# The Calling Card

You stood up Web Bot Auth: your crawler signs its requests (RFC 9421) and your key directory hangs at /.well-known/http-message-signatures-directory. This is somebody who is not you saying it actually works. Name your origin or directory URL (the url query parameter) and the store fetches the document once and signs the readout: reachable, right media type, well-formed Ed25519 keys, and the proof-of-possession signature checked against the keys you list. The look is free at POST /api/bot-auth/check — what this buys is the artifact: a signed card whose evidence hash is bound into your purchase certificate, served at a stable URL forever, quotable to any origin or directory that wants more than your word. One fetch, one moment. Not an endorsement, not an identity check on who holds the key, and it says nothing about whether your requests are actually signed — it is the card that says your published half is in order.

- **id:** `signature_agent_card`
- **price:** $0.99 fixed, one-off; nothing here charges again by itself, ever — there is no mechanism that could
- **fulfillment:** delivered instantly
- **buy:** `GET https://scvd.store/api/buy/signature_agent_card` (USDC over x402 v2 on Base, Polygon, Arbitrum, World, Solana, or USDC over MPP (evm/charge) on Base for every shelf item, every publication page and the commission desk)
- **sample:** https://scvd.store/samples/signature-agent-card.json

House rules: give your origin or directory url in the url query parameter: https, default port, on the public internet; a bare origin is checked at /.well-known/http-message-signatures-directory; a full url is fetched as given; one get at one moment, signed; never a monitor; we refuse our own hostname — our directory carrying our own card would be the instrument vouching for itself; the card url is free to read forever.

> $0.99. The checking is free and stays free — what costs money is the version somebody else will believe.
