generated: '2026-09-19' method: searched source: >- https://agents.muj428.com/openapi.json + https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-layer/openapi.json (info.version), /health (manifest_version), /v1/heartbeat (policy_epoch, accepted receipt versions, revocations feed), https://agents.muj428.com/.well-known/muj428-history.json (dated, source-bound change events), https://agents.muj428.com/AGENTS.md and developer.json (compatibility shims), all fetched 2026-09-19. versioning: scheme: semver-in-manifest + path-prefix v1 current: 1.8.3 notes: >- Every discovery document carries a manifest version (developer.json 1.8.3, mcp.json 1.8.3, agent card 1.8.3, health manifest_version 1.8.3, canonical facade OpenAPI info.version 1.8.3) while the static OpenAPI mirror on agents.muj428.com still reads 1.8.2 and carries 24 operations against the facade's 20 — the two specs are one release apart and differ in shape (the mirror has operationIds and a TrustAction schema; the facade adds /v1/welcome and /v1/payments/capabilities). REST paths are prefixed /v1. There is no version request header. Independent of the manifest version, the Trust Gravity layer publishes a POLICY EPOCH (heartbeat policy_epoch 2026-08-30.1; the X-MUJ428-Policy-Epoch response header is exposed) and a RECEIPT VERSION contract (trust_receipt current_version 1.3, accepted_versions [1.3]), and the facade's MCP server card lists supported MCP protocol versions [2026-07-28, 2025-11-25] (live initialize negotiated 2025-06-18). receipt_versions: current: '1.3' accepted: ['1.3'] source: https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-layer/v1/heartbeat changelog: url: https://agents.muj428.com/.well-known/muj428-history.json artifact: changelog/muj428-com-changelog.yml notes: >- No /changelog page (404). The provider instead publishes a source-bound history document whose policy forbids backdating and requires each event to cite a Git commit or deployment record; four dated events from 2026-08-26 to 2026-08-31 are captured in changelog/. No RSS/Atom feed. status_page: url: null provider: null machine_readable_api: true health_endpoint: https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-layer/health notes: >- No status PAGE (agents.muj428.com/status -> 404, no status.muj428.com found), so no StatusPage pointer is emitted. What exists is a machine-readable production health document: GET /health returns ok, facilitator_ready, ledger_ready, production_ready, continuous_monitoring_status and per-service entries, and GET /v1/heartbeat returns a 5-minute-expiring signal (issued_at/expires_at, poll_after_seconds 300) with component endpoints and a revocations feed (status NO_PUBLIC_REVOCATIONS at probe time). The api-catalog links /health under the "status" relation. An agent can poll these; a human has no incident page. probed: - {url: 'https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-layer/health', status: 200, checked: '2026-09-19'} - {url: 'https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-layer/v1/heartbeat', status: 200, checked: '2026-09-19'} - {url: 'https://wepmhfjzckclvywolrek.supabase.co/functions/v1/trust-gravity/health', status: 200, checked: '2026-09-19'} - {url: 'https://agents.muj428.com/status', status: 404, checked: '2026-09-19'} deprecation: policy_documented: false sunset_headers: false deprecated_operations: [] compatibility_shims: - what: Nested action object in the Trust Reflex request status: legacy — "accepted and normalized before validation"; canonical shape is flat source: OpenAPI /v1/trust description; developer.json legacy_nested_action_object - what: X-A2A-Extensions activation header status: legacy alias of A2A-Extensions source: https://agents.muj428.com/extensions/trust-reflex/v1 activation.legacyHeader - what: /.well-known/agent.json (pre-0.3 agent card path) status: still served, with an older document shape source: probe 2026-09-19 - what: N428 v1 schema (/schemas/n428/v1) status: retained for existing N428/1.x consumers alongside v2 source: AGENTS.md; sitemap.md - what: MCP compatibility facade at https://agents.muj428.com/mcp (1.7.1) status: kept live for registry-driven clients; server card marks canonical false source: https://agents.muj428.com/mcp/server-card compatibilityFacade notes: >- Several backward-compatibility paths are documented, none with a removal date or RFC 8594 Deprecation/Sunset header, and no operation in either OpenAPI carries deprecated: true. No Deprecation pointer is emitted. sla: documented: false notes: No SLA, uptime commitment or support-hours statement was found; the history document's policy explicitly forbids "unsupported uptime claims". pricing_review: cadence: approximately every 60 days; never automatic effective_date: '2026-08-29' review_date: '2026-10-20' source: https://agents.muj428.com/pricing.json