties": {
"method": {
"type": "string"
},
"note": {
"type": "string"
},
"path": {
"type": "string"
}
},
"required": [
"method",
"path",
"note"
],
"type": "object"
}
]
},
"ok": {
"description": "True when composition succeeded (no blocking conflicts).",
"type": "boolean"
},
"summary": {
"description": "One-line human-readable summary of composition status.",
"type": "string"
}
},
"required": [
"ok",
"composition_valid",
"conflicts_count",
"summary"
],
"type": "object"
}
},
{
"description": "Publish or replace an agent's alignment card: its governance modes, the principal it acts for, its declared values, the actions it may take on its own, and its audit policy. The server merges the card with the platform, organization and team policies above it and stores the result. Use preview_compose_alignment_by_agent to dry-run first.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"audit": {
"additionalProperties": false,
"description": "How long this agent's own decision log is kept, and whether it can be queried. Required. (This is the agent's audit policy — it is NOT Mnemom's retention policy for the card itself; see the tool's data-handling disclosure for that.)",
"properties": {
"query_endpoint": {
"description": "HTTPS endpoint the records can be queried from. REQUIRED when `queryable` is true, and ignored when it is false.",
"maxLength": 300,
"type": "string"
},
"queryable": {
"default": false,
"description": "Whether those retained records can be queried. Leave false unless you also supply `query_endpoint` — the server rejects a queryable audit policy with no endpoint.",
"type": "boolean"
},
"retention_days": {
"description": "How many days the agent's decision records are retained. 0 means do not retain. 3650 (10 years) maximum.",
"maximum": 3650,
"minimum": 0,
"type": "integer"
},
"tamper_evidence": {
"description": "Tamper-evidence scheme applied to the retained records.",
"enum": [
"append_only",
"signed",
"merkle"
],
"type": "string"
}
},
"required": [
"retention_days",
"queryable"
],
"type": "object"
},
"autonomy": {
"additionalProperties": false,
"description": "What the agent may do on its own authority. Required.",
"properties": {
"bounded_actions": {
"description": "Action names the agent may take within its bounds — e.g. [\"send_email\", \"create_ticket\"]. At least one required. Action identifiers only, not descriptions.",
"items": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"minItems": 1,
"type": "array"
},
"escalation_triggers": {
"description": "Conditions that route to a human instead of acting.",
"items": {
"additionalProperties": false,
"properties": {
"action": {
"description": "What to do when the condition holds.",
"enum": [
"escalate",
"deny",
"log"
],
"type": "string"
},
"condition": {
"description": "The condition, as a short expression or slug (e.g. \"amount > 1000\"). Short condition only — never paste a conversation, a log excerpt, or a record about a person. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this trigger exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"condition",
"action",
"reason"
],
"type": "object"
},
"maxItems": 32,
"type": "array"
},
"forbidden_actions": {
"description": "Action names the agent must never take. Must be disjoint from `bounded_actions`.",
"items": {
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
}
},
"required": [
"bounded_actions"
],
"type": "object"
},
"autonomy_mode": {
"description": "Master switch for the action-policing pipeline. Required. `off` disables it; `observe` records only; `nudge` warns; `enforce` blocks.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"card_version": {
"description": "Card schema version. REQUIRED by the server-side validator. Current canonical value: `unified/2026-04-26`.",
"maxLength": 40,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$",
"type": "string"
},
"integrity_mode": {
"description": "Master switch for the values pipeline. Required. Same four states as `autonomy_mode`.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"principal": {
