generated: '2026-09-19' method: probed source: https://api.clix.so/.well-known/agent-card.json card: file: a2a/clix-so-agent-card.json v1_variant: a2a/clix-so-agent-card-v1.json discovery: path: /.well-known/agent-card.json canonical: true host: api.clix.so note: >- Served from the API host, which is also the OpenAPI servers[] host and the A2A JSON-RPC host. The apex clix.so and www.clix.so do not serve a card (404). The legacy /.well-known/agent.json returns 404 on api.clix.so, and the negative-control path also 404s, so the 200 is a served document, not a catch-all. The card is version-negotiated by request header: without A2A-Version it returns the 0.3.0 shape (url + preferredTransport + top-level protocolVersion "0.3.0"); with A2A-Version: 1.0 it returns the 1.0 shape (supportedInterfaces[] with per-interface protocolVersion "1.0", securityRequirements, capabilities.extendedAgentCard). Both bodies were saved. Ownership is not in question — provider.organization "Clix", provider.url https://api.clix.so, the docs at docs.clix.so/a2a/* describe exactly this card and endpoint, and the skills are the four Clix operations. A second card on docs.clix.so (see below) is a Mintlify platform artifact, not the provider's agent. x-evidence: fetched: '2026-09-19' url: https://api.clix.so/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 2542 body_parses_as: JSON object with AgentCard shape (name, description, url, provider, version, capabilities, securitySchemes, security, defaultInputModes, defaultOutputModes, skills, preferredTransport, additionalInterfaces, protocolVersion, supportsAuthenticatedExtendedCard) corroborating_probes: - url: https://api.clix.so/.well-known/agent-card.json headers: {A2A-Version: '1.0'} http_status: 200 note: v1-shaped body (supportedInterfaces, securityRequirements, capabilities.extendedAgentCard true, documentationUrl null). Saved as a2a/clix-so-agent-card-v1.json. - url: https://api.clix.so/.well-known/agent.json http_status: 404 - url: https://api.clix.so/.well-known/clix-so-negative-control-4e9b17c2.json http_status: 404 - url: https://api.clix.so/a2a method: GET http_status: 405 note: POST-only endpoint. - url: https://api.clix.so/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tasks/get","params":{"id":"x"}}' http_status: 401 content_type: text/plain response: Missing API key headers_observed: [x-request-id, x-envoy-upstream-service-time, server cloudflare] note: A real, key-gated responder behind Envoy + Cloudflare. No task was sent; the anonymous probe is refused before JSON-RPC dispatch, so the documented -32001 Task Not Found could not be observed. x-request-id is the X-Request-ID correlation header the docs promise on every response. - url: https://docs.clix.so/.well-known/agent-card.json http_status: 200 content_type: application/json note: A DIFFERENT card — name "Clix Documentation", url https://docs.clix.so/, protocolVersion "0.3", preferredTransport HTTP+JSON, capabilities {streaming false, pushNotifications false}, one skill "clix" whose url is /.well-known/agent-skills/clix/skill.md (served, 200, text/markdown). Generated by Mintlify for the docs site (its MCP server exposes the same skill as mintlify://skills/clix). Saved as a2a/clix-so-docs-agent-card.json for the record; not graded as the provider's agent. - url: https://a2aregistry.org note: Clix entered the harvest backlog from the a2a-registry listing; the card above was fetched from the provider's own host. agent_card: name: Clix Agent description: AI Agent for Clix - Send push notifications, manage campaigns, and track user events url: https://api.clix.so/a2a version: 1.0.0 protocol_version: '0.3.0' preferred_transport: JSONRPC additional_interfaces: [{url: 'https://api.clix.so/a2a', transport: JSONRPC}] provider: {organization: Clix, url: 'https://api.clix.so'} capabilities: {streaming: true, push_notifications: true, state_transition_history: true} security_schemes: apiKey: {type: apiKey, in: header, name: X-API-Key, description: Secret API key for A2A authentication} security: [{apiKey: []}] supports_authenticated_extended_card: true default_input_modes: [text/plain, application/json] default_output_modes: [text/plain, application/json] documentation_url: null icon_url: null skill_count: 4 skills: - {id: send-push-notification, name: Send Push Notification, tags: [push, notification, messaging], examples: 2} - {id: trigger-campaign, name: Trigger Campaign, tags: [campaign, marketing, automation], examples: 2} - {id: create-user, name: Create or Update User, tags: [user, crm, profile], examples: 1} - {id: track-event, name: Track User Event, tags: [event, analytics, tracking], examples: 1} skill_invocation: >- SendMessage (v1) / message/send (v0) with a data part {"skill": "", ...params}. Payload shapes per skill are documented at https://docs.clix.so/a2a/skills; each skill writes one named