generated: '2026-09-19' method: probed source: https://optionsahoy.com/.well-known/agent-card.json card: file: a2a/optionsahoy-com-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: optionsahoy.com note: >- Served from the apex host, which is also the OpenAPI servers[] host, the MCP host and the A2A JSON-RPC host — OptionsAhoy runs everything on one Cloudflare Pages origin. The legacy /.well-known/agent.json returns a byte-identical copy (5,042 bytes, same content), and a plain GET on the JSON-RPC endpoint https://optionsahoy.com/a2a returns the card as well. www.optionsahoy.com 301s every /.well-known/* path to the apex. A negative-control path (/.well-known/apievangelist-negative-control-7f3a9c.json) returns HTTP 404, so the 200 on agent-card.json is a served document, not a catch-all. Ownership is not in question: the card's provider.organization is "AlphaLatitude Inc." with provider.url https://optionsahoy.com, the OpenAPI at the same host names AlphaLatitude Inc. as info.contact, and the Terms of Use say the site is operated by AlphaLatitude Inc., a California corporation. x-evidence: fetched: '2026-09-19' url: https://optionsahoy.com/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 5042 etag: '"610d1297fc1a3c5e8f65246ac812f3cf"' body_parses_as: JSON object with AgentCard shape (protocolVersion, name, description, url, preferredTransport, version, provider, capabilities, defaultInputModes, defaultOutputModes, documentationUrl, iconUrl, skills) corroborating_probes: - url: https://optionsahoy.com/.well-known/agent.json http_status: 200 note: Legacy pre-0.3 path; byte-identical to the canonical card. - url: https://www.optionsahoy.com/.well-known/agent-card.json http_status: 301 note: Redirects to https://optionsahoy.com/.well-known/agent-card.json. - url: https://optionsahoy.com/a2a http_status: 200 note: GET on the declared JSON-RPC endpoint returns the agent card (application/json, 4,097 bytes minified). - url: https://optionsahoy.com/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"message/send","params":{}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32602,"message":"Invalid params: expected params.message.parts to be an array."}}' note: A real JSON-RPC 2.0 responder validating the A2A message shape. No message was sent and no calculator was run. - url: https://optionsahoy.com/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tasks/get","params":{"id":"apievangelist-nonexistent-probe"}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32001,"message":"Task not found: this agent completes every call synchronously and does not persist tasks. Send \"message/send\" (or legacy \"tasks/send\") and read the result directly."}}' note: TaskNotFoundError (-32001) is the A2A-defined code; the message documents that the agent is synchronous and stateless. - url: https://optionsahoy.com/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"agent/getAuthenticatedExtendedCard","params":{}}' http_status: 200 note: Implemented — returns the same public card as the result (there is no extended card because there is no authentication). - url: https://optionsahoy.com/icon.png http_status: 404 note: The card's iconUrl does not resolve. - url: https://optionsahoy.com/for-agents http_status: 200 note: The card's documentationUrl resolves to the provider's agent integration page. - url: https://a2aregistry.org note: The card was first seen among the 415 agents listed on a2aregistry.org (fetched 2026-09-19), which is how this provider entered the harvest backlog. The registry listing was the lead; the card above was fetched directly from the provider's host. agent_card: name: OptionsAhoy Equity Planner description: >- Answers equity-compensation planning questions by calling the OptionsAhoy calculators: incentive stock option and alternative minimum tax (AMT) exercise timing, non-qualified stock options, restricted stock unit sell-versus-hold, qualified small business stock (QSBS), single-stock concentration, protective-put hedging, funding a cash goal from equity, and choosing which vested RSU lots to sell first. The financial math is deterministic and verifiable (https://optionsahoy.com/verification); OptionsAhoy's API is keyless. Send a message with a data part {"skill":"","input":{...