"additionalProperties": false,
"description": "Whose authority this agent acts under. Required.",
"properties": {
"escalation_contact": {
"description": "Where an escalation is routed. Use a ROLE ALIAS or SHARED INBOX (\"oncall-sre\", \"[email protected]\"), never an individual's personal contact details. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"identifier": {
"description": "Who the principal is. Use a ROLE or ORGANIZATION name (\"support-team\", \"Acme Corp Finance\"), NOT an individual's name, email address or phone number. Pass \"unspecified\" if there is no named principal. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 128,
"minLength": 1,
"type": "string"
},
"relationship": {
"description": "How the agent relates to that principal.",
"enum": [
"delegated_authority",
"advisory",
"autonomous"
],
"type": "string"
},
"type": {
"description": "The kind of principal the agent answers to.",
"enum": [
"human",
"organization",
"agent",
"unspecified"
],
"type": "string"
}
},
"required": [
"type",
"relationship",
"identifier"
],
"type": "object"
},
"values": {
"additionalProperties": false,
"description": "The values this agent declares it is bound by. Required.",
"properties": {
"declared": {
"description": "Value catalog IDs — e.g. [\"honesty\", \"no_harm\", \"privacy\"]. At least one required, 32 maximum. Short catalog slugs ONLY, never prose and never personal data. (Parameterized value references and long-form value definitions are available on the /v1 REST + CLI path; they are deliberately not exposed here.)",
"items": {
"maxLength": 64,
"minLength": 1,
"type": "string"
},
"maxItems": 32,
"minItems": 1,
"type": "array"
}
},
"required": [
"declared"
],
"type": "object"
}
},
"required": [
"agent_id",
"card_version",
"autonomy_mode",
"integrity_mode",
"principal",
"values",
"autonomy",
"audit"
],
"type": "object"
},
"name": "put_alignment_by_agent",
"outputSchema": {
"additionalProperties": false,
"properties": {
"card_id": {
"description": "Card ID (ac-{uuid}) of the stored alignment card.",
"pattern": "^ac-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
"type": "string"
},
"issued_at": {
"description": "ISO 8601 timestamp when the card was issued/stored.",
"format": "date-time",
"type": "string"
},
"ok": {
"const": true,
"description": "Always true on successful storage (errors return non-200 status).",
"type": "boolean"
}
},
"required": [
"card_id",
"issued_at",
"ok"
],
"type": "object"
}
},
{
"description": "Publish or replace an agent's protection card (screening mode, thresholds, trusted sources, protected assets). When connected by OAuth sign-in (e.g. ChatGPT), each publish first needs a one-time grant from the same signed-in account: open https://www.mnemom.ai/authorize-protection?agent_id=<agent_id>, approve, then publish within 15 minutes (each grant covers one publish). Required: agent_id, card_version, mode, thresholds, screen_surfaces and trusted_sources (protected_surface is optional); mode `enforce` also needs Safe House on the organization. Use preview_compose_protection_by_agent to dry-run without a grant.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "The agent this card belongs to (e.g. `smolt-abc123`). Identifier only — never place an API key, a secret, an email address, or any other personal data in this field.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"card_version": {
"description": "Card schema version. REQUIRED by the server-side validator. Current canonical value: `protection/2026-04-26`.",
"maxLength": 40,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9._/-]{1,38}[A-Za-z0-9]$",
"type": "string"
},
"mode": {
"description": "Screening mode for the protection pipeline. Required. `off` disables screening; `observe` records only; `nudge` warns; `enforce` blocks.",
"enum": [
"off",
"observe",
"nudge",
"enforce"
],
"type": "string"
},
"protected_surface": {
"additionalProperties": false,
