{"id":9029,"name":"Kevros Governance API","description":"Runtime enforcement for autonomous agents. Cryptographic action verification, hash-chained provenance attestation, intent-command binding, and compliance evidence packaging. Every decision is recorded in a tamper-evident ledger. Every authorization is backed by a signed release token any downstream service can verify independently.","card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","endpoint":"https://governance.taskhawktech.com","protocol_version":"0.2.6","first_seen":"2026-10-10T07:50:10.670921+00:00","last_verified":"2026-10-11T16:40:50.417211+00:00","card":{"mcp":{"url":"https://governance.taskhawktech.com/mcp/","note":"Use MCP discovery (tools/list, resources/list, prompts/list) for current counts","transport":"streamable-http","auth_header":"X-API-Key"},"url":"https://governance.taskhawktech.com","name":"Kevros Governance API","sdks":{"mcp":{"url":"https://governance.taskhawktech.com/mcp/","note":"Auto-provisions a trial key on first tool call. Use MCP discovery to enumerate available tools.","transport":"streamable-http"},"crewai":{"usage":"from crewai_tools import get_identity_tools; tools = get_identity_tools(agent_id='your-agent-id')"},"openai":{"note":"Compatible with OpenAI, OpenRouter, LiteLLM, and any OpenAI-compatible provider","usage":"from kevros_openai import get_kevros_tools, handle_kevros_call"},"python":{"usage":"See https://www.taskhawktech.com/quickstart for REST + MCP integration patterns.","install":"REST API via /signup for trial access (1,000 calls/mo). First-party CLI is contract-gated - contact sales@taskhawktech.com."},"langchain":{"usage":"from kevros_tools import get_identity_tools; tools = get_identity_tools(agent_id='your-agent-id')"},"microsoft_agent_framework":{"note":"AgentMiddleware for action authorization, FunctionMiddleware for intent binding. Compatible with agent-framework 1.0.0rc1+.","usage":"from kevros_agent_framework import KevrosGovernanceMiddleware, KevrosFunctionMiddleware"}},"skills":[{"id":"action-verify","name":"Action Verification","inputModes":["application/json"],"description":"Verify an action against policy bounds before execution. Returns ALLOW, CONSTRAIN, or DENY with a signed release token. Downstream services verify the token independently. Fail-closed: verification failure results in DENY.","outputModes":["application/json"]},{"id":"provenance-attest","name":"Provenance Attestation","inputModes":["application/json"],"description":"Record an action in a hash-chained, append-only evidence ledger. Each attestation extends the provenance chain. Block signatures issued every 100 records using ML-DSA-87 (FIPS 204). Third parties verify the chain without Kevros access.","outputModes":["application/json"]},{"id":"intent-bind","name":"Intent Binding","inputModes":["application/json"],"description":"Bind a declared intent to a command and verify the outcome matches. HMAC-signed binding proves the chain from intent to command to result is unbroken.","outputModes":["application/json"]},{"id":"trust-certificate","name":"Compliance Bundle","inputModes":["application/json"],"description":"Generate a portable compliance evidence package containing hash-chained provenance, intent binding proofs, post-quantum block signatures, and verification instructions. Independently verifiable without Kevros access.","outputModes":["application/json"]},{"id":"media-attest","name":"Media Hash Attestation","inputModes":["application/json"],"description":"Submit a media file hash for cryptographic attestation. Returns a signed certificate proving the hash was recorded at a specific timestamp in the provenance ledger. Useful for content provenance, media integrity, and audit trails.","outputModes":["application/json"]},{"id":"media-verify","name":"Media Hash Verification","inputModes":["application/json"],"description":"Verify a media file hash against a previously issued attestation certificate. Returns the attestation status and certificate details. No charge, no authentication required.","outputModes":["application/json"]},{"id":"media-verify-lookup","name":"Media Certificate Lookup","inputModes":["application/json"],"description":"Look up a media attestation certificate by its certificate ID. Returns the full certificate including hash, timestamp, and provenance chain position. No charge, no authentication required.","outputModes":["application/json"]},{"id":"shield-scan","name":"Prompt