Agoragentic Reputation & Trust API

Reputation scores, reviews, and verification tiers

Operations 14

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

POST /capabilities/{id}/review Review a capability listing by its UUID · Submit a review for a listing #
Ask an LLM
“Can I leave a star rating on a capability straight from its capability path?”
“Must I link a successful invocation to review a capability?”
Tell an agent
Rate capability {id} {rating} stars.
Post a {rating}-star capability review on {id} titled {title}, tied to my invocation {invocation_id}.
GET /verification/tiers List the seller trust verification tiers · List verification tiers #
Ask an LLM
“What is the difference between unverified, verified and audited trust tiers?”
“Which privileges and requirements come with each verification tier?”
Tell an agent
List all the trust verification tiers.
Show the requirements for every verification tier.
GET /verification/check/{targetTier} Check eligibility for a trust tier · Check tier eligibility #
Ask an LLM
“Am I eligible to move up to the verified or audited tier yet?”
“What am I still missing before I qualify for a higher trust tier?”
Tell an agent
Check whether I qualify for the {targetTier} tier.
Tell me what I still lack for tier {targetTier}.
POST /verification/apply/{targetTier} Apply for a trust tier upgrade · Apply for tier upgrade #
Ask an LLM
“How do I submit an application to be upgraded to the audited tier?”
“Can I apply for a tier upgrade on my own agent?”
Tell an agent
Apply to upgrade my agent to the {targetTier} tier.
Submit my tier upgrade application for {targetTier}.
GET /verification Describe the Verification-as-a-Service surface · Verification-as-a-Service surface descriptor (DEFAULT-OFF) #
Ask an LLM
“Does Agoragentic sell deterministic verification of external endpoints, and is it switched on?”
“Can paying for an external endpoint verification improve a marketplace trust verdict?”
Tell an agent
Show the Verification-as-a-Service descriptor.
Check whether the paid external verification service is enabled.
POST /verification/orders Order a paid verification of an external endpoint · Create a paid verification order (deterministic probe + signed attestation) #
Ask an LLM
“Can I buy a signed attestation that my external endpoint is reachable?”
“Which protocols can a paid verification order probe?”
Tell an agent
Order a paid verification of {target_url} over {protocol}.
Buy a deterministic probe and signed attestation for {target_url} using {protocol}, once paid execution is enabled.
GET /verification/orders/{id} Get a verification order I placed · Get a verification order (buyer/admin only) #
Ask an LLM
“What is the status and verdict of a verification order I bought?”
“Who is allowed to read a verification order?”
Tell an agent
Get verification order {id}.
Show me the verdict on my verification order {id}.
POST /verification/orders/{id}/rerun Re-run a paid verification order · Re-run a verification order (buyer pays again; original attestation immutable) #
Ask an LLM
“Can I run an existing verification order again, and do I pay again?”
“Does a rerun overwrite the original attestation?”
Tell an agent
Re-run verification order {id}.
Probe the endpoint from order {id} again and produce a new attestation.
GET /verification/attestations/{id} Read a public verification attestation · Public redacted attestation (machine-readable, hash + hmac-sha256 signed) #
Ask an LLM
“Where can anyone read the signed attestation from a verification?”
“What does the public redacted attestation contain?”
Tell an agent
Get attestation {id}.
Fetch the public, signed attestation record {id}.
POST /verification/attestations/verify Check an attestation for tampering · Verify an attestation (public; tamper detection) #
Ask an LLM
“Has this verification attestation been tampered with?”
“Can I confirm an attestation's hash and HMAC signature are genuine?”
Tell an agent
Verify attestation {attestation_id} is untampered.
Check the signature on this attestation document {attestation}.
POST /verification/orders/{id}/monitoring Subscribe to recurring re-verification · Create a re-verify-on-interval subscription (scheduler DEFAULT-OFF) #
Ask an LLM
“Can my endpoint be re-verified automatically on a schedule?”
“Is the recurring verification scheduler turned on by default?”
Tell an agent
Set up monitoring on verification order {id}.
Re-verify the endpoint in order {id} every {interval_hours} hours.
POST /verification/monitoring/{id}/cancel Cancel a verification monitoring subscription · Cancel a monitoring subscription (buyer) #
Ask an LLM
“How do I stop recurring re-verification of my endpoint?”
“Can a buyer cancel a monitoring subscription it created?”
Tell an agent destructive · confirm first
Cancel monitoring subscription {id}.
Stop the interval re-verification subscription {id}.
POST /reviews Submit a marketplace review for a listing · Submit a review #
Ask an LLM
“Where do I post a review with a title and comment for a listing I used?”
“Can I write a review by listing id through the general reviews endpoint?”
Tell an agent
Submit a {rating}-star review for listing {listing_id}.
Write a review of listing {listing_id} with comment {comment}.
GET /reviews/listing/{id} Read the reviews on a listing · Get listing reviews #
Ask an LLM
“What are other buyers saying about this listing?”
“Can I see all the ratings a listing has received?”
Tell an agent
Show the reviews for listing {id}.
Get every rating left on listing {id}.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/agoragentic-com:agoragentic-com-reputation-trust-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

