{"what_this_is":"Check an A2A agent, reproduce its failures, and hand a developer the repairs and regression tests.","proposition":"Check an A2A agent, reproduce its failures, and hand a developer the repairs and regression tests.","for_money":"The $49 pilot buys one signed repair kit, one recheck within 30 days, and seven days of daily card checks, with no automatic renewal.","price":{"description":"The $49 pilot buys one signed repair kit, one recheck within 30 days, and seven days of daily card checks, with no automatic renewal.","amount_usdc":49,"cadence":"one_off","free":"The card check, test runner and repair guidance are free; the paid kit adds hosted runtime tests and signed records."},"battery":"scvd-a2a-jsonrpc-0.3-v1","protocol_version":"0.3.0","specification":"https://a2a-protocol.org/v0.3.0/specification/","how_to_call":{"card_check":{"method":"POST","url":"https://scvd.store/api/a2a/check","body":{"url":"https://your-agent.example/.well-known/agent-card.json"}},"setup":"Publish the authorization JSON below at /.well-known/scvd-a2a-audit.json on the card origin. Replace both URLs and the safe test message; choose an expiry in the next 30 days. Only public test data. The endpoint must be on that same origin. The fixture permits repeated execution, including malformed trailing parts that a broken agent might execute.","authorization_example":{"allow_scvd_audit":true,"allow_negative_tests":true,"safe_to_repeat":true,"card_url":"https://your-agent.example/.well-known/agent-card.json","endpoint":"https://your-agent.example/a2a","expires_at":"REPLACE_WITH_FUTURE_ISO_TIMESTAMP","message":{"kind":"message","role":"user","messageId":"replaced-on-each-run","parts":[{"kind":"text","text":"REPLACE_WITH_YOUR_SAFE_TEST_TASK"}]}},"purchase":{"url":"https://scvd.store/api/buy/a2a_repair_kit?url=https%3A%2F%2Fyour-agent.example%2F.well-known%2Fagent-card.json","method":"GET","payment":"x402; the item page has the browser till","item_page":"https://scvd.store/menu/a2a_repair_kit"},"recheck":"POST the private token from your purchase to its recheck URL within 30 days. The authorization file is read again. Repeated calls return the same recheck; the original report remains intact. An interrupted run is reported as a gap, without automatic replay.","regression":{"download":"https://scvd.store/api/a2a/runner.mjs","run":"node a2a-regression.mjs https://your-agent.example/.well-known/agent-card.json --runtime","exits":{"0":"All observed applicable checks passed; the stated untested capabilities remain outside scope","1":"At least one check failed","2":"Observation gaps, unsupported scope, refusal or instrument error"},"ci":"Save the downloaded runner in your repository, require Node 22 or later, and run the command as a required CI step. Omit --runtime for card-only checks."},"implementation_quote":{"contact":"mailto:sean@recordcreativeco.com","include":"Kit ID, public repository URL, Hono/Workers stack details, and requested repair scope. Implementation is separately quoted and is not included in the kit. Never send credentials or keys."}},"errors":{"target_refused":"Use a public HTTPS URL without query, fragment, credentials or private/internal addresses; our own host is refused","unsupported_version":"Only 0.3.0 is assessed; no automatic version conversion","unsupported_transport":"This pilot tests JSON-RPC only","endpoint_refused":"The card and endpoint must share an origin","authorization_required":"Publish or refresh the authorization fixture before purchase or recheck; nothing charged","invalid_fixture":"Use a valid new user Message with no existing taskId or contextId","budget_exhausted":"The shared free/admission budget is exhausted; retry after 60 seconds","body_limit":"Read exceeded the byte ceiling and is unobserved","missing":"Check the kit ID in the purchase response","unavailable":"An instrument or storage failure prevented completion; no pass is inferred","expired":"The included recheck period has ended"},"security":{"public_data_only":true,"stored":"Bounded public card, authorization fixture, task requests and responses, signed reports and suggested fixes. The private recheck token is stored separately and never returned by report reads. Report IDs are unguessable links; anyone holding a link can read the report, so use only public test data.","authority":"The operator grants runtime permission using a fixed file on the same origin. No supplied credentials, callback registrations, redirects or existing tasks. Daily watch passes only read the card.","bounds":{"response_bytes":16384,"request_timeout_ms":4000,"watch_days":7,"recheck_days":30,"free_and_admission_requests_per_minute":30},"conflict":"The subject pays for the work, never