}} to run a calculator. url: https://optionsahoy.com/a2a version: 1.10.2 protocol_version: '0.3.0' preferred_transport: JSONRPC provider: organization: AlphaLatitude Inc. url: https://optionsahoy.com capabilities: streaming: false push_notifications: false state_transition_history: false default_input_modes: [text/plain] default_output_modes: [text/plain] security_schemes: null security: null documentation_url: https://optionsahoy.com/for-agents icon_url: https://optionsahoy.com/icon.png skill_count: 8 skills: - {id: amt_iso_optimize, name: ISO exercise and AMT optimizer, tags: [iso, amt, exercise-timing, equity-compensation, tax]} - {id: nso_calculate, name: NSO exercise tax, tags: [nso, non-qualified-stock-options, tax]} - {id: rsu_sell_vs_hold, name: RSU sell-versus-hold, tags: [rsu, vesting, capital-gains]} - {id: concentration_analyze, name: Single-stock concentration analysis, tags: [concentration, single-stock-risk, hedging]} - {id: protective_put_price, name: 'Protective put, collar, and put spread pricing', tags: [hedging, protective-put, zero-cost-collar, put-spread, options-pricing]} - {id: qsbs_check, name: QSBS Section 1202 check, tags: [qsbs, section-1202, tax-exclusion]} - {id: equity_funding_plan, name: Fund a cash goal from equity, tags: [equity-funding, liquidity, planning]} - {id: rsu_lot_optimize, name: Pick which RSU lots to sell first, tags: [rsu-lot-order, diversification, planning]} skill_invocation: >- Every skill is run the same way — a message whose DataPart is {"skill":"","input":{...}} — and every skill id is exactly the name of the matching MCP tool and maps to one REST operation (see mcp/optionsahoy-com-tool-crosswalk.yml). Each skill carries one example question; none declares its own inputModes/outputModes, so the text/plain defaults apply even though the input is structured JSON. conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '0.3.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications and stateTransitionHistory all false. protocolVersion is present at the top level (pass), declared as "0.3.0". skills is an ARRAY (pass) of eight fully-populated skills, each with id, name, description, tags and examples. All three optional discriminators are present: preferredTransport (JSONRPC), defaultInputModes and defaultOutputModes (both text/plain). The provider block, a documentationUrl and an iconUrl are also present. This is a 0.3.0-shaped card — top-level url + preferredTransport + protocolVersion rather than the 1.0.0 supportedInterfaces[] block — and it is internally consistent with that revision. deviations: - field: protocolVersion / url / preferredTransport observed: 0.3.0 top-level triple; no supportedInterfaces[] or additionalInterfaces[] note: >- Valid for A2A 0.3.0, which the card declares. A reader written against A2A 1.0.0 looks for supportedInterfaces[].protocolBinding and will not find it. Recorded because both card shapes coexist in the catalog, not as a fault. - field: securitySchemes / security observed: absent note: >- Consistent with the surface — the endpoint is keyless by design ("OptionsAhoy's API is keyless" in the card description; "No API key, no OAuth" on the for-agents page). An absent securitySchemes here means open access, not an undocumented gate. - field: iconUrl observed: https://optionsahoy.com/icon.png returns HTTP 404 note: The only dead link in the card. - field: defaultInputModes observed: text/plain, while the description instructs callers to send a DataPart with structured JSON note: A DataPart is JSON by definition; declaring application/json (or per-skill inputModes) would let a client discover that without reading prose. - field: skills[].inputModes / outputModes / security observed: absent on every skill note: Optional per-skill fields; the card relies on the top-level defaults. - field: signatures observed: absent note: No JWS signature block, so the card's authenticity rests on TLS to optionsahoy.com. surface_relationship: note: >- OptionsAhoy publishes three agent surfaces on one host and they are projections of the same eight calculators, not of one another. A2A: eight skills at https://optionsahoy.com/a2a. MCP: eight tools of the same names at https://optionsahoy.com/mcp, plus nine resources and eight prompts the A2A card does not carry. REST: eleven operations at https://optionsahoy.com, eight of which are the calculators the skills and tools map onto (the other three are discovery, usage stats and a badge). The for-agents page documents the A2A surface explicitly ("Agent-to-agent discovery through a live Agent2Agent (A2A) Agent Card at /.well-known/agent-card.json ... over JSON-RPC at /a2a (the message/send method)").