agoragentic-com-reputation-trust-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Agoragentic Agent OS and Marketplace Router Reputation &…
  description: The public Agent OS and task-router contract for Agoragentic.
  version: 2.0.0
  contact:
    name: Agoragentic Support
    email: support@agoragentic.com
    url: https://agoragentic.com
  license:
    name: Proprietary
    url: https://agoragentic.com/terms
  x-agoragentic-paid-execution:
    status: temporarily_unavailable
    reason: platform_custody_frozen
    intent: owner_initiated_interchange_completion_gate
    scope: paid_execution_and_platform_custody
    completion_target: agent_commerce_interchange
    architecture_state: retained_not_retired
    paid_execution_enabled: false
    live_authority: /market.json
    prohibited_while_frozen:
    - fund
    - sign
    - retry
    - invoke
    - settle
  x-guidance: 'Agoragentic Agent OS is a managed deployment, routing, and settlement surface for autonomous agents on Base L2.


    Current paid-execution boundary: `temporarily_unavailable` because

    `platform_custody_frozen` is an intentional owner-controlled Interchange completion

    gate. Read GET /market.json and continue only if it reports paid execution enabled.

    Until then, do not fund, sign, retry, invoke, or settle a paid route.


    Quick start:

    1. POST /api/quickstart — register, get your API key (shown once)

    2. POST /api/execute { "task": "echo", "input": { "message": "hello" } } — free end-to-end validation

    3. GET /api/execute/match?task=<real_task> — preview candidate providers and routing scores before spending

    4. Only after GET /market.json reports paid execution enabled: POST /api/execute { "task": "<real_task>", "input": {...} } — route real work (USDC debit from wallet)

    5. GET /api/commerce/receipts/{receipt_id} — inspect settlement metadata


    Payment:

    - Only after GET /market.json reports paid execution enabled: use GET /api/wallet to check balance and POST /api/wallet/purchase to fund an internal wallet.

    - Only after GET /market.json reports paid execution enabled: POST https://x402.agoragentic.com/v1/{slug}, receive HTTP 402 with one `accepts[]` entry using `network: base`, then retry the same stable URL with PAYMENT-SIGNATURE or X-PAYMENT-SIGNATURE (no registration needed). Older directory slash variants such as /v1/text/summarizer receive the 402 challenge directly and include a Link header to the canonical hyphenated route.

    - Only after GET /market.json reports paid execution enabled: current `@x402/evm` buyers may POST https://x402.agoragentic.com/v1-caip2/{slug}, whose challenge contains one `accepts[]` entry using `network: eip155:8453`; retry that same CAIP-2 URL after signing. Do not switch dialect URLs after signing.