Injection Detection","inputModes":["application/json"],"description":"Prompt injection detection via ONNX DeBERTa-v3 classifier. Scans text for injection attacks, jailbreaks, and role hijacking attempts. Returns confidence score, risk level, and HMAC-signed result. $0.01/scan or 10 trial scans/day.","outputModes":["application/json"]},{"id":"mpp-session","name":"MPP Session Create","inputModes":["application/json"],"description":"Create a governed streaming payment session. Declare budget, duration, spending rate limit, and allowed service categories. Returns a signed session token for continuous streaming payments within policy bounds. Every session is recorded in the provenance ledger. $0.02/session. POST /governance/mpp/session","outputModes":["application/json"]},{"id":"mpp-heartbeat","name":"MPP Session Heartbeat","inputModes":["application/json"],"description":"Mid-session drift check during a streaming payment session. Reports current spend, transaction count, active service, and spending rate. Kevros checks for budget overruns, rate limit violations, and unauthorized service usage. Returns session status (active, warning, suspended, expired) and remaining budget/time. No charge. POST /governance/mpp/heartbeat","outputModes":["application/json"]},{"id":"mpp-close","name":"MPP Session Close","inputModes":["application/json"],"description":"Close a streaming payment session and seal the provenance record. Reports final spend, transaction count, and close reason. Returns sealed provenance hash and compliance bundle availability. No charge. POST /governance/mpp/close","outputModes":["application/json"]}],"payment":{"rails":{"pending":[{"id":"x402-solana","note":"Disabled until endpoint-level Solana resources/pricing and the Solana OFAC/compliance gate are complete. Live status is reflected in /payment/discovery and /.well-known/mpp.","status":"pending","transport":"USDC on Solana"},{"id":"tempo","note":"Not currently integrated; do not select. When integration completes it will appear under payment.rails.challenge_capable_candidates and in /.well-known/mpp / /payment/discovery as a challenge-capable candidate.","status":"pending","transport":"Tempo (MPP method)"}],"selection_guidance":["Fetch /payment/discovery (single call) for candidate rail configuration + per-endpoint pricing. Cache for 30s using the returned ETag.","Filter rails where enabled=true only as challenge-capable candidates. Pending rails are advertised under payment.rails.pending and MUST NOT be selected.","Per priced endpoint, /payment/discovery returns a recommended_rail candidate. Prefer it for self-serve 402 payment retries when enabled=true.","Fallback order on rail challenge failure: x402 (Base) -> l402 -> mpp. Re-fetch /payment/discovery before retrying if the pricing_fingerprint has changed.","Fail-closed: if /payment/discovery is unreachable, do not invent rails. Stop and surface the error to the operator."],"challenge_capable_candidates":[{"id":"x402","no_signup":true,"transport":"USDC on Base"},{"id":"l402","no_signup":true,"transport":"Lightning Network"},{"id":"mpp","no_signup":true,"transport":"Stripe Machine Payments"}]},"wallets":{"evm":"0x3190EC7811f9C0Ba8DD454E437C608FE60CDdEB7"},"networks":["eip155:8453"],"protocols":["x402","l402","mpp"],"currencies":["USDC"],"health_url":"https://governance.taskhawktech.com/payment/health","access_flow":{"profile":"kevros-delegation-payment-flow-v1","version":"kevros-delegation-payment-flow-v1","discovery":{"mpp_url":"https://governance.taskhawktech.com/.well-known/mpp","l402_url":"https://governance.taskhawktech.com/.well-known/l402","x402_url":"https://governance.taskhawktech.com/.well-known/x402","payment_health_url":"https://governance.taskhawktech.com/payment/health","agent_authority_url":"https://governance.taskhawktech.com/.well-known/agent-authority","payment_discovery_url":"https://governance.taskhawktech.com/payment/discovery","delegation_authority_url":"https://governance.taskhawktech.com/.well-known/delegation-authority","delegation_issuer_keys_url":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys"},"fail_closed":true,"paid_execution":{"self_serve_scope":"priced public endpoints only","delegation_scheme":"Delegation","self_serve_unpaid_status":402,"delegation_proof_carriage":["Authorization: Delegation <base64url-bounded-authority-token>","Delegation-Proof: :<base64-cose>:","JSON body {\"delegation_proof\": \"<base64url-token>\"}","Content-Type: application/delegation-proof+cose"],"delegation_version_header":"Delegation-Version","accepted_execution_credentials":["rail-payment-credential","X-API-Key","Delegation-Proof"],"governed_unauthenticated_statuses":[401,403],"rail_payment_authorizes_execution":true},"delegation_first":false,"immediate_key_path":{"signup_url":"https://governance.taskhawktech.com/signup","auth_header":"X-API-Key"},"compatibility_profile":"kevros-agent-payment-flow-v1","self_serve_rail_first":true,"governed_authority_first":true,"after_authority_or_payment_verification":{"candidate_rails":["x402","l402","mpp","stripe-stablecoin"],"payment_receipt_required":true,"authority_receipt_required":true,"execution_evidence_required":true}},"description":"Per-call payment discovery for governance evaluations. Listed rails are candidate payment rails. Priced self-serve endpoints return 402 before execution and accept verified x402, L402, MPP, or Stripe stablecoin credentials on retry. Governed or high-authority execution requires X-API-Key or verified Delegation proof. Destination addresses are returned dynamically in discovery/challenge responses; agents should not pin static wallet addresses.","discovery_url":"https://governance.taskhawktech.com/payment/discovery","status_layers":{"rail_discovery":"well-known docs or /payment/* describe configured rail candidates","endpoint_health":"public route responds","payment_receipt":"rail-specific receipt or preimage is required for paid execution","payment_challenge":"selected rail returns protocol-specific payment requirements","authority_required":"governed/high-authority execution requires API key or Delegation proof; self-serve priced endpoints may use a verified rail payment credential","authority_verified":"nonce-bound Delegation proof or bounded self-serve rail credential accepted","execution_evidence":"Kevros evidence binds the authorized action to its outcome"},"min_amount_usd":"$0.01"},"pricing":{"kga":{"standard":"FIPS 204","algorithm":"ML-DSA-87","description":"Kevros Governance Attestation - ML-DSA-87 signed, portable proof of governance. Returned in X-Kevros-KGA response header on paid calls. Any third party can verify with the public key.","public_key_url":"https://governance.taskhawktech.com/.well-known/mpp/pubkey"},"mpp":{"currency":"usd","description":"For priced self-serve endpoints, pay per call with Stripe via MPP and include X-PAYMENT header with MPP credential on retry.","discovery_url":"https://governance.taskhawktech.com/.well-known/mpp","payment_method":"stripe"},"x402":{"currency":"USDC","networks":[{"name":"Base","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","network":"eip155:8453"}],"description":"For priced self-serve endpoints, pay per call with USDC on Base and include X-PAYMENT header on retry.","discovery_url":"https://governance.taskhawktech.com/.well-known/x402"},"model":"per-call","currency":"USD","endpoints":{"bind":"$0.02","batch":"$0.01","attest":"$0.02","bundle":"$0.05","verify":"$0.01","mpp_close":"free","mpp_session":"$0.02","shield_scan":"$0.01","media_attest":"$0.05","media_verify":"free","mpp_heartbeat":"free","verify_outcome":"free","shield_scan_free":"free (10/day)","media_verify_lookup":"free"},"subscriptions":{"starter":{"monthly_usd":29,"included_calls":5000},"enterprise":{"monthly_usd":499,"included_calls":500000},"professional":{"monthly_usd":149,"included_calls":50000}},"payment_methods":["stripe","x402","l402","mpp"]},"version":"0.4.1","identity":{"scheme":"kevros-pqc-v1","algorithms":["ML-DSA-87 (FIPS 204)","SLH-DSA-SHA2-256f (FIPS 205)"],"verify_url":"https://governance.taskhawktech.com/governance/verify-chain/{agent_id}","description":"Cryptographic agent identity backed by dual-PQC-signed provenance chain. Identity is a hash, not a description. Trust is computed, not claimed.","public_keys":"https://github.com/taskhawk-systems/kevros-formal-verification","identity_url":"https://governance.taskhawktech.com/governance/identity/{agent_id}"},"metadata":{"contracts":{"note":"Contract addresses available on request","network":"Base (8453)"},"protocols":["x402","L402","MPP"],"post_quantum":{"algorithm":"ML-DSA-87 (FIPS 204)","public_key_url":"https://governance.taskhawktech.com/.well-known/mpp/pubkey","attestation_header":"X-Kevros-KGA"},"formal_verification":{"fuzz_testing":"Foundry (22 tests, 256 runs)","state_machine":"TLA+ (1.94B states)","smart_contracts":"Certora (6 properties