"description": "The assets and operations this agent must protect. Omit to accept the composed default (empty surface).",
"properties": {
"assets": {
"description": "The assets under protection.",
"items": {
"additionalProperties": false,
"properties": {
"kind": {
"description": "Asset class — e.g. \"repo\", \"database\", \"bucket\".",
"maxLength": 64,
"minLength": 1,
"type": "string"
},
"label": {
"description": "Short human-readable name for the asset.",
"maxLength": 120,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why it is protected, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"selector": {
"description": "Which instance — e.g. \"mnemom/mnemom-api\". A resource identifier only: no credentials, no connection strings, no personal data.",
"maxLength": 256,
"minLength": 1,
"type": "string"
}
},
"required": [
"kind",
"selector"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
},
"escalation_required": {
"description": "Operations that require human approval before the agent may proceed.",
"items": {
"additionalProperties": false,
"properties": {
"applies_to": {
"description": "Asset identities this entry applies to. Omit to apply to every protected asset.",
"items": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"pattern": {
"description": "Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"pattern"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
},
"forbidden_operations": {
"description": "Operations the agent must never perform on the protected assets.",
"items": {
"additionalProperties": false,
"properties": {
"applies_to": {
"description": "Asset identities this entry applies to. Omit to apply to every protected asset.",
"items": {
"maxLength": 256,
"minLength": 1,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"pattern": {
"description": "Operation matcher — e.g. \"force_push\", \"drop_table*\". A short pattern, not a description.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"reason": {
"description": "Why this entry exists, in one short sentence. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"severity": {
"description": "How serious a violation of this entry is.",
"enum": [
"low",
"medium",
"high",
"critical"
],
"type": "string"
}
},
"required": [
"pattern"
],
"type": "object"
},
"maxItems": 64,
"type": "array"
}
},
"type": "object"
},
"screen_surfaces": {
"additionalProperties": false,
"description": "Which traffic surfaces are screened. Required, with all four flags set.",
"properties": {
"incoming": {
"description": "Screen prompts arriving at the agent.",
"type": "boolean"
},
"outgoing": {
"description": "Screen the agent's outbound messages.",
"type": "boolean"
},
"tool_calls": {
"description": "Screen the tool calls the agent makes.",
"type": "boolean"
},
"tool_responses": {
"description": "Screen tool responses returned to the agent.",
"type": "boolean"
}
},
"required": [
"incoming",
"outgoing",
"tool_calls",
"tool_responses"
],
"type": "object"
},
"thresholds": {
"additionalProperties": false,
"description": "Risk-score cutoffs, each in [0, 1] and ordered warn ≤ quarantine ≤ block. Required. Send the full set: a publish replaces the agent's current card rather than patching it.",
"properties": {
"block": {
"description": "Score at or above which the request is refused.",
"maximum": 1,
"minimum": 0,
"type": "number"
},
"quarantine": {
"description": "Score at or above which the request is held for review.",
"maximum": 1,
"minimum": 0,
"type": "number"
},
"warn": {
"description": "Score at or above which the request is flagged.",
"maximum": 1,
"minimum": 0,
"type": "number"
}
},
"required": [
"warn",
"quarantine",
"block"
],
"type": "object"
},
"trusted_sources": {
"additionalProperties": false,
"description": "Sources exempt from screening. Required, with all three lists present; send empty lists to trust nothing extra. Enumerate specific hosts — wildcards are rejected, and a server-side deny-list (public LLM/DNS endpoints, 0.0.0.0/0, ::/0, link-local, multicast) is always applied.",
"properties": {
"agent_ids": {
