{"id":11021,"name":"fullmakt-a2a","description":"Fullmakt management agent: create and manage collections, requests, environments, policies and agent identities in one workspace. Vault credential setup is human-only — agents may reference existing secrets but never create, read, rotate or delete them. Execution (calling a collection's requests as tools) happens over MCP at https://fullmakt.ai/mcp/{collection} with an execution-scoped token from the same token endpoint.","card_url":"https://fullmakt.ai/.well-known/agent-card.json","endpoint":"https://fullmakt.ai/a2a","protocol_version":"0.3.0","first_seen":"2026-10-10T12:38:35.865241+00:00","last_verified":"2026-10-10T19:50:19.206393+00:00","card":{"url":"https://fullmakt.ai/a2a","name":"fullmakt-a2a","skills":[{"id":"workspace.get","name":"Get workspace","tags":["WorkspaceRead"],"inputModes":["application/json"],"description":"Summary of the workspace this token manages.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"collection.list","name":"List collections","tags":["CollectionRead"],"inputModes":["application/json"],"description":"List the collections in the workspace.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"collection.create","name":"Create collection","tags":["CollectionWrite"],"inputModes":["application/json"],"description":"Create a collection in the workspace.","inputSchema":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Collection name"},"description":{"type":"string","description":"Optional description"}}},"outputModes":["application/json"]},{"id":"collection.get","name":"Get collection","tags":["CollectionRead"],"inputModes":["application/json"],"description":"Full collection detail: items tree, variables, scripts.","inputSchema":{"type":"object","required":["collectionId"],"properties":{"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"collection.update","name":"Update collection","tags":["CollectionWrite"],"inputModes":["application/json"],"description":"Update name/description/auth/default environment/scripts.","inputSchema":{"type":"object","required":["collectionId","collection"],"properties":{"collection":{"type":"object","description":"UpdateCollectionRequest: name, description?, authConfigJson?, preRequestScript?, testScript?, defaultEnvironmentId?"},"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"collection.delete","name":"Delete collection","tags":["CollectionWrite"],"inputModes":["application/json"],"description":"Delete a collection and everything in it.","inputSchema":{"type":"object","required":["collectionId"],"properties":{"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"item.create","name":"Create item","tags":["ItemWrite"],"inputModes":["application/json"],"description":"Create a folder or request (HTTP/GraphQL/WebSocket/gRPC/MCP) in a collection.","inputSchema":{"type":"object","required":["collectionId","item"],"properties":{"item":{"type":"object","description":"CreateCollectionItemRequest: itemType, name, description?, parentItemId?, protocolType?, request?, graphQlRequest?, webSocketRequest?, grpcRequest?, mcpRequest?"},"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"item.get","name":"Get item","tags":["CollectionRead"],"inputModes":["application/json"],"description":"Fetch one item with its request definition and children.","inputSchema":{"type":"object","required":["itemId"],"properties":{"itemId":{"type":"string","description":"Item GUID"}}},"outputModes":["application/json"]},{"id":"item.update","name":"Update item","tags":["ItemWrite"],"inputModes":["application/json"],"description":"Update an item's name, request definition and scripts.","inputSchema":{"type":"object","required":["itemId","item"],"properties":{"item":{"type":"object","description":"UpdateCollectionItemRequest payload"},"itemId":{"type":"string","description":"Item GUID"}}},"outputModes":["application/json"]},{"id":"item.delete","name":"Delete item","tags":["ItemWrite"],"inputModes":["application/json"],"description":"Delete an item (and its children).","inputSchema":{"type":"object","required":["itemId"],"properties":{"itemId":{"type":"string","description":"Item GUID"}}},"outputModes":["application/json"]},{"id":"item.move","name":"Move item","tags":["ItemWrite"],"inputModes":["application/json"],"description":"Re-parent and/or re-order an item within its collection.","inputSchema":{"type":"object","required":["itemId","newSortOrder"],"properties":{"itemId":{"type":"string","description":"Item GUID"},"newParentId":{"type":"string","description":"New parent item GUID, omit for root"},"newSortOrder":{"type":"integer","description":"New sort position"}}},"outputModes":["application/json"]},{"id":"environment.list","name":"List environments","tags":["EnvironmentRead"],"inputModes":["application/json"],"description":"List the workspace's environments.