generated: '2026-09-19' method: probed source: https://api.rosentic.com/.well-known/agent-card.json card: file: a2a/rosentic-com-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: api.rosentic.com note: >- Served from the API host, api.rosentic.com — which is also the hosted MCP host, the OAuth authorization server and the A2A JSON-RPC host. The apex rosentic.com is a Next.js catch-all that answers HTTP 200 with the same 8,425-byte marketing shell for EVERY unknown path, including both agent-card paths and a negative-control path that cannot exist, so nothing on the apex counts. On api.rosentic.com the legacy /.well-known/agent.json returns a byte-identical copy of the same card, a negative-control path (/.well-known/rosentic-com-negative-control-9c1e4a7b.json) returns the host's real JSON 404 ({"error":"not_found"}, 21 bytes), and the API root document at https://api.rosentic.com/ names agent_card_url https://api.rosentic.com/.well-known/agent.json itself. HEAD on the card path returns 404; only GET serves it. Ownership is not in question: provider.organization is "Rosentic" with provider.url https://rosentic.com, x-rosentic.github points at github.com/Rosentic/rosentic-action, and the skills describe the product the website, llms.txt and PyPI package describe. x-evidence: fetched: '2026-09-19' url: https://api.rosentic.com/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 4669 body_parses_as: JSON object with AgentCard shape (name, url, version, protocolVersion, capabilities, skills, provider, defaultInputModes, defaultOutputModes, authentication) corroborating_probes: - url: https://api.rosentic.com/.well-known/agent.json http_status: 200 note: Legacy pre-0.3 path; byte-identical (4,669 bytes) to the canonical path. - url: https://api.rosentic.com/.well-known/rosentic-com-negative-control-9c1e4a7b.json http_status: 404 note: Negative control — proves api.rosentic.com does not catch-all /.well-known/*. - url: https://rosentic.com/.well-known/agent-card.json http_status: 200 note: The apex answers text/html, 8,425 bytes — the same body as https://rosentic.com/ and every other unknown path. An SPA shell, not a card. Discarded. - url: https://api.rosentic.com/a2a http_status: 404 note: GET on the declared endpoint returns the host's generic JSON 404. The endpoint is POST-only. - url: https://api.rosentic.com/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tasks/get","params":{"id":"apievangelist-nonexistent-probe"}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32004,"message":"Task not found"}}' note: A live JSON-RPC responder at the card's url. No message was sent and no scan was requested. Note the code is -32004, not the A2A-specified -32001 TaskNotFoundError — recorded under deviations. - url: https://api.rosentic.com/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"agent/getAuthenticatedExtendedCard","params":{}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"Method not found"}}' note: The extended-card method is not implemented, consistent with the card not declaring supportsAuthenticatedExtendedCard. - url: https://a2aregistry.org note: The card was first seen as one of 415 agents listed on a2aregistry.org (fetched 2026-09-19, author "Rosentic"), which is how this provider entered the harvest backlog. The registry listing was the lead; the card above was fetched directly from the provider's host. agent_card: name: Rosentic description: >- Cross-branch semantic conflict detection engine. Checks whether active git branches are compatible before merge. Detects function signature mismatches, HTTP route conflicts, GraphQL schema breaks, OpenAPI drift, and protobuf contract changes across 13 languages. Deterministic AST analysis, not AI review. url: https://api.rosentic.com/a2a version: 1.0.0 protocol_version: '0.3.0' preferred_transport: null provider: organization: Rosentic url: https://rosentic.com capabilities: streaming: true push_notifications: false state_transition_history: true default_input_modes: [application/json, text/plain] default_output_modes: [application/json, text/plain] authentication: schemes: - {scheme: none, description: 'Public repos, 3 requests/hour per IP, 250MB repo cap'} - {scheme: bearer, description: 'Rosentic API key for private repos, higher limits, Merge Index access'} security_schemes: null security: null documentation_url: null icon_url: null skill_count: 5 skills: - {id: assess_integration_posture, name: Assess Integration Posture, tags: [git, ci-cd, merge-safety, cross-branch-conflict, parallel-agents, agent-verification], input_modes: [application/json, text/plain], output_modes: [application/json]} - {id: check_conflicts, name: Check Cross-Branch Conflicts, tags: [static-analysis, cross-branch-conflict, merge-safety, signature-change, parallel-agents, pull-request], input_modes: [application/json, text/plain], output_modes: [application/json, text/plain]} - {id: explain_conflict, name: Explain Conflict, tags: [code-review, cross-branch-conflict, conflict-detection, merge-safety, pull-request], input_modes: [application/json], output_modes: [application/json, text/plain]} - {id: list_branches, name: List Branches, tags: [git, parallel-agents, branch-compatibility, agent-verification], input_modes: [application/json, text/plain], output_modes: [application/json]} - {id: merge_index, name: Merge Index, tags: [code-quality, ci-cd, merge-safety, merge-verification, parallel-agents], input_modes: [application/json], output_modes: [application/json], gated: 'Requires API key with Merge Index entitlement (Team $99/mo and above per x-rosentic.pricing)'} skill_semantics: >- Four of the five skills serve STORED scan results ("Scans run via the Rosentic GitHub Action or local MCP; this endpoint serves stored results"). The A2A surface is a read projection of scans that ran elsewhere; it does not itself run the engine on a repository. x_rosentic: rate_limits: unauthenticated: 3 requests/hour per IP, 250MB repo cap, public repos only authenticated: Higher limits, private repo access, Merge Index access api_key_onboarding: https://api.rosentic.com/onboard github: https://github.com/Rosentic/rosentic-action license: BUSL-1.1 languages: 13 detection_layers: {L1: Function signature mismatches (same-language), L2: HTTP route contract conflicts (cross-language), L3a: GraphQL schema breaks, L3b: OpenAPI specification drift, L3c: Protobuf/gRPC contract changes} pricing: {free: 'Public repos, check_conflicts, explain_conflict, list_branches, assess_integration_posture', team: '$99/mo - Merge Index, private repos, higher limits', growth: '$499/mo - Org-wide Merge Index, cross-repo analysis'} conformance: spec: A2A 1.0.0 grade: near-conformant protocol_version: '0.3.0' preferred_transport: null hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: false grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications and stateTransitionHistory. protocolVersion is present at the top level (pass), declared as "0.3.0". skills is an ARRAY (pass) of five skills, each with id, name, description, tags, examples, inputModes and outputModes. defaultInputModes and defaultOutputModes are present. The card omits preferredTransport, one of the three optional discriminators, so it is near-conformant rather than conformant: no hard check fails, an optional field is missing. It is a 0.3.0-shaped card (top-level url + protocolVersion) rather than the 1.0.0 supportedInterfaces[] block. deviations: - field: preferredTransport observed: absent note: >- A2A 0.3.0 defaults the transport to JSONRPC when preferredTransport is omitted, and the endpoint does answer JSON-RPC 2.0, so a client can proceed — but the card does not say so. This is the one optional field whose absence sets the grade. - field: authentication (legacy) vs securitySchemes / security observed: 'authentication.schemes[] with {scheme: none} and {scheme: bearer}; no securitySchemes map, no security[] requirements' note: >- The card carries the PRE-0.3 authentication block rather than the 0.3.0/1.0.0 securitySchemes + security pair. A 0.3.0 reader looking for securitySchemes finds nothing and must fall back to the legacy field; a strict 1.0.0 reader sees an unauthenticated card. The information is real (anonymous access with a per-IP limit, or a bearer API key) and is echoed by the OAuth metadata on the same host for the MCP resource — it is in the wrong field for the protocol version the card declares. - field: tasks/get error code observed: -32004 "Task not found" for an unknown task id note: >- The A2A specification assigns TaskNotFoundError the code -32001 (and -32004 to UnsupportedOperationError). The responder is live and JSON-RPC-correct but uses a non-standard code for this condition, so a client switching on the numeric code will misclassify a missing task. - field: protocolVersion / url observed: 0.3.0 top-level pair; no supportedInterfaces[] or additionalInterfaces[] note: Valid for A2A 0.3.0, which the card declares. Recorded because both card shapes coexist in the catalog, not as a fault. - field: documentationUrl / iconUrl / signatures observed: absent note: >- No documentation link (the docs live at https://rosentic.com/docs and the remote-MCP docs the OAuth metadata points at, github.com/Rosentic/rosentic/blob/main/docs/remote.md, 404 anonymously) and no JWS signature block, so the card's authenticity rests on TLS to api.rosentic.com. - field: x-rosentic observed: a vendor extension object carrying rate limits, onboarding URL, license, languages, detection layers and pricing note: >- Not a defect. It is the only place the anonymous A2A rate limit (3 requests/hour per IP, 250MB repo cap) is published, and it is the source for rate-limits/rosentic-com-rate-limits.yml. surface_relationship: note: >- Rosentic publishes three agent-facing surfaces on api.rosentic.com and they are projections of the same scan ledger, not of one another. A2A: five skills at https://api.rosentic.com/a2a, four free on public repos and one (merge_index) key-gated. MCP (remote): three tools — run_status, which_lane, get_verdict — at https://api.rosentic.com/mcp behind OAuth 2.1 with PKCE and dynamic client registration; tools/list is auth-gated (see mcp/rosentic-com-mcp.yml). MCP (local stdio): nine tools in the rosentic-mcp PyPI package, six fully offline. REST: a documented GET /v1/feed/rules (Bearer key) whose anonymous probe returns the host's 404 rather than a 401. No OpenAPI is published for any of them, so there is no tool crosswalk to derive; skill ids check_conflicts, explain_conflict and list_branches are the same names as the local MCP tools, and get_verdict is shared by local and remote MCP.