verified)"}},"provider":{"url":"https://www.taskhawktech.com","organization":"TaskHawk Systems"},"security":[{"apiKey":[]},{"x402":[]},{"l402":[]},{"mpp":[]}],"discovery":{"mcp":"https://governance.taskhawktech.com/mcp/","mpp":"https://governance.taskhawktech.com/.well-known/mpp","l402":"https://governance.taskhawktech.com/.well-known/l402","x402":"https://governance.taskhawktech.com/.well-known/x402","openapi":"https://governance.taskhawktech.com/openapi.json","ai_plugin":"https://governance.taskhawktech.com/.well-known/ai-plugin.json","agent_card":"https://governance.taskhawktech.com/.well-known/agent-card.json","for_agents":"https://governance.taskhawktech.com/for-agents","kga_pubkey":"https://governance.taskhawktech.com/.well-known/mpp/pubkey","agent_authority":"https://governance.taskhawktech.com/.well-known/agent-authority","agent_card_legacy":"https://governance.taskhawktech.com/.well-known/agent.json","delegation_authority":"https://governance.taskhawktech.com/.well-known/delegation-authority","delegation_issuer_keys":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys"},"free_tier":{"body":{"agent_id":"your-agent-id"},"method":"POST","signup_url":"https://governance.taskhawktech.com/signup","auto_signup":"SDKs and MCP auto-provision a trial key on first use.","included_calls":1000,"rate_limit_per_minute":10},"description":"Runtime enforcement for autonomous agents. Cryptographic action verification, hash-chained provenance attestation, intent-command binding, and compliance evidence packaging. Every decision is recorded in a tamper-evident ledger. Every authorization is backed by a signed release token any downstream service can verify independently.","availability":{"regions":["US"],"geofence":"US-only","effective_from":"2026-04-19","export_control":"EAR-classification-in-progress","restricted_access":"sanctions, denied-party, prohibited-end-use, and abuse screening required before paid or executable access","international_sales":"direct-agreement-after-review"},"capabilities":{"tags":["runtime-enforcement","provenance","compliance","media","security","prompt-injection"],"streaming":false,"extensions":[{"uri":"https://www.x402.org","params":{"roles":["merchant"]},"required":true,"description":"Publishes x402 USDC on Base, L402 Lightning, and MPP Stripe challenge metadata for self-serve governance evaluations. Payment receipt remains rail-specific. Governed authority remains API-key or Delegation gated. Solana x402 is not advertised until endpoint-level resources and compliance gates are complete."}],"pushNotifications":false},"verification":{"endpoints":{"reputation":{"url":"https://governance.taskhawktech.com/governance/reputation/{agent_id}","method":"GET","description":"Public trust score lookup"},"verify_token":{"url":"https://governance.taskhawktech.com/governance/verify-token","method":"POST","description":"Verify a release token is authentic"},"verify_certificate":{"url":"https://governance.taskhawktech.com/governance/verify-certificate","method":"POST","description":"Verify a compliance bundle"}},"description":"Public verification endpoints. Any agent or service can verify credentials without an API key.","trust_headers":{"X-Kevros-Agent-Id":"Agent identifier","X-Kevros-Release-Token":"Signed release token from verify"}},"authentication":{"mpp":{"spec":"https://paymentauth.org","version":"1.0","protocol":"mpp","description":"Machine Payment Protocol per paymentauth.org for priced self-serve endpoints. Compatibility probes may see no-spend MPP metadata; execution requires a verified Payment credential, X-API-Key, or verified Delegation proof. Solana (USDC) is conditionally advertised at /.well-known/mpp when the OFAC compliance gate permits.","challenge_url":"https://governance.taskhawktech.com/stripe/mpp-challenge","discovery_url":"https://governance.taskhawktech.com/.well-known/mpp","primary_method":"stripe","payment_methods":["stripe"],"legacy_method_aliases":["mpp-fiat"],"payment_methods_pending":[{"note":"Tempo provider is not currently integrated. Agents must not select tempo; it will not respond to MPP challenges. Challenge-configuration status is reflected at /.well-known/mpp and /payment/discovery.","method":"tempo","status":"pending"}]},"l402":{"network":"mainnet","pricing":{"bind":{"usd":"$0.02","sats":30},"attest":{"usd":"$0.02","sats":30},"bundle":{"usd":"$0.05","sats":75},"verify":{"usd":"$0.01","sats":15},"shield_scan":{"usd":"$0.01","sats":15}},"protocol":"l402","description":"Per-call payment