Endpoint
scvd.store/api/buy/signature_agent_card
Task: Show origins my crawler's Web Bot Auth key directory is set up right, with somebody who is not me saying so. Returns: A signed JSON card — verdict (directory_ready, not_ready, unreachable or refused), every check from the directory battery by name including the proof-of-possession verification, dated, its evidence hash bound into the purchase certificate's attests field — plus a stable card URL serving the record free forever. Instant; one GET at one moment, never monitoring. Price: $0.99 USDC (x402 v2; network from the current quote). Latency: delivered in the purchase response, same request. Verify: GET /api/verify/{id} — free, unlimited, forever (live sample: cert_4dww28dx5j). Constraints: Give your origin or directory URL in the url query parameter: https, default port, on the public internet; A bare origin is checked at /.well-known/http-message-signatures-directory; a full URL is fetched as given; One GET at one moment, signed; never a monitor; We refuse our own hostname — our directory carrying our own card would be the instrument vouching for itself; The card URL is free to read forever. The Calling Card, You stood up Web Bot Auth: your crawler signs its requests (RFC 9421) and your key directory hangs at /.well-known/http-message-signatures-directory. This is somebody who is not you saying it actually works. Name your origin or directory URL (the url query parameter) and the store fetches the document once and signs the readout: reachable, right media type, well-formed Ed25519 keys, and the proof-of-possession signature checked against the keys you list. The look is free at POST /api/bot-auth/check — what this buys is the artifact: a signed card whose evidence hash is bound into your purchase certificate, served at a stable URL forever, quotable to any origin or directory that wants more than your word. One fetch, one moment. Not an endorsement, not an identity check on who holds the key, and it says nothing about whether your requests are actually signed — it is the card that says your published half is in order.
Score
The score is built from observations we collect ourselves: how the endpoint responds, what the envelope contains, how stable the price and the recipient are, who pays and how often. It is deterministic — the same input always produces the same result.
We do not publish the exact methodology yet. If you own this endpoint, write to us and we will show you, item by item, what drags the score down.
Recent probes
| When | Code | Latency | Scheme and network | Recipient | Price | Findings |
|---|---|---|---|---|---|---|
| 5h ago | 402 | 44 ms | exact eip155:8453 |
0xDD35…9bd0 | 0.990000 | clean |
| 12h ago | 402 | 28 ms | exact eip155:8453 |
0xDD35…9bd0 | 0.990000 | clean |
| 4d ago | 402 | 23 ms | exact eip155:8453 |
0xDD35…9bd0 | 0.990000 | clean |
| 4d ago | 402 | 28 ms | exact eip155:8453 |
0xDD35…9bd0 | 0.990000 | clean |
Reference
| URL | https://scvd.store/api/buy/signature_agent_card |
| Sources | bazaar well-known |
| Recipient per catalogue | 0xDD350976B8cfFc65938C0464d39A2C78BE079bd0 |
| Price per catalogue | 0.990000 |
| Machine access | /v1/endpoint · /full · badge |
Is this your endpoint?
The score is built only from public observations. If something we recorded is wrong — say our prober hit you during maintenance — write to us. We will recheck and publish your reply next to the score.
We do not delete accurate observations. The prober makes at most one request per second per host and only asks for the payment challenge — it never pays and never takes content.