generated: '2026-09-19' method: probed source: https://scvd.store/.well-known/agent-card.json card: file: a2a/scvd-store-agent-card.json discovery: path: /.well-known/agent-card.json canonical: true host: scvd.store also_served_at: - path: /.well-known/agent.json status: 200 note: The pre-0.3 legacy path serves byte-identical content (3,818 bytes, diff clean). - path: /.well-known/a2a.json status: 200 note: A third alias the provider's own RFC 9727 api-catalog and llms.txt name as "the agent card"; same bytes. note: >- Served from the apex host, which is also the OpenAPI servers[] host, all three MCP endpoints and the A2A JSON-RPC endpoint (https://scvd.store/a2a). www.scvd.store 301s every /.well-known/* path to the apex. A negative-control path (/.well-known/scvd-store-negative-control-9f3ab1c2.json) returns the site's real JSON 404 (711 bytes, application/json), as do /.well-known/acp.json and /.well-known/aauth-resource.json, so the 200s are served documents and not a catch-all. Ownership is not in question: provider.organization is "Record Creative Co. LLC" with provider.url https://scvd.store; the OpenAPI at the same host says "Operated by Record Creative Co. LLC" in info.description with contact sean@recordcreativeco.com; the ai-plugin.json carries the same contact; /.well-known/trust.json names the legal entity and its location (Oak City, North Carolina). x-evidence: fetched: '2026-09-19' url: https://scvd.store/.well-known/agent-card.json http_status: 200 content_type: application/json body_bytes: 3818 body_parses_as: JSON object with AgentCard shape (name, url, version, protocolVersion, capabilities, skills, provider, preferredTransport, additionalInterfaces, defaultInputModes, defaultOutputModes, documentationUrl, securitySchemes, security) corroborating_probes: - url: https://scvd.store/.well-known/agent.json http_status: 200 note: Identical bytes to the canonical path. - url: https://scvd.store/.well-known/a2a.json http_status: 200 note: Identical bytes; the alias the provider links from its api-catalog. - url: https://www.scvd.store/.well-known/agent-card.json http_status: 301 note: Redirects to https://scvd.store/.well-known/agent-card.json. - url: https://scvd.store/a2a method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tasks/get","params":{"id":"apievangelist-probe-nonexistent"}}' http_status: 200 response: '{"jsonrpc":"2.0","id":1,"error":{"code":-32001,"message":"Task not found."}}' note: A real A2A JSON-RPC responder — TaskNotFoundError (-32001) is the A2A-defined code for an unknown task id. No message was sent and nothing was purchased. - url: https://scvd.store/.well-known/scvd-store-negative-control-9f3ab1c2.json http_status: 404 control: negative - url: https://a2aregistry.org/api/agents/3ec62f32-4e67-4382-8d15-2b6bf689f33a note: >- The card entered the harvest backlog through the a2aregistry.org listing; the provider's own trust.json records that registry's smoke test failed on a plain-text greeting the agent rejects (it takes JSON tasks) and links the registry issue. The card above was fetched directly from the provider's host. agent_card: name: SCVD Evidence Agent description: >- The observatory's "delegated face": three read-only, free, no-account A2A tasks that return dated, signed, machine-verifiable evidence about x402 endpoints, signed offers/receipts and endpoint readiness history. The card says plainly it never says whether to trust a merchant or which endpoint to use. url: https://scvd.store/a2a version: 1.1.0 protocol_version: 0.3.0 preferred_transport: JSONRPC additional_interfaces: - {url: 'https://scvd.store/a2a', transport: JSONRPC} provider: organization: Record Creative Co. LLC url: https://scvd.store documentation_url: https://scvd.store/a2a capabilities: streaming: false push_notifications: false state_transition_history: false default_input_modes: [application/json] default_output_modes: [application/json] supports_authenticated_extended_card: false security_schemes: {} security: [] skill_count: 3 skills: - {id: preflight_endpoint, name: x402 endpoint preflight, tags: [x402, preflight, endpoint, free], example: '{"task":"preflight_endpoint","url":"https://example.com/api/paid-answer"}'} - {id: verify_receipt, name: x402 receipt verification, tags: [x402, receipt, offer, signature, ed25519, free], example: '{"task":"verify_receipt","receipt":"eyJ…","public_key_hex":"…optional…"}'} - {id: get_endpoint_readiness, name: x402 endpoint-readiness dataset, tags: [x402, readiness, corpus, history, free], example: '{"task":"get_endpoint_readiness","host":"example.com"}'} skill_invocation: >- Every skill's examples[] entry is a JSON message part {"task": "", ...inputs}. Results are retrievable with tasks/get for 86,400 seconds (x_scvd_note); terminal tasks cannot be cancelled or restarted; request messages and history are not retained. paid_surface_note: >- x_scvd_note states that the paid instruments (signed audits, watches, settlement attestations) are x402 doors listed at https://scvd.store/menu.json and are NOT A2A tasks — the A2A surface is entirely free. conformance: spec: A2A 1.0.0 grade: conformant protocol_version: '0.3.0' preferred_transport: JSONRPC hard_checks: capabilities_is_object: true protocol_version_present: true skills_is_array: true optional_fields: default_input_modes: true default_output_modes: true preferred_transport: true grade_basis: >- Graded against the A2A 1.0.0 hard checks. capabilities is an OBJECT (pass) with streaming, pushNotifications and stateTransitionHistory all declared false. protocolVersion is present at the top level (pass), declared "0.3.0". skills is an ARRAY (pass) of three fully-populated skills, each with id, name, description, tags, examples, inputModes and outputModes. All three optional discriminators are present: preferredTransport (JSONRPC), defaultInputModes and defaultOutputModes (application/json), plus additionalInterfaces[], provider{}, documentationUrl, securitySchemes and security. This is a 0.3.0-shaped card (top-level url + preferredTransport + protocolVersion rather than a 1.0.0 supportedInterfaces[] block) and is internally consistent with that revision. deviations: - field: protocolVersion / url / preferredTransport / additionalInterfaces observed: 0.3.0 top-level triple plus additionalInterfaces[] mirroring the primary url; no supportedInterfaces[] note: >- Valid for A2A 0.3.0, which the card declares. A reader written against A2A 1.0.0 looks for supportedInterfaces[].protocolBinding and will not find it. Recorded because both shapes coexist in the catalog, not as a fault. - field: agentToolsVerify observed: 'a non-standard top-level string ("atc_…") — an Agent Tools verification token' note: An extension key outside the AgentCard schema; also present at the top of /.well-known/x402.json. Harmless to a spec-conformant reader that ignores unknown keys. - field: x_scvd_note observed: a non-standard top-level prose field carrying retention, cancellation and paid-surface caveats note: Useful operational detail with no schema home; a strict validator with additionalProperties false would flag it. - field: securitySchemes / security observed: 'securitySchemes {} and security [] — explicitly empty rather than absent' note: >- Deliberate: the card's three skills are free and anonymous, and the provider's auth.md and RFC 9728 protected-resource document both say there is no credential of any kind. Empty-but-present is the honest encoding of "no auth"; it is recorded so a reader does not mistake it for an omission. - field: iconUrl / signatures observed: absent note: >- No icon and no JWS signatures[] block on the card itself, so the card's authenticity rests on TLS to scvd.store — although the provider publishes a did:web document, an Ed25519 signing key with history and a signed ARD trust manifest on the same host, none of which the card references. surface_relationship: note: >- The A2A agent is the smallest of four projections of one instrument set. Its three skills map one-to-one onto the free HTTP instruments (POST /api/preflight/v2, POST /api/conformance/v1, GET /corpus/host/{host}.json) and onto the verifier MCP door's preflight_x402_endpoint, verify_x402_receipt and lookup_endpoint_readiness tools — see mcp/scvd-store-tool-crosswalk.yml. The paid shelf (35 doors) is reachable over HTTP, the main MCP door and UCP checkout, never over A2A. The provider also runs a free A2A card-checking instrument for OTHER agents (POST /api/a2a/check, MCP check_a2a_card, and a paid a2a_repair_kit) — an A2A conformance desk, distinct from this card.