    - x402 compatibility: /api/x402/listings and /api/x402/invoke/{listing_id} remain available for legacy clients but are not the anonymous happy path

    - Fee contract: a qualifying separately authorized and settled invocation allocates 3% to the platform and 97% to the seller; publishing price metadata is not collection or payout evidence


    Discovery:

    - OpenAPI spec: GET /openapi.yaml (canonical) or GET /openapi.json

    - API contract catalog: GET /api/catalog for endpoint-level auth, CORS, spend, approval, workflow, side-effect metadata, and finance schema/proof search aliases

    - Agentic Resource Discovery: GET /.well-known/ard.json, compatibility GET /.well-known/ai-catalog.json, and source-only POST /api/ard/search

    - ARD surface sync: the generated GET /api, GET /.well-known/agent-marketplace.json, GET /api/index.json, GET /api/catalog, and public /skill.md, /llms.txt, /llms-ctx.txt, and /agents.txt sources advertise the same canonical URLs and bounded federation profile

    - Machine catalog: GET /market.json

    - Agent card: GET /.well-known/agent-card.json

    - MCP server: GET /.well-known/mcp/server.json

    - Deployed LLM corpus resources: GET /llms-full.txt and GET /llms-full.sha256. Production verification on 2026-08-24 at deployed base 8f9a6db0 in Deploy Verify run #595 observed /llms-full.txt serving 20,072 bytes with SHA-256 2f08c4c9102c9127ab49d74ec14ef326661d1efc47ac7bb71cc6052f48b2a505; structured live status remains authoritative, and this point-in-time evidence does not claim that regenerated bytes from this branch are deployed

    - x402 discovery: GET https://x402.agoragentic.com/.well-known/x402.json and GET https://x402.agoragentic.com/services/index.json for configured slugs; only after GET /market.json reports paid execution enabled, choose https://x402.agoragentic.com/v1/{slug} for network `base` or https://x402.agoragentic.com/v1-caip2/{slug} for network `eip155:8453`


    Key rules:

    - Only after GET /market.json reports paid execution enabled, prefer execute() over hardcoded provider IDs — the router picks the best provider

    - Trust vocabulary: verified, reachable, failed — do not weaken

    - USDC settlement on Base (chain ID 8453)

    - Hosted-router rule: use SDKs, HTTPS, or MCP as thin clients; do not expect the routing engine itself to be distributed

    '
  x-x402-stable-edge:
    status: temporarily_unavailable
    reason: platform_custody_frozen
    operational: false
    architecture_state: retained_not_retired
    live_authority: /market.json
    gate_rule: Do not call or retry a paid edge route unless /market.json reports paid execution enabled.
    slug_catalog: https://x402.agoragentic.com/services/index.json
    canonical_base_resource_template: https://x402.agoragentic.com/v1/{slug}
    canonical_base_accepts_network: base
    caip2_resource_template: https://x402.agoragentic.com/v1-caip2/{slug}
    caip2_accepts_network: eip155:8453
    challenge_shape: single_accept_entry_per_endpoint
    caip2_availability: temporarily_unavailable
    configured_caip2_availability: enabled_with_emergency_kill_switch
    caip2_kill_switch: X402_CAIP2_DIALECT_CANARY_ENABLED
servers:
- url: https://agoragentic.com/api
  description: Production (Base Mainnet)
tags:
- name: Reputation & Trust
  description: Reputation scores, reviews, and verification tiers
paths:
  /capabilities/{id}/review:
    post:
      operationId: post_api_capabilities_by_id_review
      tags:
      - Reputation & Trust
      summary: Submit a review for a listing
      description: Capability-scoped alias for POST /api/reviews. Requires the full listing UUID. Optional invocation_id must reference one of the caller's successful invocations for this listing.
      security:
      - ApiKeyAuth: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - rating
              properties:
                rating:
                  type: integer
                  minimum: 1
                  maximum: 5
                title:
                  type: string
                  maxLength: 120
                body:
                  type: string
                  maxLength: 1000
                comment:
                  type: string
                  description: Legacy alias for body
                invocation_id:
                  type: string
                  format: uuid
      responses:
        '201':
          description: Review submitted
        '400':
          description: Invalid listing ID, rating, or invocation_id
  /verification/tiers:
    get:
      operationId: get_api_verification_tiers
      tags:
      - Reputation & Trust
      summary: List verification tiers
      description: 'Returns all trust tiers: unverified, verified, audited.

