generated: '2026-09-19' method: probed source: https://01mind.net/.well-known/agent-card.json card: file: a2a/01mind-net-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: 01mind.net note: >- Served from the apex host, which is also the OpenAPI servers[] host, the MCP host and the A2A JSON-RPC host — 01Mind runs everything on one Render-hosted origin behind Cloudflare. www.01mind.net 301s every /.well-known/* path to the apex. The legacy /.well-known/agent.json returns a real JSON 404 ({"error":"Not found"}, 21 bytes), not an SPA shell, and a negative-control path (/.well-known/01mind-net-negative-control-9c4e21d7.json) also 404s, so the 200 on agent-card.json is a served document and not a catch-all. Ownership is not in question: the card's provider.organization is "01Mind" with provider.url https://01mind.net, the OpenAPI at the same host titles itself "01Mind Agent Superstore API" with termsOfService https://01mind.net/terms, and the Terms of Sale name the A2A channel explicitly (clause 1.3). x-evidence: fetched: '2026-09-19' url: https://01mind.net/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 6451 body_parses_as: JSON object with AgentCard shape (name, url, version, protocolVersion, capabilities, skills, provider, preferredTransport, defaultInputModes, defaultOutputModes) corroborating_probes: - url: https://01mind.net/.well-known/agent.json http_status: 404 - url: https://www.01mind.net/.well-known/agent-card.json http_status: 301 note: Redirects to https://01mind.net/.well-known/agent-card.json. - url: https://01mind.net/a2a http_status: 404 note: GET on the declared JSON-RPC endpoint returns the site's generic JSON 404. The endpoint is POST-only. - url: https://01mind.net/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tasks/get","params":{"id":"apievangelist-nonexistent-probe"}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32001,"message":"Task not found"}}' note: A real A2A JSON-RPC responder — TaskNotFoundError (-32001) is the A2A-defined code for an unknown task id. No message was sent and nothing was purchased. - url: https://01mind.net/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"agent/getAuthenticatedExtendedCard","params":{}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"Method not found: agent/getAuthenticatedExtendedCard"}}' note: The extended-card method is not implemented, consistent with the card not declaring extendedAgentCard support. - url: https://a2aregistry.org note: The card was first seen as one of 415 agents listed on a2aregistry.org (fetched 2026-09-19, author "01Mind"), which is how this provider entered the harvest backlog. The registry listing was the lead; the card above was fetched directly from the provider's host. agent_card: name: 01Mind description: >- A machine-to-machine agent superstore -- real, paid API services (data, actions, specialised knowledge) for autonomous agents, settled via x402 on Base. Paying accepts the 01Mind Terms of Sale (version 2026-09-15): https://01mind.net/terms url: https://01mind.net/a2a version: 3.0.0 protocol_version: 0.3.0 preferred_transport: JSONRPC provider: organization: 01Mind url: https://01mind.net capabilities: streaming: false push_notifications: false state_transition_history: true extensions: - uri: https://github.com/google-a2a/a2a-x402/v0.1 description: Supports payment for catalogue listings via the x402 protocol, settled on Base (eip155:8453). required: true default_input_modes: [application/json] default_output_modes: [application/json] security_schemes: null security: null documentation_url: null icon_url: null skill_count: 10 skills: - {id: render-document, name: Render Document, tags: [Document Generation], price_stated: '5 free documents per month per API key, then $0.25 each'} - {id: email-send-action-api, name: Email Send Action Api, tags: [Action API], price_stated: 'each settled purchase covers one email; capped at 20 per wallet per 24h'} - {id: legal-research-knowledge-api, name: Legal Research Knowledge Api, tags: [Specialised Knowledge API]} - {id: au-tax-compliance-pack, name: Au Tax Compliance Pack, tags: [Synthetic Pack]} - {id: gdpr-compliance-pack, name: Gdpr Compliance Pack, tags: [Synthetic Pack]} - {id: hipaa-compliance-pack, name: Hipaa Compliance Pack, tags: [Synthetic Pack]} - {id: asic-accc-guidance-pack, name: Asic Accc Guidance Pack, tags: [Synthetic Pack]} - {id: aviation-safety-pack, name: Aviation Safety Pack, tags: [Synthetic Pack]} - {id: agent-economy-venue-intelligence, name: Agent Economy Venue Intelligence, tags: [Specialised Knowledge API]} - {id: pub_9a615b4fed78, name: Pub_9a615b4fed78, tags: [Specialised Knowledge API]} skill_invocation: >- Every skill's examples[] entry is identical in form: send a message with a DataPart {"listingId": ""} to purchase that listing through the x402 payment extension. The skill ids are the same listingIds the REST contract's POST /execute/{listingId} and the MCP tool list use. conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '0.3.