Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
243 changes: 243 additions & 0 deletions tests/utils/signing_gate_card_20260928.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,243 @@
{
"name": "MCP Verification Gate",
"description": "Checks whether an MCP server exists, publishes an agent card, discloses who pays it, and returns identical output for identical input. Free. Conformance and disclosure only; this gate does not verify that any price returned by a checked server is correct.",
"supportedInterfaces": [
{
"url": "https://gate.horizonshield.dev/a2a",
"protocolBinding": "JSONRPC",
"protocolVersion": "1.0"
},
{
"url": "https://gate.horizonshield.dev/a2a",
"protocolBinding": "JSONRPC",
"protocolVersion": "0.3"
}
],
"url": "https://gate.horizonshield.dev/a2a",
"provider": {
"organization": "The HORIZ音s Co., Ltd.",
"url": "https://shield.the-horizons-innovation.com",
"legalEntity": {
"registry": "JP",
"scheme": "houjin-bango",
"id": "7021001075279",
"name": "The HORIZ音s Co., Ltd."
}
},
"version": "0.4.17",
"protocolVersion": "1.0",
"capabilities": {
"streaming": false,
"pushNotifications": false,
"extensions": [
{
"uri": "https://gate.horizonshield.dev/ext/conduct/v1",
"description": "Who pays this agent, where its measured conduct record lives, and where to file a witness walk. The specification is served at the URI.",
"required": false,
"params": {
"compensation": {
"paid_by": "buyer",
"referral_fee": false,
"listing_fee": false,
"success_fee_pct": 0,
"disclosure_url": "https://shield.the-horizons-innovation.com/yakumo/plans/"
},
"measured_endpoints": [
"https://gate.horizonshield.dev/mcp"
],
"conduct_record": "https://gate.horizonshield.dev/history?endpoint=https%3A%2F%2Fgate.horizonshield.dev%2Fmcp",
"verdict_recipe": "https://gate.horizonshield.dev/spec",
"witness_intake": "https://ledger.horizonshield.dev/witness",
"register": "https://gate.horizonshield.dev/register",
"identity": {
"kind": "did",
"ref": "did:web:gate.horizonshield.dev"
},
"witness_policy": {
"reciprocal": true
},
"witness_reply": {
"transport": "a2a",
"answers": "https://gate.horizonshield.dev/a2a",
"request_schema": "nenrin-witness-request-v1",
"reply_schema": "nenrin-witness-observation-v1",
"key_url": "https://gate.horizonshield.dev/keys/witness.json",
"surfaces": [
"health.gate_commit",
"agent-card.signature",
"well-known.jwks",
"well-known.openai-apps-challenge",
"ext.conduct-v1.spec",
"keys.agreement",
"keys.witness",
"keys.operator",
"well-known.did"
],
"note": "When drawn, this gate measures the listed public surfaces of the requested endpoint from its own vantage and returns one Ed25519-signed nenrin-witness-observation-v1 (the key served at key_url, conduct-v1.1 section 11.4). It refuses to witness itself (self_witness) and refuses non-public targets. reciprocal here means it answers a draw; it does not initiate an unprompted caller_card walk-back."
},
"rings": {
"spec": "https://github.com/ogasurfproject-jpg/horizon-shield/blob/main/workers/hs-ledger/nenrin/NENRIN_SPEC_v1.md",
"spec_sha256": "9ccba2e325fd2a555fcdb2dec519b8c6bf7a669064674846aea98ecfff824e3d",
"base": "https://raw.githubusercontent.com/ogasurfproject-jpg/mcp-conduct-register/main/rings/",
"path": "<slug>/<YYYY-MM>.json",
"slug": "endpoint URL without https://, lower case, every run of characters outside [a-z0-9] replaced by one hyphen, hyphens trimmed at both ends",
"ledger": "https://ledger.horizonshield.dev/ledger"
}
}
},
{
"uri": "https://gate.horizonshield.dev/ext/legal-entity/v1",
"description": "The legal entity that answers for this agent, declared inside the signed bytes. The specification is served at the URI.",
"required": false,
"params": {
"registry": "JP",
"scheme": "houjin-bango",
"id": "7021001075279",
"name": "The HORIZ音s Co., Ltd.",
"lookup_url": "https://www.houjin-bangou.nta.go.jp/henkorireki-johoto.html?selHouzinNo=7021001075279"
}
}
]
},
"defaultInputModes": [
"text/plain"
],
"defaultOutputModes": [
"application/json",
"text/plain"
],
"securitySchemes": {
"operator": {
"apiKeySecurityScheme": {
"location": "header",
"name": "x-sweep-token",
"description": "Operator-only routes (POST /sweep, POST /register/quarantine, POST /mould, DELETE /watch, the paid tier of POST /watch). No skill on this card requires it: the A2A interface at /a2a and the MCP interface at /mcp are public and unauthenticated."
