{"id":6940,"name":"onyx-actions","description":"The independent trust & verification layer for the agentic web — the signed check an AI agent runs BEFORE it pays or transacts. Returns a hard PROCEED / REVIEW / HOLD clearance plus Ed25519-signed FACTS any third party can verify offline (tamper -> rejected). Neutral by design — earns nothing from any tx, so it grades what conflicted incumbents structurally cannot. Facts, not judgments.","card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","endpoint":"https://onyx-actions.onrender.com/a2a","protocol_version":"1.0","first_seen":"2026-10-10T06:13:02.453289+00:00","last_verified":"2026-10-10T07:57:22.821513+00:00","card":{"aka":["0n1x","Onyx","Onyx Protocol"],"url":"https://onyx-actions.onrender.com/a2a","name":"onyx-actions","x402":{"asset":"USDC","network":"eip155:8453","manifest":"https://onyx-actions.onrender.com/.well-known/x402.json"},"brand":"0n1x","rights":{"note":"Every paid output carries a signed usage-rights envelope (resale/redistribute/derivatives/retrain/cache_ttl), hash-bound to the output. Verification is free; custom terms via onyx_usage_rights.","spec":"usage-rights-envelope/v0","policy":"https://onyx-actions.onrender.com/.well-known/rights.json","free_verify":"https://onyx-actions.onrender.com/verify","custom_terms_tool":"onyx_usage_rights","per_output_header":"X-Onyx-Rights"},"skills":[{"id":"onyx_agent_verify","name":"Agent Verify","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Signed agent liveness + authenticity oracle. Give an A2A agent's card URL or endpoint; Onyx sends two distinct challenge messages and reports whether it is ALIVE (different, on-topic replies), HOLLOW (same canned string to both — passes reg"},{"id":"onyx_ai_visibility","name":"Ai Visibility","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"description":"AI answer-engine visibility (GEO) oracle. Give a brand/product (+ optional category and competitors); get a SIGNED reading of how a live web-grounded answer engine represents it right now — presence, whether it's in the 'best <category>' re"},{"id":"onyx_attestation_verify","name":"Attestation Verify","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Verify an Onyx-signed security verdict. Paste back any result from an Onyx tool (the full JSON including its onyx_attestation block); get a cryptographic verdict: is the Ed25519 signature valid, was it signed by Onyx (kid), and has any fiel"},{"id":"onyx_contract_audit","name":"Contract Audit","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Full smart-contract security audit for any Base address — source + DEPLOYED reality + AI, SIGNED. Fetches verified source, runs curated static vuln detectors (tx.origin auth, delegatecall, selfdestruct, unchecked calls, unprotected init, ow"},{"id":"onyx_market_rank","name":"Market Rank","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"description":"Signed, conflict-free rating of any agent/x402 service — 'Moody's for the agentic web'. Point it at a URL; it probes observable reality (live, discoverable, payable, breadth, transparency) and returns a 0-100 rating + A-F grade, Ed25519-sig"},{"id":"onyx_merchant_fact_check","name":"Merchant Fact Check","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Pre-checkout merchant fact oracle. Give a storefront domain (optionally the brand you believe it is, and an expected price); get Ed25519-signed raw observations: domain registration age + registrar (RDAP), live TLS certificate age + issuer,"},{"id":"onyx_research_intel","name":"Research Intel","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"description":"Research intel — has someone solved X already? Queries 240M+ academic works via OpenAlex (includes arXiv preprints, conference papers, journal articles), ranks by citation count + recency + relevance, returns top N papers with one-line abst"},{"id":"onyx_retail_price_check","name":"Retail Price Check","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"description":"Ground-truth retail oracle. Give a product URL; get the real current price, currency, and in-stock state as actually fetched now — with the extraction source (JSON-LD / OpenGraph / microdata) as evidence. Covers the long tail of no-API shop"},{"id":"rhinogent_verify_counterparty","name":"Rhinogent Verify Counterparty","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Know-your-counterparty for agents. Before your agent pays a merchant, get Ed25519-signed raw facts about who it's paying: domain registration age, live TLS cert, reachability + off-domain redirects, brand-impersonation similarity, and obser"},{"id":"onyx_secure_payment","name":"Secure Payment","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Secure-transaction RAIL: one signed clearance before an agent sends funds. Give recipient + amount (and optionally a contract address or counterparty