"description": "Trusted Mnemom agent IDs. Must be in canonical `mnm-*` form.",
"items": {
"maxLength": 64,
"minLength": 8,
"pattern": "^mnm-[A-Za-z0-9-]{4,}$",
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"domains": {
"description": "Trusted DNS names, optionally with `:port`. No wildcards.",
"items": {
"maxLength": 253,
"minLength": 3,
"type": "string"
},
"maxItems": 64,
"type": "array"
},
"ip_ranges": {
"description": "Trusted CIDR ranges (e.g. `10.0.0.0/8`).",
"items": {
"maxLength": 43,
"minLength": 4,
"type": "string"
},
"maxItems": 64,
"type": "array"
}
},
"required": [
"domains",
"agent_ids",
"ip_ranges"
],
"type": "object"
}
},
"required": [
"agent_id",
"card_version",
"mode",
"thresholds",
"screen_surfaces",
"trusted_sources"
],
"type": "object"
},
"name": "put_protection_by_agent",
"outputSchema": {
"additionalProperties": false,
"properties": {
"card_id": {
"description": "Card ID (pc-{uuid}) of the stored protection card.",
"pattern": "^pc-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
"type": "string"
},
"issued_at": {
"description": "ISO 8601 timestamp when the card was issued/stored.",
"format": "date-time",
"type": "string"
},
"ok": {
"const": true,
"description": "Always true on successful storage (errors return non-200 status).",
"type": "boolean"
}
},
"required": [
"card_id",
"issued_at",
"ok"
],
"type": "object"
}
},
{
"description": "Submit a false-positive / false-negative correction for one of Mnemom's automated detection rules (a 'recipe') — technical feedback that improves detection accuracy, like filing a bug report against a spam filter.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Optional. The agent the report concerns. Identifier only.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"checkpoint_id": {
"description": "Optional. The related integrity checkpoint, so the reviewer can correlate. Identifier only.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"recipeId": {
"description": "The detection recipe the report is filed against (the one that misfired or failed to fire). Identifier only.",
"maxLength": 64,
"minLength": 3,
"pattern": "^[A-Za-z0-9][A-Za-z0-9_-]{1,62}[A-Za-z0-9]$",
"type": "string"
},
"summary": {
"description": "A short description of what the recipe got wrong — what it flagged, or what it missed, and why that was incorrect. DESCRIBE the misfire; do NOT paste the conversation, the prompt, the raw payload or the log that triggered it. Do NOT enter personal data (names, email addresses, phone numbers, postal addresses), and do NOT enter health, biometric, government-identifier (e.g. SSN) or payment-card data. This text is stored on the agent's governance card and is readable by everyone in the owning organization.",
"maxLength": 500,
"minLength": 1,
"type": "string"
},
"type": {
"description": "`fn` = false negative (the recipe should have fired). `fp` = false positive (it fired on legitimate behaviour).",
"enum": [
"fn",
"fp"
],
"type": "string"
}
},
"required": [
"recipeId",
"type",
"summary"
],
"type": "object"
},
"name": "report_recipe_fn_fp",
"outputSchema": {
"properties": {
"candidate_id": {
"type": "string"
},
"ok": {
"enum": [
true
],
"type": "boolean"
},
"related_recipe_id": {
"type": "string"
},
"type": {
"enum": [
"fn",
"fp"
],
"type": "string"
}
},
"required": [
"ok",
"candidate_id",
"type",
"related_recipe_id"
],
"type": "object"
}
},
{
"description": "Scan a website's agent-trust-readiness and return a signed scorecard (Trust, plus an Access axis on newer rubrics). Zero-auth. Results are CACHED for up to 24h — check `cached` and `scannedAt` on the result; pass `fresh: true` to force a re-scan (rate-limited). Proxies to the SSRF-locked isittrustready scanner; the Ed25519 signature + permalink are preserved verbatim. Rubric + docs: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"fresh": {
"description": "Force a fresh re-scan instead of the cached result (results are cached up to 24h; the engine rate-limits re-scans). Equivalent to the scanner's rescan flag.",