the result. Suggested repairs are authored by this store and have not been applied or independently code-reviewed. Any separately commissioned implementation must disclose store authorship at recheck.","gaps":["Only A2A 0.3.0 JSON-RPC is supported. No other version or transport is certified.","Streaming, push notifications, authentication, file transfer, extended cards, long-running tasks and application correctness are not tested.","One operator-supplied public test task is exercised. A Message response legitimately has no retrievable Task; lifecycle checks then remain not applicable.","Requests and responses are untrusted third-party data. No instructions in them are followed. Only public test data belongs in the authorization file.","URL checks reject private address literals and internal names; DNS pinning is not provided. Redirects are never followed. Platform egress remains part of the boundary.","A timeout or truncated read is an observation gap, never a conformance pass. Every result is dated and covers only the checks listed."]},"repair_guidance":{"card-http":{"change":"Serve the card as JSON at the supplied URL, without a redirect or login page.","acceptance":"A GET returns successful HTTP with application/json and the complete card body.","implementation":"Hono: return c.json(card). Check proxy routing and static-file rules at the deployed URL."},"card-schema":{"change":"Validate the complete card against the official schema for the version it declares. Derive skills and capabilities from the implemented methods.","acceptance":"The versioned AgentCard validator accepts the deployed document.","implementation":"Validate the built card in CI, including every skill entry, rather than asserting only the top-level names."},"endpoint-url":{"change":"Advertise an HTTPS endpoint reachable on the public internet. This instrument requires a URL without credentials, query or fragment.","acceptance":"The exact URL passes the published probe policy.","implementation":"Use a stable route. Keep authentication out of the URL; authenticated runtime tests are outside this pilot."},"send-schema":{"change":"Validate the returned Task or Message against the official schema. A Task needs its kind, id, contextId and status; a Message needs its own required fields.","acceptance":"The authorized fixture returns a schema-valid result and a JSON-RPC id matching the request.","implementation":"Hono/Workers: create a contextId for a new conversation, retain it with the task and return it on every task response. These are suggested changes, not a patch inspected against your source."},"task-get":{"change":"Persist each task before returning it, and read tasks/get from that same storage. Preserve task and context IDs.","acceptance":"Create a task, immediately retrieve its ID, and validate the retrieved response. Test from a second instance too.","implementation":"Hono/Workers: a Durable Object per task can provide immediate consistency. Set an explicit retention policy and return -32001 only for an unknown or expired task."},"terminal-cancel":{"change":"Load the task before deciding cancellation. Distinguish a terminal task from a missing ID.","acceptance":"Cancel the returned terminal task: -32002. Get an unknown ID: -32001.","implementation":"Return a JSON-RPC TaskNotCancelableError for a completed, failed, rejected or canceled task; do not turn every cancellation into task-not-found."},"parse-error":{"change":"Catch JSON parsing failures at the protocol boundary and return the standard parse error.","acceptance":"An incomplete JSON body returns -32700 with id null and no HTTP 5xx.","implementation":"Keep protocol error handling inside the A2A route so malformed JSON does not reach a generic HTML error page."},"null-part":{"change":"Validate the complete request before reading a part kind or dispatching application work.","acceptance":"A message with parts:[null] returns -32602 and does not dispatch the task.","implementation":"Use an official-schema validator compiled at build time; do not read part.kind before checking the value."},"trailing-part":{"change":"Validate every message part before using the first supported part.","acceptance":"A valid first part followed by null returns -32602 and does not dispatch the task.","implementation":"Schema validation must cover the whole array. A find() over part.kind does not validate the entries it skips."},"unknown-task":{"change":"Return the standard task-not-found error for IDs absent from task storage.","acceptance":"A random unknown ID returns -32001 in a valid JSON-RPC error envelope.","implementation":"Keep unknown-ID handling separate from storage failures; a failed storage read does not prove absence."}}}