artifact (user-result, event-result, delivery-results, trigger-result). REST bindings in mcp/clix-so-tool-crosswalk.yml. protocol_surface: base_url: https://api.clix.so endpoint: POST /a2a (JSON-RPC 2.0 over HTTPS; SSE for streaming methods) version_header: 'A2A-Version: 1.0 selects V1 method names and shapes; omitted = V0 (0.3) legacy mode' auth: 'X-API-Key: clix_sk_... (secret key only; public keys rejected; project resolved from the key, no project header)' idempotency: 'X-Clix-Idempotency-Key on SendMessage, falling back to message.messageId; replay returns the cached response, in-flight or body-mismatch reuse returns HTTP 409 with JSON-RPC -32603' tracing: X-Request-ID on every response methods_v1: [SendMessage, SendStreamingMessage, GetTask, ListTasks, CancelTask, SubscribeToTask, CreateTaskPushNotificationConfig, GetTaskPushNotificationConfig, ListTaskPushNotificationConfigs, DeleteTaskPushNotificationConfig, GetExtendedAgentCard] methods_v0: [message/send, message/stream, tasks/get, tasks/list, tasks/cancel, tasks/resubscribe, tasks/pushNotificationConfig/set, tasks/pushNotificationConfig/get, tasks/pushNotificationConfig/list, tasks/pushNotificationConfig/delete, agent/getAuthenticatedExtendedCard] task_states: [submitted, working, completed, failed, canceled, rejected, input-required, auth-required] error_codes: 'JSON-RPC -32700..-32603 plus A2A -32001 TaskNotFound, -32002 TaskNotCancelable, -32003 PushNotificationNotSupported, -32004 UnsupportedOperation, -32005 ContentTypeNotSupported, -32006 InvalidAgentResponse, -32007 SkillNotFound' task_webhooks: 'CreateTaskPushNotificationConfig registers an HTTPS callback; Clix POSTs a JSON-RPC request with method tasks/pushNotification, sends Authorization: and X-A2A-Token: when configured, and rejects loopback/link-local/site-local destinations' docs: - https://docs.clix.so/a2a/overview - https://docs.clix.so/a2a/quickstart - https://docs.clix.so/a2a/api-reference - https://docs.clix.so/a2a/advanced-features - https://docs.clix.so/a2a/skills - https://docs.clix.so/a2a/version-compatibility conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '0.3.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded on the default (unheadered) body, which is what a client that has not yet negotiated a version receives. capabilities is an OBJECT (streaming, pushNotifications, stateTransitionHistory — all true); protocolVersion is present at the top level ("0.3.0"); skills is an ARRAY of four fully populated skills (id, name, description, tags, examples). All three optional discriminators are present. The card also declares securitySchemes + security, provider, additionalInterfaces and supportsAuthenticatedExtendedCard. The v1 body served under A2A-Version: 1.0 is a correctly shaped 1.0 card (supportedInterfaces[] with protocolBinding JSONRPC and protocolVersion "1.0"; securityRequirements; capabilities.extendedAgentCard) — it has no TOP-LEVEL protocolVersion because 1.0 moves that field per interface, which is by design and not a deviation. Clix is one of the few providers serving both shapes from one path. deviations: - field: skills[].inputModes / outputModes / security observed: present but EMPTY arrays on every skill note: Optional per-skill fields; empty arrays fall back to the card defaults (text/plain, application/json). Harmless, but a reader checking `inputModes.length` sees zero. - field: documentationUrl observed: absent in the 0.3.0 body; explicitly null in the 1.0 body note: The A2A docs live at https://docs.clix.so/a2a/overview and are not linked from the card. - field: iconUrl / signatures observed: absent note: No JWS signature block; authenticity rests on TLS to api.clix.so. - field: v1 supportedInterfaces[0].tenant observed: '"" (empty string)' note: A serialised-empty field from the protobuf-generated card; not a fault. - field: v1 securitySchemes.apiKey observed: 'the oneof is serialised with every alternative present and null (httpAuthSecurityScheme, oauth2SecurityScheme, openIdConnectSecurityScheme, mtlsSecurityScheme all null) alongside apiKeySecurityScheme' note: Valid JSON and unambiguous, but strict readers that reject null members will need to tolerate it. - field: provider.url observed: https://api.clix.so note: Points at the API host rather than the company site https://clix.so. Same organisation; recorded for readers that dereference provider.url as a homepage. surface_relationship: note: >- Clix separates its agent protocols by job: MCP (a stdio docs server and a Mintlify docs endpoint) gives an assistant context; A2A executes work. The four A2A skills are projections of four of the eleven REST operations at https://api.clix.so (users, events, messages:send, campaigns:trigger) — see mcp/clix-so-tool-crosswalk.yml. The A2A layer adds what REST lacks: idempotency keys, task state, SSE streaming, cancellation and task webhooks.