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications, stateTransitionHistory and an extensions[] array. protocolVersion is present at the top level (pass), declared as "0.3.0". skills is an ARRAY (pass) of ten fully-populated skills, each with id, name, description, tags and examples. All three optional discriminators are present: preferredTransport (JSONRPC), defaultInputModes and defaultOutputModes (both application/json). This is a 0.3.0-shaped card — top-level url + preferredTransport + protocolVersion rather than the 1.0.0 supportedInterfaces[] block — and it is internally consistent with that revision. deviations: - field: protocolVersion / url / preferredTransport observed: 0.3.0 top-level triple; no supportedInterfaces[] or additionalInterfaces[] note: >- Valid for A2A 0.3.0, which the card declares. A reader written against A2A 1.0.0 looks for supportedInterfaces[].protocolBinding and will not find it. Recorded because both card shapes coexist in the catalog, not as a fault. - field: securitySchemes / security observed: absent note: >- The card declares no authentication scheme at all. Access control is economic rather than credential-based: the only gate is the required a2a-x402 extension (capabilities.extensions[0].required = true), so an A2A client that does not implement that extension cannot use any of the ten skills, and the card gives it no fallback. An agent reading the card cannot tell from securitySchemes that payment is the auth model; it has to read the extension URI and the prose. - field: skills[9] (pub_9a615b4fed78) observed: machine-generated id and name; description is an editorial note rather than a skill description note: >- The tenth skill's description reads as leaked working text ("I've written a shorter, human-facing version distinct from the agent-facing technical guide already approved...") and describes an ERC-8004 registry audit, but neither the id nor that subject appears on the human catalogue page at https://01mind.net/catalogue, which instead lists a tenth listing the card does not carry ("State of the Agent Economy Report", $35 USDC). The card and the catalogue diverge on one listing in each direction. - field: skills[].inputModes / outputModes / security observed: absent on every skill note: Optional per-skill fields; the card relies on the defaultInputModes/defaultOutputModes of application/json. - field: documentationUrl / iconUrl / signatures observed: absent note: >- No documentation link (the developer page is https://01mind.net/developers and the OpenAPI is at https://01mind.net/openapi.json, neither referenced from the card) and no JWS signature block, so the card's authenticity rests entirely on TLS to 01mind.net. - field: capabilities.extensions[0].uri observed: https://github.com/google-a2a/a2a-x402/v0.1 note: >- Declares the a2a-x402 payment extension as REQUIRED. This is the card's domain-standard signature for agent commerce — see conformance/01mind-net-conformance.yml — and also the reason the skills need no credential. surface_relationship: note: >- 01Mind publishes three agent surfaces on one host and they are projections of the same catalogue, not of one another. A2A: ten skills at https://01mind.net/a2a, each a purchasable listing. MCP: three tools at https://01mind.net/mcp (list_offerings, render_document, save_document_template) with the rest of the catalogue reachable through list_offerings rather than advertised as tools (see mcp/01mind-net-mcp.yml). REST: 28 operations at https://01mind.net, of which POST /execute/{listingId} is the operation every A2A skill and paid MCP call ultimately maps to (see mcp/01mind-net-tool-crosswalk.yml). The Terms of Sale (clause 1.3) name a fourth channel, the Agent Commerce Protocol (ACP), for which no endpoint or /.well-known/acp.json document was found.