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"environment.create","name":"Create environment","tags":["EnvironmentWrite"],"inputModes":["application/json"],"description":"Create an environment with variables. Variables may reference existing vault entries (vault://local/<name>) but LLM provider credentials cannot be set over A2A.","inputSchema":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Environment name"},"variables":{"type":"array","description":"Variables: {key, initialValue, currentValue, enabled}"}}},"outputModes":["application/json"]},{"id":"environment.update","name":"Update environment","tags":["EnvironmentWrite"],"inputModes":["application/json"],"description":"Rename an environment and/or replace its variables. Any stored LLM credential config is preserved untouched.","inputSchema":{"type":"object","required":["environmentId","name"],"properties":{"name":{"type":"string","description":"Environment name"},"variables":{"type":"array","description":"Replacement variables"},"environmentId":{"type":"string","description":"Environment GUID"}}},"outputModes":["application/json"]},{"id":"environment.delete","name":"Delete environment","tags":["EnvironmentWrite"],"inputModes":["application/json"],"description":"Delete an environment.","inputSchema":{"type":"object","required":["environmentId"],"properties":{"environmentId":{"type":"string","description":"Environment GUID"}}},"outputModes":["application/json"]},{"id":"globals.get","name":"Get global variables","tags":["EnvironmentRead"],"inputModes":["application/json"],"description":"List the workspace's global variables.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"globals.set","name":"Set global variables","tags":["EnvironmentWrite"],"inputModes":["application/json"],"description":"Replace the workspace's global variables.","inputSchema":{"type":"object","required":["variables"],"properties":{"variables":{"type":"array","description":"Variables: {key, initialValue, currentValue, enabled}"}}},"outputModes":["application/json"]},{"id":"policy.get","name":"Get collection policy","tags":["PolicyRead"],"inputModes":["application/json"],"description":"Read the policy document governing broker calls to a collection.","inputSchema":{"type":"object","required":["collectionId"],"properties":{"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"policy.set","name":"Set collection policy","tags":["PolicyWrite"],"inputModes":["application/json"],"description":"Set the policy document (hardDeny / requireApproval / behavior rules) for a collection.","inputSchema":{"type":"object","required":["collectionId","policyJson"],"properties":{"policyJson":{"type":"string","description":"The policy document as a JSON string"},"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"approval.list","name":"List pending approvals","tags":["ApprovalRead"],"inputModes":["application/json"],"description":"List approvals awaiting a human decision. Deciding them is human-only.","inputSchema":{"type":"object","properties":{"limit":{"type":"integer","description":"Max rows (default 100)"},"status":{"type":"string","description":"Pending|Approved|Rejected|Expired|Used"}}},"outputModes":["application/json"]},{"id":"principal.list","name":"List agent principals","tags":["PrincipalRead"],"inputModes":["application/json"],"description":"List the account's agent principals. Principals are account-level identities (not workspace-scoped), so this spans the owner's whole account.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"principal.create","name":"Create agent principal","tags":["PrincipalWrite"],"inputModes":["application/json"],"description":"Create a named account-level agent identity for execution-side auditing and policy.","inputSchema":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Principal name"}}},"outputModes":["application/json"]},{"id":"client.list","name":"List execution clients","tags":["ClientRead"],"inputModes":["application/json"],"description":"List account-level OAuth clients for the remote MCP execution surface (no secrets returned).","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"client.create","name":"Create execution client","tags":["ClientWrite"],"inputModes":["application/json"],"description":"Create an OAuth client scoped to collections in this workspace. The secret is returned exactly once.","inputSchema":{"type":"object","required":["principalId","collectionIds"],"properties":{"principalId":{"type":"string","description":"Principal GUID"},"collectionIds":{"type":"array","description":"Collection GUIDs the client may scope tokens to"}}},"outputModes":["application/json"]},{"id":"vault.listEntries","name":"List vault entry references","tags":["VaultRead"],"inputModes":["application/json"],"description":"Metadata for existing vault entries (names + vault://local/<name> references). Values are never returned, and secrets can only be created, rotated or deleted by a human in the UI.