generated: '2026-09-19' method: probed source: https://agenthealthmonitor.xyz/.well-known/agent.json card: file: a2a/agenthealthmonitor-xyz-agent-card.json discovery: path: /.well-known/agent.json canonical: false host: agenthealthmonitor.xyz note: 'Found at the pre-0.3 legacy path only: /.well-known/agent-card.json returns a real JSON 404 ({"detail":"Not Found"}) on the same host. The apex host is a FastAPI app that answers unknown paths with a 404, and the negative-control path /.well-known/agenthealthmonitor-xyz-negative-control-7f3ab91c.json also returned 404, so the 200 on agent.json is a served document and not a catch-all. The provider''s own test suite (tests/test_a2a_discovery.py in github.com/moonshot-cyber/agent-health-monitor) asserts the card at this legacy path, so the location is deliberate. Ownership is not in question: provider.organization is "Digital Intensity Ltd" with provider.url https://agenthealthmonitor.xyz, the same host serves the Agent Health Monitor OpenAPI (contact url https://agenthealthmonitor.xyz/), and the OpenAPI itself declares the GET /.well-known/agent.json operation (operationId a2a_agent_card__well_known_agent_json_get).' conformance: spec: A2A 1.0.0 grade: flavored protocol_version: null preferred_transport: null hard_checks: capabilities_is_object: true protocol_version_present: false skills_is_array: true deviations: - no-top-level-protocolVersion (only supportedInterfaces[].protocolVersion "1.0") - supportedInterfaces-instead-of-additionalInterfaces - no-preferredTransport - declared-endpoint-url-404 (https://agenthealthmonitor.xyz/a2a answers 404 to GET and to a JSON-RPC POST; /a2a/http likewise) - documentationUrl-404 (https://agenthealthmonitor.xyz/endpoints returns 404; the live docs are https://docs.agenthealthmonitor.xyz) - served-as-application/json-not-application/a2a+json - securitySchemes-name-X-AHM-API-Key-differs-from-the-REST-API-header-X-API-Key note: 'Grade is flavored because the top-level protocolVersion required by A2A 1.0.0 is absent (a hard check). capabilities is an object and skills is an array, so the shape is otherwise correct. Beyond the structural grade: the card is a discovery document for an A2A endpoint that does not currently answer, so an A2A client that reads it cannot complete a task here today.' x-evidence: fetched: '2026-09-19' url: https://agenthealthmonitor.xyz/.well-known/agent.json http_status: 200 content_type: application/json body_bytes: 5341 last_modified: Wed, 02 Sep 2026 19:40:13 GMT body_parses_as: JSON object with AgentCard shape (name, description, url, version, provider, iconUrl, documentationUrl, capabilities, defaultInputModes, defaultOutputModes, supportedInterfaces, securitySchemes, security, skills, extensions) corroborating_probes: - url: https://agenthealthmonitor.xyz/.well-known/agent-card.json http_status: 404 - url: https://agenthealthmonitor.xyz/.well-known/agenthealthmonitor-xyz-negative-control-7f3ab91c.json http_status: 404 note: negative control — the host does not echo unknown well-known paths - url: https://agenthealthmonitor.xyz/a2a method: POST http_status: 404 note: JSON-RPC {"method":"agent/getAuthenticatedExtendedCard"} answered {"detail":"Not Found"}; GET also 404 - url: https://agenthealthmonitor.xyz/a2a/http method: POST http_status: 404 - url: https://agenthealthmonitor.xyz/endpoints http_status: 404 note: the card documentationUrl - url: https://agenthealthmonitor.xyz/static/ahm-logo.png http_status: 200 note: the card iconUrl resolves - url: https://www.agenthealthmonitor.xyz/.well-known/agent.json http_status: 301 note: redirects to the apex - url: https://docs.agenthealthmonitor.xyz/.well-known/agent-card.json http_status: 200 note: SPA catch-all — HTML shell of the docs site (40,648 bytes); NOT a card and not counted - url: https://verify.agenthealthmonitor.xyz/.well-known/agent-card.json http_status: 404 - url: https://verify.agenthealthmonitor.xyz/.well-known/agent.json http_status: 404 - url: https://blog.agenthealthmonitor.xyz/.well-known/agent-card.json http_status: 404 - url: https://intelligence.agenthealthmonitor.xyz/.well-known/agent-card.json http_status: 404 - url: https://github.com/moonshot-cyber/agent-health-monitor/blob/master/docs/ecosystem/agent-card.json note: the same card in the provider's public source repo; ECOSYSTEM.md lists submitting the live URL to prassanna-ravishankar/a2a-registry as a to-do, which is how this provider reached the harvest backlog (x-source harvest:a2a-registry). agent_card: name: Agent Health Monitor (AHM) description: A trust-scoring and health-monitoring service for AI agents. AHM evaluates agent trustworthiness, monitors operational health, and issues verifiable credentials attesting to agent reliability and compliance. url: https://agenthealthmonitor.xyz/a2a version: 0.1.0 provider: organization: Digital Intensity Ltd url: https://agenthealthmonitor.xyz documentation_url: https://agenthealthmonitor.xyz/endpoints icon_url: https://agenthealthmonitor.xyz/static/ahm-logo.png capabilities: streaming: false pushNotifications: true stateTransitionHistory: true extendedAgentCard: true default_input_modes: - application/json - text/plain default_output_modes: - application/json supported_interfaces: - url: https://agenthealthmonitor.xyz/a2a protocolBinding: JSONRPC protocolVersion: '1.0' - url: https://agenthealthmonitor.xyz/a2a/http protocolBinding: HTTP+JSON protocolVersion: '1.0' security_schemes: - bearerAuth - apiKey skills: - id: trust_score_evaluation name: Trust Score Evaluation tags: - trust - scoring - evaluation - risk-assessment - id: agent_health_monitoring name: Agent Health Monitoring tags: - health - monitoring - uptime - observability - id: verifiable_credential_issuance name: Verifiable Credential Issuance tags: - credentials - verifiable - attestation - compliance - W3C-VC - id: trust_report_generation name: Trust Report Generation tags: - report - analytics - trust-history - benchmarking - id: agent_registration name: Agent Registration tags: - registration - onboarding - discovery skill_count: 5 extensions: - urn:ahm:extension:verifiable-credentials:1.0 - urn:ahm:extension:trust-dimensions:1.0 x-notes: card_vs_deployed_product: The card describes a trust-scoring service that "issues verifiable credentials" and offers "trust report generation"; the deployed REST API (openapi/agenthealthmonitor-xyz-openapi.yml, info.version 1.8.0) is wallet-intelligence for agents on Base L2 — risk scores, health reports, the Agent Health Score, trust routing, alerts. The skills map loosely onto real operations (trust_score_evaluation ~ get_ahs_report_ahs__address__get / get_risk_score_risk__address__get; agent_health_monitoring ~ subscribe_alerts_alerts_subscribe__address__get + alert_status_alerts_status__address__get; trust_report_generation ~ get_report_card_report_card__address__get; agent_registration ~ no public operation — the trust registry is populated by nightly scans of ERC-8004/ACP/Olas/Celo/Arc). verifiable_credential_issuance has no public operation; the provider's ECOSYSTEM.md shows a sample W3C VC and describes issuance via the agntcy Identity Service as planned work. a2a_endpoint: No A2A JSON-RPC server is deployed at the declared url. The pipeline sent one discovery-shaped JSON-RPC message (agent/getAuthenticatedExtendedCard) and received the FastAPI 404 envelope; no task was created and no paid operation was invoked.