}
}
},
"securityRequirements": [
{}
],
"compensation": {
"paid_by": "buyer",
"referral_fee": false,
"listing_fee": false,
"success_fee_pct": 0,
"disclosure_url": "https://shield.the-horizons-innovation.com/yakumo/plans/"
},
"preferredTransport": "JSONRPC",
"skills": [
{
"id": "check",
"name": "Conformance check",
"description": "POST /check with an MCP endpoint URL, or call the check_conformance tool over MCP at /mcp. Returns a verdict with a recomputable SHA-256. Over A2A (SendMessage at /a2a), a text part carrying an MCP endpoint URL returns this gate's current register reading for it (the same bytes as GET /is-verified): verified true only on a full pass, null otherwise, never false.",
"tags": [
"mcp",
"verification",
"conformance",
"disclosure"
],
"examples": [
"Check https://example.com/mcp for conformance",
"Does this server exist, publish an agent card, and return identical output for identical input?"
],
"inputModes": [
"text/plain",
"application/json"
],
"outputModes": [
"application/json"
]
},
{
"id": "verify",
"name": "Verdict verification",
"description": "Recompute the SHA-256 of a verdict this gate issued, so you do not have to trust the issuer. Available as the verify_verdict tool over MCP.",
"tags": [
"verification",
"tamper-evident",
"recomputable"
],
"examples": [
"Verify this verdict hashes to its own record_sha256",
"Recompute the digest of a verdict returned by check"
],
"inputModes": [
"application/json"
],
"outputModes": [
"application/json"
]
},
{
"id": "conditions",
"name": "Verification conditions",
"description": "Return the exact conditions this gate measures (MCP reachability, agent card, compensation disclosure, deterministic output) and how each verdict is recomputed. The get_conditions tool over MCP and GET /spec serve the same methodology.",
"tags": [
"methodology",
"transparency",
"spec"
],
"examples": [
"What does this gate actually check?",
"How is a verdict recomputed independently?"
],
"inputModes": [
"text/plain"
],
"outputModes": [
"application/json"
]
},
{
"id": "is-verified",
"name": "Verification status",
"description": "Report whether an endpoint's latest measurement passed all measured conditions. Returns true or null (state: verified, pending, held, watched, absent), never false. Available as the is_verified tool over MCP.",
"tags": [
"verification",
"status",
"honest-null"
],
"examples": [
"Is https://example.com/mcp currently verified?",
"What is this endpoint's latest state on the register?"
],
"inputModes": [
"text/plain"
],
"outputModes": [
"application/json"
]
},
{
"id": "lookup",
"name": "Register lookup",
"description": "Look up an endpoint's record on the public register: its latest verdict, state, and record SHA-256, with a recompute URL. Available as the lookup_server tool over MCP.",
"tags": [
"register",
"lookup",
"recomputable"
],
"examples": [
"Look up the record for https://example.com/mcp",
"Find the latest verdict hash for this endpoint"
],
"inputModes": [
"text/plain"
],
"outputModes": [
"application/json"
]
}
],
"signatures": [
{
"protected": "eyJhbGciOiJFUzI1NiIsInR5cCI6IkpPU0UiLCJraWQiOiJocy0yMDI2LTA5Iiwiamt1IjoiaHR0cHM6Ly9nYXRlLmhvcml6b25zaGllbGQuZGV2Ly53ZWxsLWtub3duL2p3a3MuanNvbiJ9",
"signature": "XxE-am8AERjp58y72N4jx6mk3wbxyoSv635yeFALY7dkbOs26OE2neHBCA5rAP1K9xuWMyulYCPIuhON4-0QwA"
},
{
"protected": "eyJhbGciOiJFUzI1NiIsInR5cCI6IkpPU0UiLCJraWQiOiJocy0yMDI2LTA5Iiwiamt1IjoiaHR0cHM6Ly9nYXRlLmhvcml6b25zaGllbGQuZGV2Ly53ZWxsLWtub3duL2p3a3MuanNvbiJ9",
"signature": "Fw5bTIYhj9EXUMyq8viKoi2qnA3S3IsrSwsi-uw3J7BrwcMIVqu0tOnyDqrqR-yv2zzm3-_eAFh3zCa03FV-xA"
}
]
}
13 changes: 13 additions & 0 deletions tests/utils/signing_gate_jwks_20260928.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"keys": [
{
"kty": "EC",
"x": "CytwnuXFtXi7PFCcF-TCbvW5OgOg4KuWRLeRvdfHWLs",
"y": "Zha3FI2QplMaGveXjrIg8PxrZ6dTjHmESoGs88uAIiA",
"crv": "P-256",
"kid": "hs-2026-09",
"alg": "ES256",
"use": "sig"
}
]
}
Loading
Loading