generated: '2026-09-19' method: probed source: https://movehome.org/.well-known/agent-card.json card: file: a2a/movehome-org-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: movehome.org note: >- Served from the apex host, which is also the A2A JSON-RPC host (/api/a2a), the MCP host (/mcp) and the RAIA Portal Feed API host — one Vercel-hosted Next.js origin (region lhr1). The same 2,090-byte body is served byte-for-byte at the canonical /.well-known/agent-card.json, at the legacy /.well-known/agent.json (the provider's own docs call the legacy path primary and the canonical one an "alias"), at GET /api/a2a and at /api/agent-card. www.movehome.org serves the identical body without redirecting. This is not an SPA catch-all: every other /.well-known/* path returns a real 404 (the Next.js not-found page, 7,664 bytes, text/html) and the card is application/json. Ownership is not in question — the card's provider.organization is "Move Home Organisation CIC" with provider.url https://movehome.org, the homepage footer carries the same company name and Companies House number 17202438, and the card is generated by src/lib/a2a/card.ts in the provider's own open-source repository (github.com/MoveHome/MoveHome.Org). x-evidence: fetched: '2026-09-19' url: https://movehome.org/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 2090 body_parses_as: JSON object with AgentCard shape (protocolVersion, name, description, url, preferredTransport, version, provider, documentationUrl, capabilities, defaultInputModes, defaultOutputModes, skills) corroborating_probes: - url: https://movehome.org/.well-known/agent.json http_status: 200 note: Legacy pre-0.3 path. Byte-identical to the canonical document. - url: https://www.movehome.org/.well-known/agent-card.json http_status: 200 note: Identical body on the www host; no redirect. - url: https://movehome.org/api/a2a method: GET http_status: 200 note: The declared JSON-RPC endpoint returns the agent card on GET, as the provider's integrator guide documents. - url: https://movehome.org/api/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"message/send","params":{"message":{"kind":"message","role":"user","messageId":"ae-probe-1","parts":[{"kind":"data","data":{"skill":"search_properties","params":{"un_locode":"GBLON","limit":2}}}]}}}' http_status: 200 response_summary: 'A2A Task, status.state "completed", status.message "Found 21 listings; returning 2.", one artifact named search_results carrying total 21 and two RAIA listing cards (prop-gb-rlf-001141, prop-gb-rlf-000528). Response headers: x-ratelimit-limit 60, x-ratelimit-remaining 59, x-ratelimit-reset, access-control-allow-origin *.' note: A read-only, anonymous skill invocation. No enquiry was created and no personal data was sent. - url: https://movehome.org/api/a2a method: POST body: '{"jsonrpc":"2.0","id":11,"method":"tasks/get","params":{"id":"x"}}' http_status: 200 response: '{"jsonrpc":"2.0","id":11,"error":{"code":-32001,"message":"Task not found: x"}}' note: The A2A-defined TaskNotFoundError; tasks are not persisted in v1, as the integrator guide states. - url: https://movehome.org/api/a2a method: POST body: '{"jsonrpc":"2.0","id":9,"method":"message/stream","params":{}}' http_status: 200 response: '{"jsonrpc":"2.0","id":9,"error":{"code":-32004,"message":"Unsupported operation: Method message/stream requires streaming capability."}}' note: Consistent with capabilities.streaming false. - url: https://movehome.org/.well-known/jwks.json http_status: 200 response: '{"keys":[]}' note: The JWKS the provider's skills.md names for optional ES256 card-signature verification is served but EMPTY, and the card carries no signatures[] block; card authenticity currently rests on TLS alone. - url: https://a2aregistry.org note: The card was first seen as one of 415 agents listed on a2aregistry.org (fetched 2026-09-19, author "Move Home Organisation CIC", task_conformance WORKING, uptime 100), which is how this provider entered the harvest backlog. MoveHome also lists itself in its own registry at https://movehome.org/api/registry/v1/agents/move-home-organisation-cic (signature_verified false, domain_verified false, is_healthy null). agent_card: name: MoveHome.org Property Agent description: >- Agent-to-agent access to the MoveHome.org property catalogue. Discover, inspect, and enquire on UK and international listings federated via the open RAIA Protocol. Read-only search and listing retrieval are anonymous; enquiries are forwarded to the source estate agent. url: https://movehome.org/api/a2a version: 0.1.0 protocol_version: 0.3.0 preferred_transport: JSONRPC provider: organization: Move Home Organisation CIC url: https://movehome.org documentation_url: https://movehome.org/skills.md capabilities: streaming: false push_notifications: false state_transition_history: false default_input_modes: [application/json, text/plain] default_output_modes: [application/json, text/plain] security_schemes: null security: null icon_url: null signatures: null skill_count: 3 skills: - {id: search_properties, name: Search properties, tags: [property, search, real-estate, lettings, sales], write: false} - {id: get_property, name: Get property, tags: [property, detail, real-estate], write: false} - {id: create_enquiry, name: Create enquiry, tags: [property, enquiry, lead, transact, viewing], write: true, note: 'Records an enquiry and forwards it to the source estate agent — a real human receives it. Requires enquirer name, email and a message.'} skill_invocation: >- A2A messages are free-form, so MoveHome fixes one convention: message/send with a single DataPart {"skill": "", "params": {...}}. The reply is a terminal Task; the structured result is in result.artifacts[0].parts[0].data (artifact names search_results, property, enquiry_receipt) and the human summary in result.status.message.parts[0].text. Skill-level failures (bad params, unknown listing, unknown skill) come back as a Task with status.state "failed" over HTTP 200, not as a JSON-RPC error. conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '0.3.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications and stateTransitionHistory all false. protocolVersion is present at the top level (pass), declared as "0.3.0". skills is an ARRAY (pass) of three fully-populated skills, each with id, name, description, tags and examples. All three optional discriminators are present: preferredTransport (JSONRPC), defaultInputModes and defaultOutputModes (application/json and text/plain). The card is produced by the @a2a-js/sdk 0.3.x server library, which the provider's package.json declares, and the live endpoint behaves as the card says (no streaming, no task persistence, JSON-RPC 2.0). deviations: - field: protocolVersion / url / preferredTransport observed: 0.3.0 top-level triple; no supportedInterfaces[] or additionalInterfaces[] note: >- Valid for A2A 0.3.0, which the card declares. A reader written against A2A 1.0.0 looks for supportedInterfaces[].protocolBinding and will not find it. Recorded because both card shapes coexist in the catalog, not as a fault. - field: securitySchemes / security observed: absent note: >- The card declares no authentication scheme, and none is needed: the provider's skills.md states "Auth: none (anonymous)" for every skill including create_enquiry. The only gate on the write skill is rate limiting and duplicate suppression, which the card does not express. - field: signatures observed: absent note: >- skills.md says the card "may carry a JWS signature (signatures[])" verifiable against /.well-known/jwks.json (ES256). The served card carries none and the JWKS is {"keys":[]}. The signing code exists in the provider's repository (src/lib/a2a/card-signing.ts) but is not active in production. - field: iconUrl observed: absent note: Optional. The provider serves brand assets at /branding/icon.png and /branding/icon.svg but does not reference them from the card. - field: skills[].inputModes / outputModes / security observed: absent on every skill note: Optional per-skill fields; the card relies on the defaults. - field: skills[].description vs live behaviour observed: search_properties describes bedrooms and maximum price filters; the live MCP inputSchema for the same skill omits bedrooms_max, features and offset, which skills.md documents for the A2A skill note: A divergence between the A2A skill (richer, per skills.md) and its MCP twin (narrower), not a card fault. See mcp/movehome-org-tool-crosswalk.yml. surface_relationship: note: >- MoveHome publishes four machine surfaces on one host and they are projections of the same public listing mirror, not of one another. A2A: three skills at https://movehome.org/api/a2a (the only agent surface with the create_enquiry write). MCP: two read-only property tools at https://movehome.org/mcp and three registry tools at https://movehome.org/api/registry/mcp. REST: an unauthenticated A2A-registry API under /api/registry/v1 (no OpenAPI published) and an OAuth2-gated RAIA Portal Feed API under /api/raia/portal/v1 for CRMs pushing listings IN, whose contract is the RAIA Protocol's published OpenAPI 3.1.0 (see openapi/). MoveHome also runs a public registry OF real-estate A2A agents and lists its own card in it.