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]},{"id":"audit.list","name":"Query the audit trail","tags":["AuditRead"],"inputModes":["application/json"],"description":"Recent broker/A2A audit entries for this account.","inputSchema":{"type":"object","properties":{"limit":{"type":"integer","description":"Max rows (default 100)"},"surface":{"type":"string","description":"Filter by surface, e.g. 'a2a'"},"collectionId":{"type":"string","description":"Filter by collection GUID"}}},"outputModes":["application/json"]},{"id":"collection.import","name":"Import Postman collection","tags":["ImportExport"],"inputModes":["application/json"],"description":"Import a Postman v2.1 collection JSON into the workspace.","inputSchema":{"type":"object","required":["json"],"properties":{"json":{"type":"string","description":"The Postman collection JSON"}}},"outputModes":["application/json"]},{"id":"collection.export","name":"Export Postman collection","tags":["ImportExport"],"inputModes":["application/json"],"description":"Export a collection as Postman v2.1 JSON.","inputSchema":{"type":"object","required":["collectionId"],"properties":{"collectionId":{"type":"string","description":"Collection GUID"}}},"outputModes":["application/json"]},{"id":"discovery.probe","name":"Probe an API surface","tags":["DiscoveryRun"],"inputModes":["application/json"],"description":"Run the discovery ladder (OpenAPI/GraphQL/MCP/A2A, plus mail and file servers) against a URL and return the normalized operations, connections and auth summary. Reads only — persists nothing.","inputSchema":{"type":"object","required":["url"],"properties":{"url":{"type":"string","description":"Absolute URL to probe: http(s), imap/smtp/pop3/mailto, or sftp/ftps"}}},"outputModes":["application/json"]},{"id":"discovery.generate","name":"Generate a collection from a URL","tags":["CollectionWrite"],"inputModes":["application/json"],"description":"Discover an API and generate a persisted, authenticated collection wired to credential references (never plaintext secrets). Same pipeline as the REST generate endpoint.","inputSchema":{"type":"object","required":["url","environmentId"],"properties":{"url":{"type":"string","description":"Absolute URL to generate from: http(s) API, imap/smtp/pop3/mailto mailbox, or sftp/ftps server"},"hint":{"type":"string","description":"Optional intent hint to filter/name endpoints"},"environmentId":{"type":"string","description":"Environment GUID scoping the collection (its LLM config is used for HTTP APIs; mail/file targets work without one)"}}},"outputModes":["application/json"]},{"id":"assistant.plan","name":"Plan an integration from a sentence","tags":["AssistantRun"],"inputModes":["application/json"],"description":"Start an assistant run: the free-text wish is decomposed into connector targets and the run pauses on its first question. Returns the run (transcript, plan, pending question). Never returns secrets.","inputSchema":{"type":"object","required":["message"],"properties":{"message":{"type":"string","description":"What the agent should be able to do"},"parentRunId":{"type":"string","description":"Completed run to amend (allow writes, rotate secret, remint)"},"environmentId":{"type":"string","description":"Environment GUID providing the LLM config (default: workspace's)"}}},"outputModes":["application/json"]},{"id":"assistant.get","name":"Get an assistant run","tags":["AssistantRun"],"inputModes":["application/json"],"description":"Current state, transcript, plan and pending question of a run started by this principal's owner.","inputSchema":{"type":"object","required":["runId"],"properties":{"runId":{"type":"string","description":"Run GUID"}}},"outputModes":["application/json"]},{"id":"assistant.answer","name":"Answer an assistant run question","tags":["AssistantRun"],"inputModes":["application/json"],"description":"Answer the run's pending question (confirm_plan, connection_params, scope, agent_identity, confirm_provision). credential and oauth_consent questions are human-only and are refused. When the run completes, the one-time handoff (client secret, tokens) is returned exactly once.","inputSchema":{"type":"object","required":["runId","questionId","answer"],"properties":{"runId":{"type":"string","description":"Run GUID"},"answer":{"type":"object","description":"The typed answer payload for the question"},"questionId":{"type":"string","description":"The pending question id"}}},"outputModes":["application/json"]},{"id":"grant.list","name":"List upstream OAuth grant references","tags":["GrantRead"],"inputModes":["application/json"],"description":"Metadata for existing upstream OAuth grants (names + oauth://<name> references, provider, scopes, status). Secrets and tokens are never returned; grants are created, connected and deleted by a human in the UI.","inputSchema":{"type":"object","properties":{}},"outputModes":["application/json"]}],"version":"0.1.0","security":[{"oauth2":["management"]}],"description":"Fullmakt management agent: create and manage collections, requests, environments, policies and agent identities in one workspace. Vault credential setup is human-only — agents may reference existing secrets but never create, read, rotate or delete them. Execution (calling a collection's requests as tools) happens over MCP at https://fullmakt.ai/mcp/{collection} with an execution-scoped token from the same token endpoint.","capabilities":{"streaming":false,"pushNotifications":false,"stateTransitionHistory":false},"protocolVersion":"0.3.0","securitySchemes":{"oauth2":{"type":"oauth2","flows":{"clientCredentials":{"scopes":{"management":"Manage the workspace this client was provisioned for."