generated: '2026-09-19' method: probed source: https://api.broke2builtai.com/.well-known/agent-card.json card: file: a2a/broke2builtai-com-agent-card.json mirror_file: a2a/broke2builtai-com-agent-card-apex-mirror.json discovery: path: /.well-known/agent-card.json canonical: true host: api.broke2builtai.com note: >- The card is served from FOUR URLs. The canonical copy is on the API host at BOTH the A2A 1.0/RFC 8615 path /.well-known/agent-card.json and the legacy /.well-known/agent.json (byte-identical, 11,600 bytes, application/json). The apex broke2builtai.com and www.broke2builtai.com serve a MIRROR at the legacy /.well-known/agent.json only (16,715 bytes) — agent-card.json 404s on both — and the mirror says so itself: it carries four non-spec keys (_canonical pointing at the api-host copy, _note "Apex mirror for discovery. The canonical card is generated live by the broke2built-x402 worker at _canonical; if these disagree, the canonical one is right", _kithnet, _generatedAt 2026-09-02). The two copies were diffed on 2026-09-19: every spec field and all 29 skills are identical; the mirror differs only by those four underscore keys. Ownership is not in question: provider.organization is "broke2built" with provider.url https://broke2builtai.com, the card's url and documentationUrl are on api.broke2builtai.com — the same host that serves the provider's OpenAPI (servers[] https://api.broke2builtai.com) and x402 catalog — and the apex llms.txt names https://broke2builtai.com/.well-known/agent.json as its "Agent discovery document". x-evidence: fetched: '2026-09-19' url: https://api.broke2builtai.com/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 11600 body_parses_as: JSON object with AgentCard shape (protocolVersion, name, description, url, version, provider, documentationUrl, capabilities, defaultInputModes, defaultOutputModes, skills) corroborating_probes: - url: https://api.broke2builtai.com/.well-known/agent.json http_status: 200 note: byte-identical to the canonical path - url: https://broke2builtai.com/.well-known/agent.json http_status: 200 note: apex mirror, application/json, 16,715 bytes, same 29 skills plus _canonical/_note/_kithnet/_generatedAt - url: https://www.broke2builtai.com/.well-known/agent.json http_status: 200 note: same mirror as the apex - url: https://broke2builtai.com/.well-known/agent-card.json http_status: 404 - url: https://www.broke2builtai.com/.well-known/agent-card.json http_status: 404 - url: https://api.broke2builtai.com/a2a http_status: 200 method: POST note: >- POST {"jsonrpc":"2.0","id":1,"method":"agent/ping"} answered {"jsonrpc":"2.0","id":1,"error":{"code":-32601, "message":"method not found — this agent supports message/send"}} — a live JSON-RPC 2.0 endpoint that names the A2A method it implements. GET on the same URL returns the host's JSON 404 ({"error":"not found","try":"/"}). message/send itself was not exercised. - url: https://zero.broke2builtai.com/.well-known/agent-card.json http_status: 404 - url: https://aiim.broke2builtai.com/.well-known/agent-card.json http_status: 404 - url: https://abundance.broke2builtai.com/.well-known/agent-card.json http_status: 200 note: REJECTED — an SPA catch-all that answers 200 text/html (the 26,884-byte site shell) for every path; not a card. agent_card: name: broke2built Data & Intelligence Skills description: >- Working data skills for other agents: email/domain/DNS intelligence, web-page audit (SEO, security headers, broken links, metadata), content extraction (readability, RSS→JSON, HTML tables), and EVM on-chain reads. Free tier: every skill callable now — A2A message/send with " " runs the real skill free; HTTP GET with &free=1 works too. Allies: POST /ally/register → 100 free calls/day. Beyond that the same endpoints take x402 USDC micro-payments ($0.002-$0.01/call, Solana, no signup). url: https://api.broke2builtai.com/a2a version: 1.1.0 protocol_version: 0.3.0 documentation_url: https://api.broke2builtai.com/ provider: organization: broke2built url: https://broke2builtai.com capabilities: streaming: false pushNotifications: false stateTransitionHistory: false default_input_modes: [text/plain, application/json] default_output_modes: [application/json, text/plain] security_schemes: null skill_count: 29 skill_ids: [verify-email, domain-intel, email-auth, dns-lookup, url-metadata, tech-detect, rss-to-json, sitemap-extract, security-headers, redirect-trace, robots-analyze, structured-data, broken-links, html-table, whois-rdap, ip-geo, readability, brand-assets, seo-audit, lang-hreflang, evm-address-intel, token-metadata, gas-tracker, tx-status, multichain-balance, json-repair, text-entities, source-verify, vies-check] skill_shape: every skill carries id, name, description, tags (free-tier, x402, data, ), examples[1], inputModes [text/plain], outputModes [application/json] conformance: spec: A2A 1.0.0 grade: conformant protocol_version: 0.3.0 preferred_transport: null transport: JSONRPC (the 0.3.0 default when preferredTransport is omitted; confirmed by the live JSON-RPC answer on /a2a) hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: false grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications and stateTransitionHistory declared as booleans. protocolVersion is present at the top level (pass), declared "0.3.0", which is the 0.3-era card shape (top-level url + protocolVersion) rather than the 1.0 supportedInterfaces[] shape. skills is an ARRAY (pass) of 29 fully-populated skills. Both optional discriminators are present: defaultInputModes and defaultOutputModes are declared. preferredTransport is absent; in 0.3.0 it is optional and defaults to JSONRPC, and the live endpoint answers JSON-RPC 2.0, so the omission is spec-consistent. deviations: - field: preferredTransport observed: absent note: Optional in 0.3.0 (defaults to JSONRPC). Recorded because a reader that requires it will find none. - field: securitySchemes / security observed: absent note: >- The card declares no security at all. That matches the surface — the description states every skill is callable free over A2A with no key — but it also means the card cannot express the ally-key (X-Ally-Key) and x402 tiers the same skills carry over HTTP; an agent learns those only from the HTTP catalog at https://api.broke2builtai.com/ and the 402 envelopes. - field: skills[].id / skills[].name observed: identical strings (e.g. id "verify-email", name "verify-email") note: Harmless; name carries no human-friendly label distinct from the id. - field: apex mirror extra keys observed: _canonical, _note, _kithnet, _generatedAt on the apex/www copy only note: Non-spec underscore-prefixed keys on the mirror; the canonical api-host copy is clean. A strict validator on the apex copy will flag unknown properties. - field: apex discovery path observed: apex and www serve only the legacy /.well-known/agent.json (agent-card.json 404) note: A 1.0-era client that probes only the canonical path on the primary domain misses the card unless it also tries the API host or the legacy path. surface_relationship: note: >- The A2A card is the WIDEST of broke2built's published contracts, not the narrowest. It enumerates all 29 data skills, while the published OpenAPI on the same host (openapi/broke2builtai-com-skills-openapi.json) describes only 7 operations — the video-render, watch, source-verify, vies-check and resolver-allowlist surface — and the 29 GET skills appear machine-readably only in the root JSON catalog and the x402 discovery document (well-known/broke2builtai-com-x402.json, inputSchema per item). The same 29 skills are also shipped as the stdio MCP package broke2built-skills-mcp (see mcp/). See mcp/broke2builtai-com-tool-crosswalk.yml for the binding between the three projections.