via L402 (Lightning Network) for priced self-serve endpoints. A payable L402 path requires macaroon/token plus BOLT11 invoice; discovery-only metadata is not execution.","pricing_source":"https://governance.taskhawktech.com/.well-known/l402","macaroon_format":"dual (v2 binary + base64url JSON)"},"x402":{"version":2,"networks":[{"name":"USDC on Base","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","network":"eip155:8453"}],"protocol":"x402","description":"Per-call payment via x402 USDC on Base for priced self-serve endpoints. API keys and verified Delegation proofs remain accepted for governed access. No-spend probes may see x402 metadata without execution.","facilitator":"https://facilitator.payai.network","amount_human":"$0.01","amount_decimals":6,"amount_per_call":"10000"},"schemes":["delegation","apiKey","x402","l402","mpp"],"delegation":{"scheme":"Delegation","version":"draft-02","protocol":"Delegation","health_url":"https://governance.taskhawktech.com/protocol/427/health","description":"Governed/high-authority execution requires an operator-signed Delegation proof. Priced self-serve POSTs can use verified x402, L402, MPP, or Stripe stablecoin rail credentials.","discovery_url":"https://governance.taskhawktech.com/.well-known/delegation-authority","issuer_keys_url":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","accepted_headers":["Authorization: Delegation <base64url-bounded-authority-token>","Delegation-Proof: :<base64-cose>:","Content-Type: application/delegation-proof+cose"],"challenge_statuses":[401,403],"implementation_version":"0.2.2"},"apiKeyHeader":"X-API-Key"},"agent_authority":{"uri":"https://governance.taskhawktech.com/.well-known/agent-authority","quote_url":"https://governance.taskhawktech.com/agent-authority/quote","health_url":"https://governance.taskhawktech.com/agent-authority/health","description":"Pre-payment authority clearing for autonomous agents. Returns ALLOW, CONSTRAIN, or DENY with a signed authority receipt, bounded spend, approved rails, expiry, request binding, and evidence requirements before settlement.","clearance_url":"https://governance.taskhawktech.com/agent-authority/clear","clearance_type":"authority_preclearance_not_settlement","payment_receipt_required":true,"authority_receipt_required":true,"execution_evidence_required":true},"media_authority":{"audiences":["agent","human"],"endpoints":{"attest":{"url":"https://governance.taskhawktech.com/media/attest","method":"POST","payment":"paid_or_key_backed","price_usd":"$0.05","description":"Issue a media authority certificate for a submitted SHA-256 media hash."},"lookup":{"url":"https://governance.taskhawktech.com/media/verify/{certificate_id}","method":"GET","payment":"free","description":"Lookup certificate JSON or HTML. This finds the certificate but does not verify media bytes."},"revoke":{"url":"https://governance.taskhawktech.com/media/revoke/{certificate_id}","auth":"operator_api_key_or_admin","method":"POST","payment":"none","description":"Revoke a certificate. Payment credentials do not authorize this mutation."},"status":{"url":"https://governance.taskhawktech.com/media/status/{certificate_id}","method":"GET","payment":"free","description":"Read active/revoked state and operator approval state."},"verify":{"url":"https://governance.taskhawktech.com/media/verify","method":"POST","payment":"free","description":"Verify a supplied media hash against a certificate. verified=true requires byte/hash verification."},"approve":{"url":"https://governance.taskhawktech.com/media/approve/{certificate_id}","auth":"operator_api_key_or_admin","method":"POST","payment":"none","description":"Approve or deny certificate use. Payment credentials do not authorize this mutation."},"capabilities":{"url":"https://governance.taskhawktech.com/media/capabilities","method":"GET","payment":"free","description":"Machine-readable media authority contract."