ERC-8004 agent id); Onyx runs the full security stack — recipient firewall, contract audit"},{"id":"onyx_signature_guard","name":"Signature Guard","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Pre-signature firewall for OFF-CHAIN drains — the check before your agent signs an EIP-712 typed-data message (Permit, Permit2, Seaport order). These drain a wallet with no on-chain approval: the signature itself is the authorization. Give "},{"id":"onyx_token_risk","name":"Token Risk","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Signed token-security oracle. Give a token contract (and chain); get the real on-chain risk facts as read right now — honeypot status, buy/sell tax, mintable, ownership-reclaim, transfer-pausable, proxy, LP-lock, holder count — plus a trans"},{"id":"onyx_tx_guard","name":"Tx Guard","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Pre-payment security firewall. Give the recipient address your agent is about to pay (Base); get a SIGNED ALLOW/REVIEW/BLOCK verdict + risk score from real on-chain checks: EOA-vs-contract, contract code/verification, account age (tx count)"},{"id":"onyx_verify_explain","name":"Verify Explain","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Diagnose a failing x402 v2 /verify. Decodes a captured X-PAYMENT header, runs 10 rules (decode, schema, network/asset/payTo match, value sufficiency, EIP-3009 timing, signature shape, scheme) against expected paymentRequirements, and return"},{"id":"onyx_x402_receipt_verify","name":"X402 Receipt Verify","tags":["security","verification","trust","x402","ed25519-signed"],"description":"Verify an x402 USDC settlement on Base or Base Sepolia. Given a tx hash, decodes the USDC Transfer log and confirms (or refutes) a claim of the form: 'tx X moved $Y USDC from A to B'. Returns success status, actual decoded values, and a cle"}],"contact":{"auth":"none","free":true,"note":"Free, no-key front door — POST a message and Onyx auto-replies (Ed25519-signed). New agent? POST /onboard to get your own signed A2A card + self-custody wallet in one call. The deeper skills are pay-per-call over x402.","accepts":["{\"message\":\"...\"}","A2A message/send"],"connect":"https://onyx-actions.onrender.com/connect","onboard":"https://onyx-actions.onrender.com/onboard"},"erc8004":{"note":"Onyx reads these live to vet counterparty agents (onyx_agent_reputation).","identity_registry":"0x8004A169FB4a3325136EB29fA0ceB6D2e539a432","reputation_registry":"0x8004BAa17C55a88189AE136b182e5fdA19dE9b63"},"version":"1.0.0","keywords":["trust layer","verification","verify before pay","pre-payment gate","merchant verification","fact-check","scam detection","fake store","fraud prevention","price verification","counterparty risk","due diligence","signed attestation","Ed25519","provenance","agentic commerce","AI shopping","x402","A2A","AP2","ERC-8004","agent reputation","neutral oracle","know before you pay"],"provider":{"url":"https://onyx-actions.onrender.com","organization":"Onyx Protocol"},"keyPoints":["Pre-payment gate: PROCEED/REVIEW/HOLD before an agent pays","Merchant fact-check: is this store real? (domain age, TLS, redirect, lookalike)","Know Before You Pay: free consumer scam red-flag check (/check)","Retail price verification · smart-contract audit · token risk · agent liveness","Onyx Verified: sell-side badge, merchant pays to be verified","Public signed observation log (CT-for-commerce): /history /merchant/{domain} /proof","Free verify booth /verify · every output Ed25519-signed, offline-verifiable"],"governance":{"note":"Published, signed terms of service and observation methodology — the neutral-attestor posture, auditable by any agent.","terms":"https://onyx-actions.onrender.com/.well-known/terms.json","methodology":"https://onyx-actions.onrender.com/.well-known/methodology.json"},"signatures":[{"protected":"eyJhbGciOiJFZERTQSIsImp3ayI6eyJjcnYiOiJFZDI1NTE5Iiwia3R5IjoiT0tQIiwieCI6ImZna3VPZ1hLMUhYX1RIcG5YT3hpbUZPTTJSRHl4WUd6bmQyQ3ZGRUI0a2sifSwia2lkIjoib255eC04OTk0YTViNWE0MjY2NjE1Iiwib255eF9wdWJrZXlfdXJsIjoiaHR0cHM6Ly9vbnl4LWFjdGlvbnMub25yZW5kZXIuY29tLy53ZWxsLWtub3duL29ueXgtcHVia2V5In0","signature":"78xycR45xMJ9wbdiiBvhdnmIu_3K8RN17_7GVTljlPxvQRXxRv1a_9rQ3OOeDgD7fkGD_5ez2qcJxodq1rahCg"}],"attestation":{"alg":"Ed25519+JCS","pubkey":"https://onyx-actions.onrender.com/.well-known/onyx-pubkey"},"description":"The independent trust & verification layer for the agentic web — the signed check an AI agent runs BEFORE it pays or transacts. Returns a hard PROCEED / REVIEW / HOLD clearance plus Ed25519-signed FACTS any third party can verify offline (tamper -> rejected). Neutral by design — earns nothing from any tx, so it grades what conflicted incumbents structurally cannot. Facts, not judgments.","capabilities":{"streaming":false,"extensions":[{"uri":"https://github.com/google-agentic-commerce/ap2/tree/v0.1","params":{"roles":["merchant"]},"required":false,"description":"Onyx participates in AP2 agentic-payment flows as a merchant: agents pay Onyx for signed verification under an AP2 Cart Mandate."