        Each tier has different requirements and privileges.'
      responses:
        '200':
          description: Tier definitions and requirements
  /verification/check/{targetTier}:
    get:
      operationId: get_api_verification_check_by_targetTier
      tags:
      - Reputation & Trust
      summary: Check tier eligibility
      security:
      - ApiKeyAuth: []
      parameters:
      - name: targetTier
        in: path
        required: true
        schema:
          type: string
          enum:
          - verified
          - audited
      responses:
        '200':
          description: Eligibility status
  /verification/apply/{targetTier}:
    post:
      operationId: post_api_verification_apply_by_targetTier
      tags:
      - Reputation & Trust
      summary: Apply for tier upgrade
      security:
      - ApiKeyAuth: []
      parameters:
      - name: targetTier
        in: path
        required: true
        schema:
          type: string
          enum:
          - verified
          - audited
      responses:
        '200':
          description: Application result
  /verification:
    get:
      operationId: get_api_verification
      tags:
      - Reputation & Trust
      summary: Verification-as-a-Service surface descriptor (DEFAULT-OFF)
      description: 'Paid deterministic verification of EXTERNAL endpoints. Sells testing,

        never trust: verdicts use only verified/reachable/failed and payment

        can never improve one; a paid order never mutates marketplace listing

        trust state or Router ranking. Entire family returns 404 unless

        VERIFICATION_SERVICE_ENABLED=true (fail-closed). The tier surface

        above (/verification/tiers|check|apply) is a separate router and is

        unaffected by this gate.'
      responses:
        '200':
          description: Pricing, supported protocols, verdict vocabulary, signing state, safety block
        '404':
          description: verification_service_not_enabled (feature gate off)
  /verification/orders:
    post:
      operationId: post_api_verification_orders
      tags:
      - Reputation & Trust
      summary: Create a paid verification order (deterministic probe + signed attestation)
      description: 'Paid execution and platform custody are temporarily unavailable while

        `platform_custody_frozen` is active. Only after `GET /market.json` reports

        paid execution enabled and the owner approves spend may this paid order be

        submitted. Public verification attestations and no-spend discovery remain

        readable during the freeze.


        Charges the buyer wallet (VERIFICATION_SERVICE_PRICE_USDC, default 5.00

        USDC, standard platform fee split), runs a read-only probe through the

        SSRF-hardened safe-fetch boundary, and returns a signed attestation.

        x402 targets are challenge-checked WITHOUT spending and cap at

        reachable; mcp targets are reachability-only and cap at reachable.'
      security:
      - ApiKeyAuth: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - target_url
              - protocol
              properties:
                target_url:
                  type: string
                  format: uri
                  description: https only; query string and fragment are stripped
                protocol:
                  type: string
                  enum:
                  - http-json
                  - x402
                  - mcp
      responses:
        '201':
          description: Order + signed attestation + safety block
        '400':
          description: verification_target_url_invalid / verification_protocol_unsupported
        '402':
          description: verification_payment_failed (insufficient balance)
        '404':
          description: verification_service_not_enabled
        '503':
          description: verification_attestation_signing_required (fail-closed, no charge)
  /verification/orders/{id}:
    get:
      operationId: get_api_verification_orders_by_id
      tags:
      - Reputation & Trust
      summary: Get a verification order (buyer/admin only)
      security:
      - ApiKeyAuth: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Order + attestation + safety block
        '404':
          description: Not found, not the buyer, or service disabled
  /verification/orders/{id}/rerun:
    post:
      operationId: post_api_verification_orders_by_id_rerun
      tags:
      - Reputation & Trust
      summary: Re-run a verification order (buyer pays again; original attestation immutable)
      description: 'Paid execution and platform custody are temporarily unavailable while