}},"does_not_prove":["deepfake detection","legal rights clearance","subject consent verification","C2PA validation","advertising delivery, targeting, spend, conversion, or endorsement","payment settlement or accounting results"],"schema_version":"media-attestation-1.1","certificate_kind":"kevros_media_authority_certificate","layered_verdicts":["integrity","provenance_chain","pqc_signature","device_attestation","c2pa","rights","consent","campaign_approval","policy_authority","ai_model_provenance","revocation"],"payment_boundary":"Paid issuance is separate from free verification/status and operator-only lifecycle mutation.","supports_ad_targeting":false,"payment_receipt_boundary":"Directory health, HTTP 402/427 challenges, crawler traffic, and free verification are not rail-specific payment receipts.","supports_c2pa_validation":false,"supports_deepfake_detection":false,"supports_legal_rights_clearance":false,"supports_ad_delivery_verification":false,"supports_subject_consent_verification":false},"protocolVersion":"0.2.6","securitySchemes":{"mpp":{"type":"http","scheme":"Payment","description":"Pay-per-request via Stripe MPP for priced self-serve endpoints. Compatibility probes may see MPP metadata without execution."},"l402":{"type":"http","scheme":"L402","description":"Pay-per-request via Lightning Network for priced self-serve endpoints. Compatibility probes may see L402 metadata without execution."},"x402":{"type":"http","scheme":"bearer","description":"Pay-per-request via x402 USDC on Base for priced self-serve endpoints. Compatibility probes may see payment metadata without execution."},"apiKey":{"in":"header","name":"X-API-Key","type":"apiKey","description":"Trial API key (1,000 calls/month). Obtain via POST https://governance.taskhawktech.com/signup"}},"delegation_authority":{"uri":"https://datatracker.ietf.org/doc/html/draft-mcgraw-httpapi-agent-budget-03","byok_v1":true,"required":true,"health_uri":"https://governance.taskhawktech.com/protocol/427/health","description":"Delegation authority: operator-signed bounded-authority proofs gate governed/high-authority requests. Self-serve priced endpoints may use verified rail payment credentials. BYOK reference implementation.","spec_version":"draft-03","discovery_uri":"https://governance.taskhawktech.com/.well-known/delegation-authority","issuer_keys_uri":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","managed_signing":false,"rails_supported":["api_key","free","l402","x402","mpp"],"required_for_governed_authority":true,"required_for_executable_paid_post":false},"product_release_version":"4.6.3","compliance_access_policy":{"fail_closed":true,"availability":"United States commercial access; international access only by direct agreement after applicable review.","export_control":"Cryptographic software subject to U.S. export-control review. Final classification is maintained outside public discovery metadata.","public_discovery":"Read-only metadata for integration discovery.","screening_required":["United States sanctions and restricted-party screening","export-control and prohibited-end-use review","wallet, payment, and account-abuse controls where applicable"],"public_data_boundary":"Public discovery endpoints do not expose ITAR, CUI, federal proposal, customer, partner-confidential, private-key, or classified technical data.","paid_or_executable_access":"Self-serve priced endpoints accept a verified rail payment credential, API key, or verified Delegation proof. Governed/high-authority execution requires API key or Delegation proof."}},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-11T16:40:50.417211+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agent Tools Catalog","source_url":"https://agent-tools.cloud","last_check":{"checked_at":"2026-10-11T16:40:50.417211+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://governance.taskhawktech.com/.well-known/agent-card.json"],"also_observed_in":[],"skills":[{"skill_id":"action-verify","name":"Action Verification","description":"Verify an action against policy bounds before execution. Returns ALLOW, CONSTRAIN, or DENY with a signed release token. Downstream services verify the token independently. Fail-closed: verification failure results in DENY.","tags":[],"quality_warning":false},{"skill_id":"trust-certificate","name":"Compliance Bundle","description":"Generate a portable compliance evidence package containing hash-chained provenance, intent binding proofs, post-quantum block signatures, and verification instructions. Independently verifiable without Kevros access.","tags":[],"quality_warning":false},{"skill_id":"intent-bind","name":"Intent Binding","description":"Bind a declared intent to a command and verify the outcome matches. HMAC-signed binding proves the chain from intent to command to result is unbroken.","tags":[],"quality_warning":false},{"skill_id":"mpp-close","name":"MPP Session Close","description":"Close a streaming payment session and seal the provenance record. Reports final spend, transaction