generated: '2026-09-19' method: probed source: https://agent-ready.dev/.well-known/agent-card.json card: file: a2a/agent-ready-dev-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: agent-ready.dev note: >- Served from the apex host, which is also the OpenAPI servers[] host, the MCP host and the A2A JSON-RPC host. The legacy /.well-known/agent.json returns a real 404 (the site's HTML not-found page), and other unpublished /.well-known/* paths (ucp.json, acp.json, aauth-resource.json, apis.json) also 404, so the 200 on agent-card.json is a served document and not an SPA catch-all. It is served with the A2A media type application/a2a+json. The same card is also served from https://mcp.agent-ready.dev/.well-known/agent-card.json, identical except that its JWS protected header points jku at the mcp. host's own /.well-known/jwks.json. Ownership is not in question: provider.organization is "Agent Ready" with provider.url https://agent-ready.dev, documentationUrl is https://agent-ready.dev/docs/api, and the OpenAPI on the same host titles itself "Agent Ready API" with contact support@agent-ready.dev. x-evidence: fetched: '2026-09-19' url: https://agent-ready.dev/.well-known/agent-card.json http_status: 200 content_type: application/a2a+json; charset=utf-8 body_bytes: 2586 body_parses_as: >- JSON object with AgentCard shape (name, url, version, protocolVersion, capabilities, skills, provider, preferredTransport, defaultInputModes, defaultOutputModes, securitySchemes, security, supportedInterfaces, documentationUrl, signatures) corroborating_probes: - url: https://agent-ready.dev/.well-known/agent.json http_status: 404 - url: https://mcp.agent-ready.dev/.well-known/agent-card.json http_status: 200 note: Same card; only the signature's jku (mcp.agent-ready.dev/.well-known/jwks.json) and signature value differ. - url: https://agent-ready.dev/.well-known/jwks.json http_status: 200 note: 'ES256 P-256 key kid agent-ready-es256-2026-08-20 — the kid named in the card''s JWS protected header.' - url: https://agent-ready.dev/api/v1/a2a method: GET http_status: 401 note: >- The declared JSON-RPC endpoint sits under /api/, which answers unauthenticated GETs with the RFC 9728 WWW-Authenticate challenge (resource_metadata=https://agent-ready.dev/.well-known/oauth-protected-resource). No message was sent to the endpoint by this pipeline. - url: https://agent-ready.dev/.well-known/ai-catalog.json http_status: 200 note: The provider's own AI Catalog lists the card as urn:air:agent-ready.dev:a2a:agent-ready. - url: https://a2aregistry.org note: >- The card was first seen listed on a2aregistry.org, which is how this provider entered the harvest backlog. The registry listing was the lead; the card above was fetched directly from the provider's host. agent_card: name: agent-ready description: >- AI agent readability scanner. Scores any site against the Vercel Agent Readability Spec and llmstxt.org, and reports per-check remediation guidance. url: https://agent-ready.dev/api/v1/a2a version: 1.0.0 protocol_version: '1.0' preferred_transport: JSONRPC documentation_url: https://agent-ready.dev/docs/api provider: organization: Agent Ready url: https://agent-ready.dev capabilities: streaming: false push_notifications: false default_input_modes: [application/json, text/plain] default_output_modes: [application/json] supported_interfaces: - {protocol_binding: JSONRPC, protocol_version: '1.0', url: https://agent-ready.dev/api/v1/a2a} security_schemes: bearer: type: httpAuthSecurityScheme scheme: bearer bearer_format: ar_live_ description: >- Agent Ready Pro API key (ar_live_…). Required for scan_site and tasks/get; the ask skill is public. Issue a key at https://agent-ready.dev/dashboard/api-keys. security: - {bearer: []} - {} signatures: count: 1 alg: ES256 kid: agent-ready-es256-2026-08-20 jku: https://agent-ready.dev/.well-known/jwks.json skill_count: 3 skills: - {id: scan_site, name: Scan a site, tags: [scan, readability, llms-txt, mcp, a2a], auth: bearer, input_modes: [application/json, text/plain], output_modes: [application/json]} - {id: get_scan, name: Get a scan by id, tags: [scan, read], auth: bearer, input_modes: [application/json], output_modes: [application/json]} - {id: ask, name: Ask Agent Ready, tags: [ask, nlweb, search, methodology], auth: public, input_modes: [text/plain, application/json], output_modes: [application/json]} skill_invocation: >- scan_site is sent via message/send; a long scan returns a working Task whose id is polled with tasks/get (the get_scan skill). ask is a natural-language NLWeb query returning Schema.org-typed results. Every skill carries an examples[] entry. conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '1.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming and pushNotifications booleans. protocolVersion is present at the top level (pass), declared as "1.0", and is repeated inside supportedInterfaces[0]. skills is an ARRAY (pass) of three fully-populated skills, each with id, name, description, tags, examples, inputModes and outputModes. All three optional discriminators are present. The card carries BOTH the 1.0.0 supportedInterfaces[] block and the 0.3-era top-level url + preferredTransport triple, so readers written against either revision resolve the same JSON-RPC endpoint. It also declares securitySchemes/security (bearer with an anonymous alternative) and a JWS signature whose key is published at the jku — the fullest card shape this catalog has recorded. deviations: - field: capabilities observed: only streaming and pushNotifications declared; no stateTransitionHistory, no extensions[] note: Optional members; recorded for completeness, not as a fault. - field: security observed: '[{bearer: []}, {}] — the empty object makes anonymous access a declared alternative' note: >- Correct A2A/OpenAPI semantics for "bearer OR anonymous", and the securitySchemes.bearer description says which skills need the key (scan_site, tasks/get) and which does not (ask). A client cannot read the per-skill requirement from skills[].security, which is absent; it is stated only in prose. - field: iconUrl observed: absent note: Optional; the MCP initialize response and ai-plugin.json publish https://agent-ready.dev/icon-512.png. surface_relationship: note: >- Agent Ready publishes three agent surfaces on one host and they are projections of the same scanner. A2A: three skills at https://agent-ready.dev/api/v1/a2a. MCP: the same three names as tools at https://agent-ready.dev/api/v1/mcp and /api/apps/mcp (see mcp/agent-ready-dev-mcp.yml). REST: eight operations in the OpenAPI, of which startScan/getScan back scan_site/get_scan and askGet/askPost back ask (see mcp/agent-ready-dev-tool-crosswalk.yml). The provider's own /.well-known/ucp declares the three transports (rest, mcp, a2a) side by side under the dev.agent-ready.scanning service.