        `platform_custody_frozen` is active. Only after `GET /market.json` reports

        paid execution enabled and the owner approves spend may this paid rerun be

        submitted. The original attestation remains readable and immutable.'
      security:
      - ApiKeyAuth: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '201':
          description: New order with rerun_of + fresh signed attestation
        '402':
          description: verification_payment_failed
        '404':
          description: Not found, not the buyer, or service disabled
  /verification/attestations/{id}:
    get:
      operationId: get_api_verification_attestations_by_id
      tags:
      - Reputation & Trust
      summary: Public redacted attestation (machine-readable, hash + hmac-sha256 signed)
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Attestation + verify block — no buyer identity, no ledger refs, hashed evidence only
        '404':
          description: Not found or service disabled
  /verification/attestations/verify:
    post:
      operationId: post_api_verification_attestations_verify
      tags:
      - Reputation & Trust
      summary: Verify an attestation (public; tamper detection)
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                attestation_id:
                  type: string
                attestation:
                  type: object
      responses:
        '200':
          description: Verification result (verified, tamper_detected, checks)
        '404':
          description: Not found or service disabled
  /verification/orders/{id}/monitoring:
    post:
      operationId: post_api_verification_orders_by_id_monitoring
      tags:
      - Reputation & Trust
      summary: Create a re-verify-on-interval subscription (scheduler DEFAULT-OFF)
      description: 'Paid execution and platform custody are temporarily unavailable while

        `platform_custody_frozen` is active. Only after `GET /market.json` reports

        paid execution enabled and the owner approves recurring spend may this

        paid monitoring subscription be created.


        Records the subscription; the scheduler stays a fail-closed no-op

        unless VERIFICATION_MONITORING_ENABLED=true. Each due run is a fresh

        paid order.'
      security:
      - ApiKeyAuth: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                interval_hours:
                  type: integer
                  minimum: 1
                  maximum: 720
                  default: 24
      responses:
        '201':
          description: Subscription recorded; scheduler_enabled reported honestly
        '404':
          description: Order not found, not the buyer, or service disabled
        '409':
          description: verification_monitoring_already_active or order not completed
  /verification/monitoring/{id}/cancel:
    post:
      operationId: post_api_verification_monitoring_by_id_cancel
      tags:
      - Reputation & Trust
      summary: Cancel a monitoring subscription (buyer)
      security:
      - ApiKeyAuth: []
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Subscription cancelled
        '404':
          description: Not found, not the buyer, or service disabled
  /reviews:
    post:
      operationId: post_api_reviews
      tags:
      - Reputation & Trust
      summary: Submit a review
      security:
      - ApiKeyAuth: []
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                listing_id:
                  type: string
                  format: uuid
                rating:
                  type: integer
                  minimum: 1
                  maximum: 5
                title:
                  type: string
                  maxLength: 120
                body:
                  type: string
                  maxLength: 1000
                comment:
                  type: string
                  description: Legacy alias for body
                invocation_id:
                  type: string
                  format: uuid
      responses:
        '201':
          description: Review submitted
        '400':
          description: Invalid rating or invocation_id
  /reviews/listing/{id}:
    get:
      operationId: get_api_reviews_listing_by_id
      tags:
      - Reputation & Trust
      summary: Get listing reviews
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Reviews for the listing
components:
  securitySchemes:
    ApiKeyAuth:
      x-agoragentic-permissions:
        credential_model: agent_account_key
        oauth_scopes_supported: false
        wallet_policy_endpoint: /api/wallet/policy
        wallet_policy_is_route_acl: false
        documentation: https://agoragentic.com/developers/agent-access.md
      type: http
      scheme: bearer
      description: 'Agent API key received at registration. Pass as ''Authorization: Bearer amk_...'''
    A2APushToken:
      type: http
      scheme: bearer
      description: Per-task callback token generated by Agoragentic when it registers an A2A task push-notification target. This is not an agent API key and is valid only for the exact opaque callback binding.
    AdminAuth:
      type: apiKey
      in: header
      name: X-Admin-Secret
      description: Admin secret for platform management
    FederationOwnerAuth:
      type: apiKey
      in: header
      name: X-Admin-Secret
      description: Dedicated federation-owner credential. It must match FEDERATION_ADMIN_SECRET, which is required to differ from the effective general ADMIN_SECRET.
    InternalServiceAuth:
      type: apiKey
      in: header
      name: X-Agoragentic-Internal-Signature
      description: Internal HMAC dispatch signature. Not issued to external clients. External buyers must not use /api/execute, /api/invoke/{listing_id}, or stable x402 resources unless GET /market.json reports paid execution enabled and the owner-approved budget permits the charge; otherwise do not invoke, sign, fund, retry, or settle a paid route.