Agent Bench · Agentic Access

Agent Bench Agentic Access

x-agentic-access searched

Agent Bench exposes 2 API operations that an AI agent could call, of which 1 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.

By consequence: 1 read and 1 physical.

1 operation are classed safety-critical and should require human-in-the-loop approval at runtime.

Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.

AgentsA2AMCPAgentic CommerceDNS-AIDTravelFlightsPaymentsAgent IdentityProof of ConceptAgent-Native
Operations: 2 Acting: 1 Human-in-the-loop: 1 Method: searched

By consequence

read 1 physical 1

Highest-consequence actions

The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.

MethodPathConsequenceHuman-in-loop
physical required

Source

Agentic Access

agenthaven-dev-agentic-access.yml Raw ↑
generated: '2026-09-19'
method: searched
source: https://travel.agenthaven.dev/
derived_from:
- a2a/agenthaven-dev-agent-card.json (skills[].security, securitySchemes.bearer)
- mcp/agenthaven-dev-mcp-tools.json (tool descriptions, const constraints, evidence/audit fields)
- https://travel.agenthaven.dev/health (guests policy, mandate_issuers, verifiers)
- https://provedby.dev/contracts/guest-buyer.md (mandate jti, TTL, revocation)
description: >-
  x-agentic-access execution contracts for the two operations Agent Bench exposes. derive-agentic-access.py
  was not run — there is no OpenAPI — and this file is NOT a heuristic classification: the provider publishes
  real agent-access guidance (who may call what, under whose authority, with what cap, for how long, audited
  where), and every field below cites the surface it was read from. Only the action-class / consequence labels
  are ours, applied from the Curity vocabulary to what the provider states. Reviewed per deployment; audience
  is left null.
summary:
  operations: 2
  by_action_class: {connected: 1, acting: 1}
  by_consequence: {read: 1, physical: 1}
  human_in_the_loop_required: 1
  note: >-
    The one acting operation moves money in name only — Stripe test mode — so its real-world consequence today
    is nil; it is classified as physical because the contract is written for a purchase (payment intent, EUR
    amounts, mandates with spending caps) and a production deployment of the same contract would be one.
operations:
- operation: search_flights
  protocol: [MCP tools/call, A2A message/send action search_flights]
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    audience: null
    authentication: none — "search_flights and tools/list are open" (card securitySchemes.bearer description)
    token: {required: false}
    quota: shared anonymous budget 40/day, 120/month; authorised searches exempt (docs; /health counters)
    escalation: {human-in-the-loop: none}
    audit: required — one quote.created ledger entry per option returned, with facts.actor null for anonymous calls (ledger reading guide)
    purpose-binding: correlation_id (optional UUID v4) and exercise (optional test-vector label) travel into the ledger
  provider_statements:
  - 'agent card skills[0]: "No authorization needed."'
  - 'ledger reading guide: "facts.actor null with no facts.authorization_id means the search was anonymous (allowed since 2026-09-14): nobody vouched for the caller, and any authorization that covers the quote may check it out."'
- operation: create_checkout
  protocol: [MCP tools/call, A2A message/send action create_checkout]
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    authentication: 'http bearer JWT; skill security [{bearer: [commerce:purchase]}]'
    token:
      forms: [request envelope (typ request+jwt) signed by the agent's own attested key + third-party mandate (typ mandate+jwt), operator-issued JWT (iss agent-bench-demo-issuer, aud agent-bench, scope commerce:purchase), guest self-issued mandate under a DNSSEC-published key]
      proof-of-possession: 'yes for form (1) and guests — the mandate is "bound to the quote and to that key" and the envelope is signed per call'
      max-ttl: 'guest mandates at most 600 s (health guests.mandate_max_seconds); quote valid 10 minutes; operator-token lifetime not published'
      single-use: 'mandate jti "never reused: the mandate buys once" — replay refused as mandate_consumed'
      spending-cap: 'carried in the token/mandate — "a spending cap, a currency and a deadline set by the buyer''s human; a request above the cap is refused, and the refusal is written to the ledger"; guests capped at 1000.00 EUR per purchase'
      revocation: 'live check of the mandate at its issuer (guest-buyer contract §5; refusal mandate_revoked observed)'
    escalation:
      human-in-the-loop: required
      basis: 'the authority to spend comes from a mandate whose cap, currency and deadline are "set by the buyer''s human"; the merchant does not issue self-service tokens ("issued by this merchant''s operator on request")'
      triggers: [above-cap, expired-mandate, consumed-mandate, revoked-mandate, unknown-signer, quote-hash-mismatch]
    audit: required — payment_intent.created and checkout.completed (or request.refused) ledger entries, hash-chained and ES256-signed; receipt_jws returned to the caller; correlation_id joins the chain
    reversibility: none — no cancel/refund/void operation (see conventions/agenthaven-dev-conventions.yml)
    dry-run: none — the exercise label "changes nothing about how the call is checked"
  provider_statements:
  - 'agent card skills[1]: "Needs the bearer authorization described in securitySchemes.bearer."'
  - 'docs step 2: "The token carries a spending cap, a currency and a deadline set by the buyer''s human; a request above the cap is refused, and the refusal is written to the ledger."'
  - 'tools/list create_checkout: "Turns the quote into a payment intent and stops there: no ticket is issued. … Test mode: no real card, no real money."'
verification_for_agents:
  responder_identity: 'every output carries evidence {merchant_id const demo-travel-seller, merchant_domain const travel.agenthaven.dev, agent_card_sha256, signer {spiffe_id, kid, key_url}}; the card digest is pinned in the DNSSEC-signed SVCB record and the signer key in /.well-known/spiffe-bundle.json'
  third_party_verifiers: [https://provedby.dev]

Work with this as data

Every access contract here is available over the APIs.io API and to AI agents over MCP. Agentic Access is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for agentic access

3 MCP tools reach this
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
Search the catalog
curl "https://apis.io/api/v1/search?q=agenthaven-dev-agentic-access&limit=10"
Everything under a tag
curl "https://apis.io/api/v1/tags/agenthaven-dev-agentic-access"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.