generated: '2026-09-19' method: probed source: https://apimesh.xyz/.well-known/agent-card.json card: file: a2a/apimesh-xyz-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: apimesh.xyz note: >- Served from the apex host by Caddy as a static file out of the repo's public/.well-known/ directory (caddy/Caddyfile in github.com/mbeato/APIMesh). The legacy path /.well-known/agent.json returns a byte-identical body. No other APIMesh host serves a card: api., mcp., agentsmd. and stripesig.apimesh.xyz all 404 both paths (probed 2026-09-19). ownership: >- provider.organization is "APIMesh" with provider.url https://apimesh.xyz; every skill example points at a *.apimesh.xyz host; the card is generated by shared/agent-card.ts in the provider's own MIT repository and the static file it writes is what the apex serves. The contact address in the sibling documents (c@vtxathlete.com) is the operator's personal address hard-coded as CONTACT in that same source file, not a different company. x-evidence: fetched: '2026-09-19' url: https://apimesh.xyz/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 3404 body_parses_as: JSON object with AgentCard shape (name, version, protocolVersion, capabilities, skills, securitySchemes, defaultInputModes, defaultOutputModes) generated_at_in_body: '2026-05-11T21:42:25.881Z' corroborating_probes: - url: https://apimesh.xyz/.well-known/agent.json http_status: 200 note: identical body (diff clean) - url: https://apimesh.xyz/.well-known/apimesh-xyz-negative-control-9c1f4a2e.json http_status: 404 note: negative control — the host is not a path-echoing catch-all - url: https://apimesh.xyz/v1/message:send http_status: 401 note: POST to the declared HTTP+JSON interface root returns a bare "Unauthorized" with WWW-Authenticate Bearer — the apex reverse-proxies unknown paths to the app, which answers 401 for anything it does not route. No A2A JSON-RPC or REST binding responded. - url: https://agentcontext.apimesh.xyz/check http_status: 301 note: skill example endpoint; redirects to agentsmd.apimesh.xyz/check which returns 404 - url: https://agentsmd.apimesh.xyz/check http_status: 404 - url: https://sigdebug.apimesh.xyz/check http_status: 301 note: redirects to stripesig.apimesh.xyz/check which returns 404 - url: https://stripesig.apimesh.xyz/check http_status: 404 note: GET 404; the live stripesig API is POST /check (400 with a validation error when called without a body) agent_card: name: APIMesh description: Pay-per-call API marketplace. 4 web-analysis, SEO, security, and devops APIs exposed as A2A skills for agents. version: 1.0.0 protocol_version: '1.0' documentation_url: https://apimesh.xyz/openapi.json provider: organization: APIMesh url: https://apimesh.xyz supported_interfaces: - url: https://apimesh.xyz protocol_binding: HTTP+JSON protocol_version: '1.1' capabilities: streaming: false push_notifications: false state_transition_history: false extended_agent_card: false default_input_modes: [application/json, text/plain] default_output_modes: [application/json] security_schemes: x402: {type: Payment, protocol: x402, version: '1', networks: [base-mainnet], asset: USDC} mpp: {type: Payment, protocol: mpp, version: draft-ryan-httpauth-payment} apiKey: {type: apiKey, in: header, name: Authorization, purchase_url: https://apimesh.xyz/signup} skill_count: 4 skills: - id: agentcontext example: GET https://agentcontext.apimesh.xyz/check tags: [web-analysis, agentcontext] - id: agentsmd example: GET https://agentsmd.apimesh.xyz/check tags: [web-analysis, agentsmd] - id: sigdebug example: GET https://sigdebug.apimesh.xyz/check tags: [web-analysis, sigdebug] - id: stripesig example: GET https://stripesig.apimesh.xyz/check tags: [devops, stripesig] conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '1.0' preferred_transport: null transport: HTTP+JSON (via supportedInterfaces[0].protocolBinding) hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: false grade_basis: >- Graded on shape against the A2A 1.0.0 hard checks. capabilities is an OBJECT with four boolean fields (pass); protocolVersion "1.0" is present at the top level AND "1.1" on supportedInterfaces[0] (pass); skills is an ARRAY of four fully-populated skills with id, name, description, tags, examples, inputModes and outputModes (pass). defaultInputModes and defaultOutputModes are both declared. preferredTransport is absent because the card uses the 1.0-era supportedInterfaces[].protocolBinding instead, which is spec-current. The grade is a statement about the document's shape only — see deviations for why an agent acting on it today would fail. deviations: - field: skills[].examples observed: all four example endpoints are unreachable note: >- The card was generated 2026-05-11, the day the provider retired its marketplace and pivoted to two "wedge" tools. agentcontext.* and sigdebug.* now 301 to agentsmd.* and stripesig.*, and GET /check is 404 on both surviving hosts (the live APIs are POST /normalize on agentsmd and POST /check on stripesig). A conformant card whose every skill points at a dead endpoint is a discovery document without a callable surface behind it. - field: supportedInterfaces[0].url observed: https://apimesh.xyz with protocolBinding HTTP+JSON note: >- No A2A endpoint answers there. POST /v1/message:send returns 401 "Unauthorized" and POST / returns 405. The card declares an interface the host does not implement; the skills were intended to be called as plain HTTP GETs, not through an A2A task lifecycle. - field: securitySchemes.x402 / securitySchemes.mpp observed: type "Payment" with protocol/networks/asset fields note: >- "Payment" is not an A2A 1.0.0 security scheme type (the spec allows apiKey, http, oauth2, openIdConnect, mutualTLS). This is a provider-invented extension expressing HTTP 402 pay-per-call access via x402 and MPP; readers written to the spec will not recognise it. - field: securitySchemes.apiKey observed: in header, name Authorization, description "Bearer sk_live_… key" note: An apiKey scheme carrying a Bearer token in the Authorization header is really an http/bearer scheme. - field: protocolVersion observed: '"1.0" at the top level, "1.1" on supportedInterfaces[0]' note: Two different protocol versions declared in one card. - field: generated_at observed: non-spec top-level field note: Harmless provenance stamp; it is what dates the card to the day of the pivot. surface_relationship: note: >- APIMesh publishes four machine-discovery documents that describe three different generations of the product. The agent card (4 wedge skills, 2026-05-11) and the root /openapi.json (4 wedge servers, empty paths) describe the post-pivot surface; /.well-known/openapi.json, /llms.txt, /.well-known/ai-plugin.json and /.well-known/x402.json (23 APIs) and the npm MCP server (76 tools) describe the retired marketplace. None of them describes the two endpoints that actually answer today (agentsmd POST /normalize, stripesig POST /check).