"type": "boolean"
},
"url": {
"description": "Domain or URL to scan, e.g. \"example.com\" or \"https://example.com\".",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "scan_trust",
"outputSchema": {
"additionalProperties": true,
"description": "Signed iitr two-axis trust-readiness scorecard (returned verbatim). Verify it in-band with the verify_scan tool, or follow the rule + key in the scorecard's own `verification` block (Ed25519 against mnemom://iitr/jwks; canonicalization strips [signature, cached, permalink, verification]).",
"properties": {
"access": {
"additionalProperties": true,
"description": "The independent Access/discoverability axis (never blended with Trust). Present from the two-axis rubric (0.3.0+).",
"properties": {
"applicable": {
"description": "False when the site declares Access N/A.",
"type": "boolean"
},
"axis": {
"description": "Always \"access\".",
"type": "string"
},
"categories": {
"description": "Per-category Access scores + checks.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"grade": {
"description": "Access letter grade (A+…F).",
"type": "string"
},
"score": {
"description": "0–100 weighted Access/discoverability score (independent of Trust).",
"type": "number"
},
"version": {
"description": "Access-axis rubric version this sub-score was computed against.",
"type": "string"
}
},
"type": "object"
},
"cached": {
"description": "True when served from the scanner's 24h cache rather than a fresh scan.",
"type": "boolean"
},
"categories": {
"description": "Trust-axis categories with per-category scores + checks.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"grade": {
"description": "Trust letter grade (A+…F).",
"type": "string"
},
"permalink": {
"description": "Shareable /r/ permalink (only on /r/ responses; transport field).",
"format": "uri",
"type": "string"
},
"rubricVersion": {
"description": "Rubric version (e.g. \"0.4.0\").",
"type": "string"
},
"scannedAt": {
"description": "When this scorecard was produced. Results are cached up to 24h — pass fresh:true to scan_trust to force a re-scan.",
"format": "date-time",
"type": "string"
},
"schema": {
"description": "iitr-scan schema version string (e.g. \"iitr-scan/v0.N\").",
"type": "string"
},
"score": {
"description": "0–100 weighted overall TRUST score.",
"type": "number"
},
"signature": {
"additionalProperties": true,
"description": "Ed25519 signature over the canonical result (transport field; stripped before verify).",
"properties": {
"alg": {
"description": "Always \"Ed25519\".",
"type": "string"
},
"publicKeyId": {
"description": "16-hex key fingerprint, e.g. 94502b2b7235c986.",
"type": "string"
},
"signedAt": {
"description": "When the scorecard was signed.",
"format": "date-time",
"type": "string"
},
"value": {
"description": "base64 signature.",
"type": "string"
}
},
"type": "object"
},
"target": {
"description": "Normalized host that was scanned.",
"type": "string"
},
"verification": {
"additionalProperties": true,
"description": "Self-describing in-band verification block {alg, kid, jwks, canonicalization} — how to verify this scorecard's signature. Self-describing, so signed-EXCLUDED (stripped before verify).",
"type": "object"
}
},
"required": [
"schema",
"target",
"score",
"grade",
"signature"
],
"type": "object"
}
},
{
"description": "Resolve an agent name or id-prefix to a real agent_id over the PUBLIC reputation directory (only agents whose reputation visibility is public). Zero-auth. The arriving-agent entry point: discover a concrete agent_id, then call get_reputation / verify_reputation on it.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"confidence": {
"description": "Filter to agents at a given reputation-confidence level (driven by how much evidence backs the score).",
"enum": [
"high",
"medium",
"low",
"insufficient"
],
"type": "string"
},
"grade": {
"description": "Filter to one grade (e.g. `AAA`, `B`, `NR`).",
"type": "string"
},
"page": {
"default": 1,
"description": "1-based page number for pagination. Default 1.",
