Infisical serves an AI Catalog
manifest at /.well-known/ard.json on infisical.com, declaring
11 agentic resources
that a discovery service can index without asking anyone’s permission.
Run against this exact body with the project’s own
conformance CLI — 7 critical errors.
Discovery path
ard.json
Served at /.well-known/ard.json — the path ARD v0.91 says a consumer MUST fetch.
Declared spec version
none
The specVersion in the manifest. 1.0 is current for the AI Catalog data model; anything lower is an earlier draft. ARD reads this field as transport-defined and ignores it.
⚠ Hard checks failed. An ARD client cannot assume this manifest parses to the model the specification defines.
no-host-object
Optional affordances missing. None of these break a client, but each one costs the publisher search relevance or verifiability.
content-type-not-ai-catalog-json
11 entries
4 media types
31 representative queries
0 trust manifests
Host identifier: none
What this manifest advertises
Infisical MCP server
urn:air:infisical.com:server:mcp
Official MCP server. Runs locally over stdio via `npx -y @infisical/mcp` and authenticates as an Infisical machine identity.
“read the DATABASE_URL secret from my staging environment”
“add an API key to the production environment of my Infisical project”
“list the projects in my Infisical organization”
Infisical REST API
urn:air:infisical.com:api:rest
OpenAPI 3.0 description of the full Infisical API: secrets, projects, identities, PKI, and PAM. Bearer authentication with a machine identity access token.
What the platform does for agents rather than how to install it, covering Agent Proxy for third-party credentials, brokered PAM sessions on your own infrastructure, and agent identity and audit.
“which Infisical plan includes SSO, dynamic secrets, or audit log streaming”
How it is served
The publishing guide asks for three things at the transport layer, because a crawler is the
consumer that matters and a crawler is a browser-shaped client.
HTTPS only — yes (HTTP 200)
Content-Type: application/json —
yes
Access-Control-Allow-Origin: * —
yes
Evidence. Fetched https://infisical.com/.well-known/ard.json on 2026-09-13, HTTP
200. The verbatim body is stored alongside its manifest in the
Infisical repository
as ai-catalog/infisical-ai-catalog.json. Nothing on this page is derived
or generated: an AI Catalog manifest is served from the publisher’s own domain or it does not
exist, which makes it — like an
A2A Agent Card — one of the few agent artifacts that cannot be
produced on a provider’s behalf. Grades are recomputed on every build; the specification is a
v0.9 draft and
these verdicts will move when it does.
Every descriptor here is available over the APIs.io API and to AI agents over MCP. Agent Discovery is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for agent discovery
3 MCP tools reach this
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.