{"protocol":"ATC","version":"1.1.0","description":"Agent Trust Card — SSL certificates for AI agents. Cryptographically signed by MarketNow Sentinel CA.","cryptography":{"algorithm":"Ed25519 (RFC 8032)","signature_format":"detached, hex-encoded","canonical_json":"RFC 8785 JCS (JSON Canonicalization Scheme)"},"endpoints":{"issue":"POST /api/atc {action:\"issue\", agent_id, public_key, capabilities?, skill_id?, wallet_address?}","verify":"GET /api/atc?action=verify&card_id=ATC-2026-XXXXX","envelope":"GET /api/atc?action=envelope&card_id=ATC-2026-XXXXX (NEW — returns exact signed bytes for external verification)","verify_receipt":"GET /api/atc?action=verify-receipt&receipt_id=rcpt_xxxxxxxxxxxx","verify_vibe_receipt":"GET /api/atc?action=verify-vibe-receipt (fetches Vibe sample + verifies) or POST {action: \"verify-vibe-receipt\", receipt: {...}}","revoke":"POST /api/atc {action:\"revoke\", card_id, reason}","list":"GET /api/atc","ca_key":"GET /api/atc?action=ca-key","spec":"GET /api/atc?action=spec","translate":"POST /api/atc {action:\"translate\", from, to, message}","resign_all":"POST /api/atc?action=resign-all (admin only — requires x-ca-secret header)"},"schema_version":"1.1.0","decision_authority":"consumer","what_the_atc_answers":["identity binding (Ed25519 public key)","issuer (which CA vouches for the binding)","validity state (valid | revoked, with timestamp + reason)","review evidence (Sentinel score, layers passed, audit timestamp, artifact hash)"],"what_the_atc_does_NOT_answer":["should this agent be trusted? (runtime policy decision)","is this agent safe for MY context? (consumer decides)","will this agent behave at runtime? (covered by L3, separate layer)"],"sentinel_review_score":"Review evidence (0-10). Derived from Sentinel certificate. NOT a trust verdict.","action_receipts":{"description":"Signed delivery proof for completed purchases. Closes the gap identified with @doteyeso-ops (Vibe) on PipedreamHQ/awesome-mcp-servers#94.","issue":"Emitted automatically by POST /api/agent-purchase on successful instant_purchase or direct_purchase.","verify":"GET /api/atc?action=verify-receipt&receipt_id=rcpt_xxxxxxxxxxxx","storage":"_data/receipts/{receipt_id}.json (public GitHub repo, same audit-ledger pattern as ATC)","interop":{"vibe_decision_ref":"mandate_id field","vibe_settle_coordinate":"settle_txhash field","vibe_action_receipt":"receipt_id field"}},"persistence":"ATCs persisted to _data/atc/{card_id}.json; receipts to _data/receipts/{receipt_id}.json. Both in the public GitHub repo — anyone can audit the ledger.","schema_changelog":["v1.1.0 (2026-07-25): renamed trust.sentinel_score → trust.sentinel_review_score (review evidence, not verdict). Added decision_authority=\"consumer\". Added action-receipt endpoint. sentinel_score kept as backward-compat alias.","v1.0.0: original schema (sentinel_score, no decision_authority, no receipts)."]}