"minimum": 1,
"type": "integer"
},
"per_page": {
"default": 20,
"description": "Number of results per page. 1–100, default 20.",
"maximum": 100,
"minimum": 1,
"type": "integer"
},
"q": {
"description": "Name search (ilike) or agent-id prefix match.",
"type": "string"
},
"sort": {
"default": "score",
"description": "Result ordering. Default \"score\" (highest-rated first); other supported keys order by recency or name.",
"type": "string"
}
},
"type": "object"
},
"name": "search_reputation_directory",
"outputSchema": {
"$defs": {
"ReputationScore": {
"description": "Agent reputation row computed by the reputation worker's 6-hour cron. Grade alphabet: `AAA AA+ AA A+ A B+ B C+ C D NR` (NR = not-rated, insufficient data). Score is an integer 0–1000.",
"properties": {
"a2a_trust_extension": {
"description": "A2A trust extension for interop. Only present on `GET /reputation/{agent_id}` (not on batch/compare rows).",
"properties": {
"badge_url": {
"format": "uri",
"type": "string"
},
"confidence": {
"type": "string"
},
"extension_uri": {
"type": "string"
},
"grade": {
"type": "string"
},
"last_updated": {
"format": "date-time",
"type": "string"
},
"methodology_url": {
"format": "uri",
"type": "string"
},
"provider": {
"type": "string"
},
"score": {
"type": "number"
},
"verified_url": {
"format": "uri",
"type": "string"
}
},
"type": "object"
},
"agent_id": {
"type": "string"
},
"agent_name": {
"type": [
"string",
"null"
]
},
"checkpoint_accounting": {
"description": "Structured breakdown of how checkpoints were counted toward the score. `analyzed` is the scoring population; `excluded` buckets are mutually exclusive and `analyzed + synthetic + insufficient_thinking + quarantined = total`. Null for legacy rows computed before this field existed.",
"properties": {
"analyzed": {
"description": "Checkpoints that counted toward the score (drives the X/50 eligibility gauge).",
"type": "integer"
},
"excluded": {
"properties": {
"insufficient_thinking": {
"description": "Zero-analysis checkpoints (no extraction confidence, thinking tokens, or analysis duration).",
"type": "integer"
},
"quarantined": {
"description": "Checkpoints referenced by a non-expired enforce advisory; excluded from scoring entirely.",
"type": "integer"
},
"synthetic": {
"description": "Synthetic (`ic-synthetic-*`) checkpoints.",
"type": "integer"
}
},
"required": [
"synthetic",
"insufficient_thinking",
"quarantined"
],
"type": "object"
},
"re_evaluated": {
"description": "How many of the agent's checkpoints carry each kind of re-evaluation annotation (counted over `total`, not the analyzed subset). Observability only — these are not an exclusion bucket and do not enter the score arithmetic. Absent on scores computed before this breakdown existed.",
"properties": {
"corrected_clear": {
"description": "Checkpoints explicitly corrected to `clear` (`re_evaluation_metadata.corrected_verdict = 'clear'`).",
"type": "integer"
},
"corrected_non_clear": {
"description": "Checkpoints corrected to a NON-clear verdict — a cross-turn escalation or a reviewer reclassification to `review_needed`/`boundary_violation`. These count against the score per the correction, not as exonerations; a non-zero value is why this agent's score differs from the pre-MNE-2156 calculation.",
"type": "integer"
},
"resolved_no_correction": {
"description": "Checkpoints re-evaluated with NO recorded correction — the trust-recovery convention, scored as `clear`.",
"type": "integer"
}
},
"required": [
"corrected_clear",
"corrected_non_clear",
"resolved_no_correction"
],
"type": "object"
},
"total": {
"description": "All checkpoints recorded for the agent.",
"type": "integer"
}
},
"required": [
"total",
"analyzed",
"excluded"
],
"type": [
"object",
"null"
]
},
"checkpoint_count": {
"type": "integer"
},
"claimed": {
"type": "boolean"
},
"components": {
"items": {
"properties": {
"factors": {
"type": "array"
},
"key": {
"enum": [
"integrity_ratio",
"compliance",
"drift_stability",
"trace_completeness",