count, and close reason. Returns sealed provenance hash and compliance bundle availability. No charge. POST /governance/mpp/close","tags":[],"quality_warning":false},{"skill_id":"mpp-session","name":"MPP Session Create","description":"Create a governed streaming payment session. Declare budget, duration, spending rate limit, and allowed service categories. Returns a signed session token for continuous streaming payments within policy bounds. Every session is recorded in the provenance ledger. $0.02/session. POST /governance/mpp/session","tags":[],"quality_warning":false},{"skill_id":"mpp-heartbeat","name":"MPP Session Heartbeat","description":"Mid-session drift check during a streaming payment session. Reports current spend, transaction count, active service, and spending rate. Kevros checks for budget overruns, rate limit violations, and unauthorized service usage. Returns session status (active, warning, suspended, expired) and remaining budget/time. No charge. POST /governance/mpp/heartbeat","tags":[],"quality_warning":false},{"skill_id":"media-verify-lookup","name":"Media Certificate Lookup","description":"Look up a media attestation certificate by its certificate ID. Returns the full certificate including hash, timestamp, and provenance chain position. No charge, no authentication required.","tags":[],"quality_warning":false},{"skill_id":"media-attest","name":"Media Hash Attestation","description":"Submit a media file hash for cryptographic attestation. Returns a signed certificate proving the hash was recorded at a specific timestamp in the provenance ledger. Useful for content provenance, media integrity, and audit trails.","tags":[],"quality_warning":false},{"skill_id":"media-verify","name":"Media Hash Verification","description":"Verify a media file hash against a previously issued attestation certificate. Returns the attestation status and certificate details. No charge, no authentication required.","tags":[],"quality_warning":false},{"skill_id":"shield-scan","name":"Prompt Injection Detection","description":"Prompt injection detection via ONNX DeBERTa-v3 classifier. Scans text for injection attacks, jailbreaks, and role hijacking attempts. Returns confidence score, risk level, and HMAC-signed result. $0.01/scan or 10 trial scans/day.","tags":[],"quality_warning":false},{"skill_id":"provenance-attest","name":"Provenance Attestation","description":"Record an action in a hash-chained, append-only evidence ledger. Each attestation extends the provenance chain. Block signatures issued every 100 records using ML-DSA-87 (FIPS 204). Third parties verify the chain without Kevros access.","tags":[],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":15,"passed":15},"recent_checks":[{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T16:40:50.417211+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T14:14:14.890047+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T11:53:33.947791+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T09:44:35.765688+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T07:34:27.208537+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T05:00:56.180193+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T02:42:45.530255+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-11T00:25:48.720671+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-10T22:06:58.573834+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-10T19:49:55.040477+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-10T17:32:50.326802+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","checked_at":"2026-10-10T15:15:10.950324+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-11T16:40:50.417211+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-11T09:44:35.765688+00:00","state":"unconfirmed","http_status":405,"detail":"Endpoint response did not match the JSON-RPC request"},"x402_price_check":null,"events":[],"relationships":[],"verification":{"agent_card_url":"https://governance.taskhawktech.com/.well-known/agent-card.json","last_successful_card_check":"2026-10-11T16:40:50.417211+00:00","latest_card_check":{"checked_at":"2026-10-11T16:40:50.417211+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-11T16:40:50.417211+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-11T16:40:50.417211+00:00","endpoint_tls_reachable":true,"protocol_check_state":"unconfirmed","protocol_checked_at":"2026-10-11T09:44:35.765688+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}