{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_ped84twdu7bd","handle":"mcp-trustcard","url":"https://wellknown.network/agents/mcp-trustcard","links":{"self":"https://wellknown.network/agents/mcp-trustcard/record.json","html":"https://wellknown.network/agents/mcp-trustcard","markdown":"https://wellknown.network/agents/mcp-trustcard/record.md","api":"https://wellknown.network/api/v1/agents/mcp-trustcard","status":"https://wellknown.network/api/v1/agents/mcp-trustcard/status","claim":"https://wellknown.network/agents/mcp-trustcard/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/mcp-trustcard/claim.json","badge":"https://wellknown.network/agents/mcp-trustcard/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:mcp-trustcard","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"mcp-trustcard","summary":"Cryptographic trust infrastructure for MCP servers — content-addressed tool identity, signed manifests, TOFU pinning, capability descriptors, a two-gate invocation policy, signed+chained receipts, publisher key rotation, and per-agent OAuth 2.1 auth scope","description":"Cryptographic trust infrastructure for MCP servers — content-addressed tool identity, signed manifests, TOFU pinning, capability descriptors, a two-gate invocation policy, signed+chained receipts, publisher key rotation, and per-agent OAuth 2.1 auth scope","publisher":{"name":"davidnichols-ops","url":null},"homepage":"https://github.com/davidnichols-ops/trustcard#readme","repository":"git+https://github.com/davidnichols-ops/trustcard.git","version":"3.1.0","license":"MIT","protocols":["mcp"],"tags":["mcp","model-context-protocol","security","trust","provenance","tool-identity","supply-chain","audit","healthcheck","agents","oauth","authorization","scopes"],"pricing":null,"endpoints":[{"url":"npm:mcp-trustcard","type":"package_npm","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":{"npmKeywords":["mcp","model-context-protocol","security","trust","provenance","tool-identity","supply-chain","audit","healthcheck","agents","oauth","authorization","scopes"]},"attribution":{"kind":"npm","name":"npm","license":"npm","repoUrl":"npm","summary":"npm","version":"npm","description":"npm","homepageUrl":"npm","publisherName":"npm"}},"derived":{"capabilities":[{"slug":"security.identity","name":"Identity & Access","confidence":1,"provenance":"declared"}],"categories":["security"]},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"mcp-trustcard","registry":"npm","observedAt":"2026-09-06T06:17:40.974Z","publishedAt":"2026-08-18T23:44:11.119Z","latestVersion":"3.1.0","weeklyDownloads":136}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"npm","key":"mcp-trustcard","url":"https://www.npmjs.com/package/mcp-trustcard","firstSeenAt":"2026-09-05T21:19:54.899Z","fetchedAt":"2026-09-06T06:17:24.642Z","normalizedAt":"2026-09-06T06:17:24.642Z"}]},"firstSeenAt":"2026-09-05T21:19:54.899Z","updatedAt":"2026-09-06T06:17:40.974Z"}