"coherence_compatibility"
],
"type": "string"
},
"label": {
"type": "string"
},
"score": {
"type": "number"
},
"weight": {
"type": "number"
},
"weighted_score": {
"type": "number"
}
},
"required": [
"key",
"score",
"weight",
"weighted_score"
],
"type": "object"
},
"type": "array"
},
"computed_at": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"confidence": {
"enum": [
"insufficient",
"low",
"medium",
"high"
],
"type": "string"
},
"grade": {
"description": "AAA–D or NR.",
"type": [
"string",
"null"
]
},
"is_eligible": {
"type": "boolean"
},
"next_compute_at": {
"description": "Next scheduled recompute — the 00/06/12/18 UTC cron slot strictly after `computed_at` (`floor(computed_at/6h)*6h + 6h`). Null when `computed_at` is null.",
"format": "date-time",
"type": [
"string",
"null"
]
},
"score": {
"maximum": 1000,
"minimum": 0,
"type": [
"integer",
"null"
]
},
"tier": {
"type": [
"string",
"null"
]
},
"trend_30d": {
"type": [
"number",
"null"
]
},
"visibility": {
"description": "Reputation-publication axis — whether this agent's Trust Rating is published. Every registered agent's reputation is `public` by accountability standard (the default; that is the whole point of a portable, verifiable rating); `private` is a rare owner opt-out that 403s the read to non-owners. This is DISTINCT from `Agent.public` (the identity-record visibility axis) — they share the word \"public\" but govern different things.",
"enum": [
"public",
"private"
],
"type": "string"
}
},
"required": [
"agent_id",
"score",
"grade",
"is_eligible",
"checkpoint_count",
"confidence",
"components",
"visibility"
],
"type": "object"
}
},
"properties": {
"agents": {
"items": {
"$ref": "#/$defs/ReputationScore"
},
"type": "array"
},
"page": {
"type": "integer"
},
"per_page": {
"type": "integer"
},
"total": {
"type": "integer"
}
},
"required": [
"agents",
"total",
"page",
"per_page"
],
"type": "object"
}
},
{
"description": "Attest an agent's Trust Rating — returns a Merkle-root + hash-chain attestation (hash_chain_valid) proving the rating derives from an unbroken, append-only checkpoint chain, plus a pointer to the signed integrity certificate. This is a chain-integrity attestation, NOT an in-band Ed25519 signature check (that parity is verify_scan, for website scorecards).",
"inputSchema": {
"additionalProperties": false,
"properties": {
"agent_id": {
"description": "Agent identifier (e.g. smolt-abc123)",
"type": "string"
}
},
"required": [
"agent_id"
],
"type": "object"
},
"name": "verify_reputation",
"outputSchema": {
"properties": {
"agent_id": {
"type": "string"
},
"computed_at": {
"format": "date-time",
"type": "string"
},
"grade": {
"type": "string"
},
"score": {
"type": "number"
},
"verification": {
"properties": {
"certificate_url": {
"type": [
"string",
"null"
]
},
"checkpoint_count": {
"type": "integer"
},
"first_checkpoint": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"hash_chain_valid": {
"type": "boolean"
},
"last_checkpoint": {
"format": "date-time",
"type": [
"string",
"null"
]
},
"latest_certificate_hash": {
"type": [
"string",
"null"
]
},
"merkle_root": {
"type": [
"string",
"null"
]
}
},
"type": [
"object",
"null"
]
}
},
"required": [
"agent_id",
"score",
"grade",
"computed_at",
"verification"
],
"type": "object"
}
},
{
"description": "Verify a website scan scorecard's Ed25519 signature IN-BAND (verify, don't trust). Pass a `scan` (a scorecard from scan_trust) or a `url` to re-scan; returns {verified, key_id, canonicalization} checked against the public key at mnemom://iitr/jwks. Zero-auth. Spec + rubric: https://www.isittrustready.ai/rubric and https://docs.mnemom.ai/.",
"inputSchema": {
"additionalProperties": false,
"oneOf": [
{
"not": {
"required": [
"url"
]
},
"required": [
"scan"
]
},
{
"not": {
"required": [
"scan"
]
},
"required": [
"url"
]
}
],
"properties": {
"scan": {
"additionalProperties": true,
"description": "A scan scorecard previously returned by scan_trust (or iitr's /r/ JSON), passed back verbatim to verify. Same shape as scan_trust's result; the signature is checked against mnemom://iitr/jwks.",
