Verified Digital Agents (VDA) Bundles API

The Bundles API from Verified Digital Agents (VDA) — 2 operation(s) for bundles.

Operations 2

GET /bundles/{env}/active.json The active signed governance bundle (public; evaluator SDK) #
GET /bundles/{env}/versions/{version} A specific signed bundle version (public) #

Documentation

Specifications

Other Resources

🔗
LLMsTxt
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/llms/getvda-ai-witness-llms.txt
🔗
LLMsTxt
https://witness.getvda.ai/llms.txt
🔗
ToolCrosswalk
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/mcp/getvda-ai-tool-crosswalk.yml
🔗
DataModel
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/data-model/getvda-ai-data-model.yml
🔗
Sandbox
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/sandbox/getvda-ai-sandbox.yml
🔗
X-DID
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-witness-did.json
🔗
X-ProofOfIntegrity
https://witness.getvda.ai/proof
🔗
X-DID
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-hitl-did.json
🔗
X-DID
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-acp-did.json
🔗
LLMsTxt
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/llms/getvda-ai-c2md-llms.txt
🔗
LLMsTxt
https://c2md.getvda.ai/llms.txt
🔗
OAuthScopes
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/scopes/getvda-ai-scopes.yml
🔗
LLMsTxt
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/llms/getvda-ai-gosce-llms.txt
🔗
LLMsTxt
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/llms/getvda-ai-gosce-router-llms.txt
🔗
X-AgentCatalog
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-agents-ai-catalog.json
🔗
X-JWKS
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-agents-jwks.json
🔗
X-DID
https://raw.githubusercontent.com/api-evangelist/getvda-ai/refs/heads/main/well-known/getvda-ai-agents-did.json
🔗
SourceCode
https://github.com/mikerawsonnz/gosce-agents

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/getvda-ai-bundles-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

getvda-ai-bundles-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VDA ACP Bundles API
  version: 0.1.0
  description: Agent Control Plane — governance-aware wrapper on git.
servers:
- url: https://acp.getvda.ai
tags:
- name: Bundles
paths:
  /bundles/{env}/active.json:
    get:
      summary: The active signed governance bundle (public; evaluator SDK)
      responses:
        '200':
          description: The active SignedBundle
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SignedBundle'
        '404':
          description: no active bundle for this environment
      tags:
      - Bundles
      operationId: getBundlesByEnvActiveJson
      x-operation-id-source: derived
  /bundles/{env}/versions/{version}:
    get:
      summary: A specific signed bundle version (public)
      responses:
        '200':
          description: The requested SignedBundle version
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SignedBundle'
        '404':
          description: no such version
      tags:
      - Bundles
      operationId: getBundlesByEnvVersionsByVersion
      x-operation-id-source: derived
components:
  schemas:
    BundleSignature:
      type: object
      required:
      - algorithm
      - value
      - keyId
      additionalProperties: false
      properties:
        algorithm:
          type: string
          enum:
          - Ed25519
        value:
          type: string
          description: base64url signature over the canonical manifest bytes.
        keyId:
          type: string
          description: Must equal manifest.keyId.
    BundleManifest:
      type: object
      required:
      - schema
      - version
      - environment
      - commitSha
      - contentHash
      - did
      - keyId
      - files
      additionalProperties: false
      properties:
        schema:
          type: string
          enum:
          - acp.bundle/1
        version:
          type: string
          description: Monotonic per-environment version, assigned by the pipeline (not a timestamp).
        environment:
          type: string
        commitSha:
          type: string
          description: The git commit this bundle was built from — the tie to authoring provenance.
        contentHash:
          type: string
          pattern: ^sha256:[0-9a-f]{64}$
          description: Binds the file set to the manifest.
        did:
          type: string
          description: ACP's DID; resolve it for the bundle-signing key.
        keyId:
          type: string
          description: The verification method that signs bundles, e.g. did:web:acp.getvda.ai#key-3.
        files:
          type: array
          items:
            type: string
          description: Governance file names included, sorted.
    SignedBundle:
      type: object
      required:
      - manifest
      - files
      - signature
      additionalProperties: false
      description: 'Deterministic by design: the same commit + version always produces the same bytes and the same signature. Verify by canonicalising `manifest`, checking `signature.value` against the key `manifest.keyId` resolves to, then confirming sha256 of the canonical `files` equals `manifest.contentHash`. Fail-static: a bundle that does not verify is not used.'
      properties:
        manifest:
          $ref: '#/components/schemas/BundleManifest'
        files:
          type: object
          description: Governance file name → raw VDA-MD source. Capability/condition/authority/scope are parsed from these bodies.
          additionalProperties:
            type: string
        signature:
          $ref: '#/components/schemas/BundleSignature'
  securitySchemes:
    witness_bearer:
      type: http
      scheme: bearer
      bearerFormat: wtn.<keyId>.<secret>