},"tokenUrl":"https://fullmakt.ai/mcp-oauth/token"}}}},"defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"preferredTransport":"JSONRPC"},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T19:50:19.206393+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agenstry federation","source_url":"https://agenstry.com/docs","last_check":{"checked_at":"2026-10-10T19:50:19.206393+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://fullmakt.ai/.well-known/agent-card.json"],"skills":[{"skill_id":"assistant.answer","name":"Answer an assistant run question","description":"Answer the run's pending question (confirm_plan, connection_params, scope, agent_identity, confirm_provision). credential and oauth_consent questions are human-only and are refused. When the run completes, the one-time handoff (client secret, tokens) is returned exactly once.","tags":["AssistantRun"],"quality_warning":false},{"skill_id":"principal.create","name":"Create agent principal","description":"Create a named account-level agent identity for execution-side auditing and policy.","tags":["PrincipalWrite"],"quality_warning":false},{"skill_id":"collection.create","name":"Create collection","description":"Create a collection in the workspace.","tags":["CollectionWrite"],"quality_warning":false},{"skill_id":"environment.create","name":"Create environment","description":"Create an environment with variables. Variables may reference existing vault entries (vault://local/<name>) but LLM provider credentials cannot be set over A2A.","tags":["EnvironmentWrite"],"quality_warning":false},{"skill_id":"client.create","name":"Create execution client","description":"Create an OAuth client scoped to collections in this workspace. The secret is returned exactly once.","tags":["ClientWrite"],"quality_warning":false},{"skill_id":"item.create","name":"Create item","description":"Create a folder or request (HTTP/GraphQL/WebSocket/gRPC/MCP) in a collection.","tags":["ItemWrite"],"quality_warning":false},{"skill_id":"collection.delete","name":"Delete collection","description":"Delete a collection and everything in it.","tags":["CollectionWrite"],"quality_warning":false},{"skill_id":"environment.delete","name":"Delete environment","description":"Delete an environment.","tags":["EnvironmentWrite"],"quality_warning":false},{"skill_id":"item.delete","name":"Delete item","description":"Delete an item (and its children).","tags":["ItemWrite"],"quality_warning":false},{"skill_id":"collection.export","name":"Export Postman collection","description":"Export a collection as Postman v2.1 JSON.","tags":["ImportExport"],"quality_warning":false},{"skill_id":"discovery.generate","name":"Generate a collection from a URL","description":"Discover an API and generate a persisted, authenticated collection wired to credential references (never plaintext secrets). Same pipeline as the REST generate endpoint.","tags":["CollectionWrite"],"quality_warning":false},{"skill_id":"assistant.get","name":"Get an assistant run","description":"Current state, transcript, plan and pending question of a run started by this principal's owner.","tags":["AssistantRun"],"quality_warning":false},{"skill_id":"collection.get","name":"Get collection","description":"Full collection detail: items tree, variables, scripts.","tags":["CollectionRead"],"quality_warning":false},{"skill_id":"policy.get","name":"Get collection policy","description":"Read the policy document governing broker calls to a collection.","tags":["PolicyRead"],"quality_warning":false},{"skill_id":"globals.get","name":"Get global variables","description":"List the workspace's global variables.","tags":["EnvironmentRead"],"quality_warning":false},{"skill_id":"item.get","name":"Get item","description":"Fetch one item with its request definition and children.","tags":["CollectionRead"],"quality_warning":false},{"skill_id":"workspace.get","name":"Get workspace","description":"Summary of the workspace this token manages.","tags":["WorkspaceRead"],"quality_warning":false},{"skill_id":"collection.import","name":"Import Postman collection","description":"Import a Postman v2.1 collection JSON into the workspace.","tags":["ImportExport"],"quality_warning":false},{"skill_id":"principal.list","name":"List