"properties": {
"access": {
"additionalProperties": true,
"description": "The independent Access/discoverability axis (never blended with Trust). Present from the two-axis rubric (0.3.0+).",
"properties": {
"applicable": {
"description": "False when the site declares Access N/A.",
"type": "boolean"
},
"axis": {
"description": "Always \"access\".",
"type": "string"
},
"categories": {
"description": "Per-category Access scores + checks.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"grade": {
"description": "Access letter grade (A+…F).",
"type": "string"
},
"score": {
"description": "0–100 weighted Access/discoverability score (independent of Trust).",
"type": "number"
},
"version": {
"description": "Access-axis rubric version this sub-score was computed against.",
"type": "string"
}
},
"type": "object"
},
"cached": {
"description": "True when served from the scanner's 24h cache rather than a fresh scan.",
"type": "boolean"
},
"categories": {
"description": "Trust-axis categories with per-category scores + checks.",
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
"grade": {
"description": "Trust letter grade (A+…F).",
"type": "string"
},
"permalink": {
"description": "Shareable /r/ permalink (only on /r/ responses; transport field).",
"format": "uri",
"type": "string"
},
"rubricVersion": {
"description": "Rubric version (e.g. \"0.4.0\").",
"type": "string"
},
"scannedAt": {
"description": "When this scorecard was produced. Results are cached up to 24h — pass fresh:true to scan_trust to force a re-scan.",
"format": "date-time",
"type": "string"
},
"schema": {
"description": "iitr-scan schema version string (e.g. \"iitr-scan/v0.N\").",
"type": "string"
},
"score": {
"description": "0–100 weighted overall TRUST score.",
"type": "number"
},
"signature": {
"additionalProperties": true,
"description": "Ed25519 signature over the canonical result (transport field; stripped before verify).",
"properties": {
"alg": {
"description": "Always \"Ed25519\".",
"type": "string"
},
"publicKeyId": {
"description": "16-hex key fingerprint, e.g. 94502b2b7235c986.",
"type": "string"
},
"signedAt": {
"description": "When the scorecard was signed.",
"format": "date-time",
"type": "string"
},
"value": {
"description": "base64 signature.",
"type": "string"
}
},
"type": "object"
},
"target": {
"description": "Normalized host that was scanned.",
"type": "string"
},
"verification": {
"additionalProperties": true,
"description": "Self-describing in-band verification block {alg, kid, jwks, canonicalization} — how to verify this scorecard's signature. Self-describing, so signed-EXCLUDED (stripped before verify).",
"type": "object"
}
},
"required": [
"schema",
"target",
"score",
"grade",
"signature"
],
"type": "object"
},
"url": {
"description": "Alternatively, a domain/URL to re-scan and then verify.",
"type": "string"
}
},
"type": "object"
},
"name": "verify_scan",
"outputSchema": {
"additionalProperties": true,
"description": "In-band verification verdict for an iitr scan scorecard's Ed25519 signature.",
"properties": {
"algorithm": {
"description": "Always \"Ed25519\".",
"type": "string"
},
"canonicalization": {
"description": "The exact canonicalization used (so the verdict is reproducible).",
"type": "string"
},
"key_id": {
"description": "The signing key id (kid) checked.",
"type": [
"string",
"null"
]
},
"reason": {
"description": "Why verification failed or could not be evaluated (absent when verified).",
"type": "string"
},
"scorecard": {
"additionalProperties": true,
"description": "The scorecard verified (present when re-scanned via `url`).",
"type": "object"
},
"verified": {
"description": "True iff the signature verifies against the in-band JWKS.",
"type": "boolean"
}
},
"required": [
"verified",
"algorithm",
"key_id",
"canonicalization"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:0c59d90259a2fc4073f81d4dd3bd556df98d36358f47bdf18c7d23ae1a681f1d | sha256sum