generated: '2026-09-19' method: searched source: https://travel.agenthaven.dev/.well-known/agent-card.json docs: - https://travel.agenthaven.dev/ - https://provedby.dev/contracts/guest-buyer.md derived_from: - a2a/agenthaven-dev-agent-card.json (securitySchemes, skills[].security) - mcp/agenthaven-dev-mcp-tools.json (create_checkout inputSchema mandate_jws) - https://travel.agenthaven.dev/health (guests policy, mandate_issuers) note: >- derive-authentication.py was not run because the provider publishes no OpenAPI; the profile below is read from the agent card's securitySchemes (the only machine-readable auth declaration), the MCP initialize instructions (which repeat it verbatim), the documentation page, and the live /health document. summary: types: [none, http-bearer-jwt] api_key_in: [] oauth2_flows: [] token_endpoint: none published discovery: none (no RFC 8414 / OIDC / RFC 9728 documents on any host) anonymous_surface: [MCP initialize, MCP ping, MCP tools/list, MCP tools/call search_flights, A2A message/send search_flights, GET /health, GET /ledger, every /.well-known document] authenticated_surface: [MCP tools/call create_checkout, A2A message/send create_checkout] delegation_model: >- Buyer-side mandates rather than OAuth authorization_code. The docs state the checkout token "carries a spending cap, a currency and a deadline set by the buyer's human; a request above the cap is refused, and the refusal is written to the ledger" — a delegated, human-bounded authority — but it is expressed as a JWT mandate from an issuer the merchant trusts, not as a token obtained through an authorization server, so no discovery document exists for the rubric's delegated_identity check to read. schemes: - name: bearer type: http scheme: bearer bearerFormat: JWT required_for: [create_checkout] scopes: [commerce:purchase] sources: ['a2a/agenthaven-dev-agent-card.json#securitySchemes.bearer', 'a2a/agenthaven-dev-agent-card.json#skills[1].security'] description: >- "Needed for create_checkout only; search_flights and tools/list are open. There is no public token endpoint. Two forms are accepted. (1) Sign each call as a request envelope (Authorization: Bearer ) under a key attested at /.well-known/agent-keys.json on your own domain, and present at checkout a mandate from an authority this merchant trusts (https://sealedby.dev), bound to the quote and to that key. (2) A JWT issued by this merchant's operator on request: iss agent-bench-demo-issuer, aud agent-bench, scope commerce:purchase, with a spending cap in EUR." forms: - id: request-envelope how: Per-call compact JWS with typ request+jwt in the Authorization header, signed by the caller's own key. key_attestation: 'The signing key is attested at /.well-known/agent-keys.json on the CALLER''s domain (the merchant does not serve one for itself; travel.agenthaven.dev/.well-known/agent-keys.json 404).' mandate: 'At checkout, mandate_jws (typ mandate+jwt) from a trusted authority — GET /health lists mandate_issuers ["https://sealedby.dev"] — bound to quote_hash and to the envelope key; ledger entries record mandate_format ap2-v0.2.' - id: operator-issued-jwt how: A JWT the merchant's operator issues on request (no self-service path). Claims stated by the card — iss agent-bench-demo-issuer, aud agent-bench, scope commerce:purchase, plus an EUR spending cap. - id: guest-buyer how: >- Documented on the page under "Buying as a guest": a buyer with no introduction publishes a P-256 public key in a DNSSEC-signed TXT record at _agent-keys. ("v=agentkey1; kty=EC; crv=P-256; x=...; y=..."), signs each call as a request envelope with iss spiffe:///, and presents a mandate it issues itself (typ mandate+jwt, iss https://, signed by a key in that record, bound to the quote and the envelope key, living at most 10 minutes). limits: 'GET /health guests: accepted true, ceiling_minor 100000 EUR (1000.00 EUR per purchase), mandate_max_seconds 600, purchases_per_day 20 (all guests together); guest searches spend the anonymous budget. Contract, vector and a one-file reference buyer at https://provedby.dev/contracts/guest-buyer.md (200, third-party host named by the provider).' - name: anonymous type: none applies_to: [search_flights, tools/list, initialize, ping, /health, /ledger, well-known documents] limits: anonymous searches 40 per day and 120 per month, shared; an authorised search never counts (docs; live counters in GET /health counters.anonymous_searches). sources: [https://travel.agenthaven.dev/, https://travel.agenthaven.dev/health] verification_keys: merchant_jwks: https://travel.agenthaven.dev/.well-known/jwks.json merchant_jwks_note: 'Documented as "Authorization key set — public keys the merchant verifies buyer tokens against" (kid eF_VZyTpOBYDR0TXuvJF0nALLjaWIHQYWQhgbPZzMnM, ES256).' instance_svid: https://travel.agenthaven.dev/.well-known/spiffe-svid.json trust_bundle: https://travel.agenthaven.dev/.well-known/spiffe-bundle.json dns_aid_record_key: https://dns-aid.agenthaven.dev/.well-known/dns-aid-jwks.json refusals: See errors/agenthaven-dev-problem-types.yml — authorization_missing, authorization_invalid, authorization_denied, signer_unknown, identity_revoked, mandate_expired, mandate_consumed, mandate_revoked and quote_hash_mismatch are the auth-stage refusal reasons observed in the public ledger.