agent principals","description":"List the account's agent principals. Principals are account-level identities (not workspace-scoped), so this spans the owner's whole account.","tags":["PrincipalRead"],"quality_warning":false},{"skill_id":"collection.list","name":"List collections","description":"List the collections in the workspace.","tags":["CollectionRead"],"quality_warning":false},{"skill_id":"environment.list","name":"List environments","description":"List the workspace's environments.","tags":["EnvironmentRead"],"quality_warning":false},{"skill_id":"client.list","name":"List execution clients","description":"List account-level OAuth clients for the remote MCP execution surface (no secrets returned).","tags":["ClientRead"],"quality_warning":false},{"skill_id":"approval.list","name":"List pending approvals","description":"List approvals awaiting a human decision. Deciding them is human-only.","tags":["ApprovalRead"],"quality_warning":false},{"skill_id":"grant.list","name":"List upstream OAuth grant references","description":"Metadata for existing upstream OAuth grants (names + oauth://<name> references, provider, scopes, status). Secrets and tokens are never returned; grants are created, connected and deleted by a human in the UI.","tags":["GrantRead"],"quality_warning":false},{"skill_id":"vault.listEntries","name":"List vault entry references","description":"Metadata for existing vault entries (names + vault://local/<name> references). Values are never returned, and secrets can only be created, rotated or deleted by a human in the UI.","tags":["VaultRead"],"quality_warning":false},{"skill_id":"item.move","name":"Move item","description":"Re-parent and/or re-order an item within its collection.","tags":["ItemWrite"],"quality_warning":false},{"skill_id":"assistant.plan","name":"Plan an integration from a sentence","description":"Start an assistant run: the free-text wish is decomposed into connector targets and the run pauses on its first question. Returns the run (transcript, plan, pending question). Never returns secrets.","tags":["AssistantRun"],"quality_warning":false},{"skill_id":"discovery.probe","name":"Probe an API surface","description":"Run the discovery ladder (OpenAPI/GraphQL/MCP/A2A, plus mail and file servers) against a URL and return the normalized operations, connections and auth summary. Reads only — persists nothing.","tags":["DiscoveryRun"],"quality_warning":false},{"skill_id":"audit.list","name":"Query the audit trail","description":"Recent broker/A2A audit entries for this account.","tags":["AuditRead"],"quality_warning":false},{"skill_id":"policy.set","name":"Set collection policy","description":"Set the policy document (hardDeny / requireApproval / behavior rules) for a collection.","tags":["PolicyWrite"],"quality_warning":false},{"skill_id":"globals.set","name":"Set global variables","description":"Replace the workspace's global variables.","tags":["EnvironmentWrite"],"quality_warning":false},{"skill_id":"collection.update","name":"Update collection","description":"Update name/description/auth/default environment/scripts.","tags":["CollectionWrite"],"quality_warning":false},{"skill_id":"environment.update","name":"Update environment","description":"Rename an environment and/or replace its variables. Any stored LLM credential config is preserved untouched.","tags":["EnvironmentWrite"],"quality_warning":false},{"skill_id":"item.update","name":"Update item","description":"Update an item's name, request definition and scripts.","tags":["ItemWrite"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":4,"passed":4},"recent_checks":[{"card_url":"https://fullmakt.ai/.well-known/agent-card.json","checked_at":"2026-10-10T19:50:19.206393+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://fullmakt.ai/.well-known/agent-card.json","checked_at":"2026-10-10T17:33:13.528871+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://fullmakt.ai/.well-known/agent-card.json","checked_at":"2026-10-10T15:15:33.289094+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://fullmakt.ai/.well-known/agent-card.json","checked_at":"2026-10-10T12:38:35.865241+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T19:50:19.206393+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T12:38:35.865241+00:00","state":"auth_required","http_status":401,"detail":"Endpoint requires authentication; A2A response not confirmed"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://fullmakt.ai/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T19:50:19.206393+00:00","latest_card_check":{"checked_at":"2026-10-10T19:50:19.206393+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T19:50:19.206393+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T19:50:19.206393+00:00","endpoint_tls_reachable":true,"protocol_check_state":"auth_required","protocol_checked_at":"2026-10-10T12:38:35.865241+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}