},{"uri":"https://github.com/google-a2a/a2a-x402/v0.1","required":false,"description":"Supports payments using the x402 protocol for on-chain settlement (USDC on Base). Activate via the X-A2A-Extensions header."},{"uri":"https://onyx-actions.onrender.com/ext/usage-rights/v0","params":{"spec":"usage-rights-envelope/v0","policy":"https://onyx-actions.onrender.com/.well-known/rights.json","free_verify":"https://onyx-actions.onrender.com/verify"},"required":false,"description":"usage-rights-envelope/v0 — signed, hash-bound declaration of what a buyer may do with a purchased output (resale/redistribute/derivatives/retrain/cache_ttl). Data-only: envelope rides Artifact.metadata.usage_rights or the X-Onyx-Rights HTTP header."}],"pushNotifications":false,"stateTransitionHistory":false},"trust_posture":{"summary":"Onyx is a neutral attestor and runs a hardened agent. We publish how we behave so counterparties can rely on it.","verify_us":"https://onyx-actions.onrender.com/verify","principles":["Facts, not judgments — we sign observations, never opinions dressed as facts.","Math is the judge — verdicts verify by Ed25519, never by an LLM that could be talked around.","Inbound is untrusted data — agent/user text is never executed as commands (injection-resistant).","Fetched content cannot make us act silently or withhold from our principal; we never auto-authenticate or auto-move funds.","Conflict-free — Onyx earns nothing from any transaction, rail, or marketplace it grades."],"challenge_us":"https://onyx-actions.onrender.com/fool"},"securitySchemes":{"x402":{"type":"x402","description":"Pay-per-call via x402 USDC on Base; the payment is the auth."}},"defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"preferredTransport":"HTTP+JSON","supportedInterfaces":[{"url":"https://onyx-actions.onrender.com/a2a","protocolBinding":"HTTP+JSON","protocolVersion":"1.0"},{"url":"https://onyx-actions.onrender.com/a2a","protocolBinding":"JSONRPC","protocolVersion":"1.0"},{"url":"https://onyx-actions.onrender.com/v1/","protocolBinding":"HTTP+JSON","protocolVersion":"1.0"}],"additionalInterfaces":[{"url":"https://onyx-actions.onrender.com/v1/","transport":"HTTP+JSON"},{"url":"https://onyx-actions.onrender.com/mcp/","transport":"MCP"},{"url":"https://onyx-actions.onrender.com/connect","transport":"HTTP+JSON"}]},"signature_status":"unverifiable","signature_detail":"Key set returned HTTP 404","signature_key_url":null,"signature_checked_at":"2026-10-10T07:57:22.821513+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Global A2A Registry","source_url":"https://api.a2a-registry.org/public/agents","last_check":{"checked_at":"2026-10-10T07:57:22.821513+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://onyx-actions.onrender.com/.well-known/agent-card.json"],"skills":[{"skill_id":"onyx_agent_verify","name":"Agent Verify","description":"Signed agent liveness + authenticity oracle. Give an A2A agent's card URL or endpoint; Onyx sends two distinct challenge messages and reports whether it is ALIVE (different, on-topic replies), HOLLOW (same canned string to both — passes reg","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_ai_visibility","name":"Ai Visibility","description":"AI answer-engine visibility (GEO) oracle. Give a brand/product (+ optional category and competitors); get a SIGNED reading of how a live web-grounded answer engine represents it right now — presence, whether it's in the 'best <category>' re","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_attestation_verify","name":"Attestation Verify","description":"Verify an Onyx-signed security verdict. Paste back any result from an Onyx tool (the full JSON including its onyx_attestation block); get a cryptographic verdict: is the Ed25519 signature valid, was it signed by Onyx (kid), and has any fiel","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_contract_audit","name":"Contract Audit","description":"Full smart-contract security audit for any Base address — source + DEPLOYED reality + AI, SIGNED. Fetches verified source, runs curated static vuln detectors (tx.origin auth, delegatecall, selfdestruct, unchecked calls, unprotected init, ow","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_market_rank","name":"Market Rank","description":"Signed, conflict-free rating of any agent/x402 service — 'Moody's for the agentic web'. Point it at a URL; it probes observable reality (live, discoverable, payable, breadth, transparency) and returns a 0-100 rating + A-F grade, Ed25519-sig","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_merchant_fact_check","name":"Merchant Fact Check","description":"Pre-checkout merchant fact oracle. Give a storefront domain (optionally the brand you believe it is, and an expected price); get Ed25519-signed raw observations: domain registration age + registrar (RDAP), live TLS certificate age + issuer,","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_research_intel","name":"Research Intel","description":"Research intel — has someone solved X already? Queries 240M+ academic works via OpenAlex (includes arXiv preprints, conference papers, journal articles), ranks by citation count + recency + relevance, returns top N papers with one-line abst","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_retail_price_check","name":"Retail Price Check","description":"Ground-truth retail oracle. Give a product URL; get the real current price, currency, and in-stock state as actually fetched now — with the extraction source (JSON-LD / OpenGraph / microdata) as evidence. Covers the long tail of no-API shop","tags":["data","signed-data","ground-truth","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"rhinogent_verify_counterparty","name":"Rhinogent Verify Counterparty","description":"Know-your-counterparty for agents. Before your agent pays a merchant, get Ed25519-signed raw facts about who it's paying: domain registration age, live TLS cert, reachability + off-domain redirects, brand-impersonation similarity, and obser","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_secure_payment","name":"Secure Payment","description":"Secure-transaction RAIL: one signed clearance before an agent sends funds. Give recipient + amount (and optionally a contract address or counterparty ERC-8004 agent id); Onyx runs the full security stack — recipient firewall, contract audit","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_signature_guard","name":"Signature Guard","description":"Pre-signature firewall for OFF-CHAIN drains — the check before your agent signs an EIP-712 typed-data message (Permit, Permit2, Seaport order). These drain a wallet with no on-chain approval: the signature itself is the authorization. Give ","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_token_risk","name":"Token Risk","description":"Signed token-security oracle. Give a token contract (and chain); get the real on-chain risk facts as read right now — honeypot status, buy/sell tax, mintable, ownership-reclaim, transfer-pausable, proxy, LP-lock, holder count — plus a trans","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_tx_guard","name":"Tx Guard","description":"Pre-payment security firewall. Give the recipient address your agent is about to pay (Base); get a SIGNED ALLOW/REVIEW/BLOCK verdict + risk score from real on-chain checks: EOA-vs-contract, contract code/verification, account age (tx count)","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_verify_explain","name":"Verify Explain","description":"Diagnose a failing x402 v2 /verify. Decodes a captured X-PAYMENT header, runs 10 rules (decode, schema, network/asset/payTo match, value sufficiency, EIP-3009 timing, signature shape, scheme) against expected paymentRequirements, and return","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false},{"skill_id":"onyx_x402_receipt_verify","name":"X402 Receipt Verify","description":"Verify an x402 USDC settlement on Base or Base Sepolia. Given a tx hash, decodes the USDC Transfer log and confirms (or refutes) a claim of the form: 'tx X moved $Y USDC from A to B'. Returns success status, actual decoded values, and a cle","tags":["security","verification","trust","x402","ed25519-signed"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":6,"passed":6},"recent_checks":[{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T07:57:22.821513+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T07:50:59.823569+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T07:11:52.031938+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T06:46:38.026691+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T06:38:45.782744+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","checked_at":"2026-10-10T06:13:02.453289+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T07:57:22.821513+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T06:38:45.782744+00:00","state":"unconfirmed","http_status":404,"detail":"Endpoint returned a generic not-found response"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://onyx-actions.onrender.com/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T07:57:22.821513+00:00","latest_card_check":{"checked_at":"2026-10-10T07:57:22.821513+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unverifiable","signature_checked_at":"2026-10-10T07:57:22.821513+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T07:57:22.821513+00:00","endpoint_tls_reachable":true,"protocol_check_state":"unconfirmed","protocol_checked_at":"2026-10-10T06:38:45.782744+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}