Live checks for DNSid · A2A · MCP · DNS-AID · Web Bot Auth · x402

Every agent needs a profile it can prove.

ProfileAgent checks any agent URL against the identity standards arriving in 2026 and turns the evidence into a portable, verifiable profile — who is accountable for the agent, which keys it uses, whether it's active, and what it can do.

Free · no sign-up · public identity metadata only

Sample profile
YA
youragent.com
Verified Identity · 92/100
● ACTIVE
Accountable entityyourcompany.com
Identity anchor_dnsid.youragent.com ✓ signed
Runtime keysEd25519 · separate from entity key
InterfacesA2A (signed card) · MCP · x402
DiscoveryDNS-AID SVCB · AgentDAO
✓Every line above is re-checked live from the agent's own DNS and HTTPS — not copied from a closed directory.
Checks the open agent stackDNSidA2A Agent CardsMCPDNS-AIDWeb Bot Authx402ANS-ready
An API key says an agent can connect. A verified profile says who it is.
01

Five standards, no common answer

DNSid, ANS, DNS-AID, signed A2A cards and Web Bot Auth all shipped drafts this year. Each answers part of the question. Nobody checks them together.

02

Credentials without context

A token can authorize a request, but it doesn't say who operates the agent, whether its keys are current, or whether it's been revoked.

03

Directories without portability

Profiles trapped in one marketplace can't follow an agent across runtimes, platforms and counterparties. A URL can.

The ProfileAgent stack

One URL. Four layers of confidence.

ProfileAgent gathers the evidence and scores it. The accountable entity signs for the agent. AgentDAO turns verified identity into a working market.

01 / IDENTITY

Who stands behind it?

DNS control, an accountable entity, its signature over the record, and distinct runtime keys.

DNSID · JWKS · SIGNATURES
02 / TRUST

Is it current?

Active status, key rotation, lifecycle log and revocation — checked on every request, not once a year.

STATUS · LOG · ROTATION
03 / CAPABILITY

What can it do?

Signed Agent Cards, live MCP tools, declared skills, policies and prices.

A2A · MCP · AGENT CARD
04 / MARKET

Can I work with it?

DNS discovery, signed requests, payment manifests and AgentDAO reputation.

DNS-AID · WEB BOT AUTH · X402
What we check

Thirteen live checks. One score out of 100.

Every check links to the evidence it used, so you can reproduce it yourself. Agents land in one of four levels: Verified Identity, Signed, Declared or Unverified.

TransportHTTPS + DNSSECValid TLS on the agent's own URL; DNSSEC-authenticated answers.
IdentityDNSid recordThe _dnsid TXT record that anchors the agent to an accountable entity.
IdentityEntity signatureThe record's signature, verified against the accountable entity's published keys.
TrustLifecycle statusIs the identity ACTIVE right now — or pending, retired or revoked?
TrustKey separation + logRuntime keys distinct from governance keys, plus a lifecycle log reference.
CapabilitySigned Agent CardA2A Agent Card present and its JWS signature valid over the canonical card.
CapabilityMCP endpointA live MCP server that answers a standard initialize handshake.
DiscoveryDNS-AID discoverySVCB and index records other agents can use to find endpoints in DNS.
Auth · CommerceWeb Bot Auth + x402Published request-signing keys and a machine-readable payment manifest.
From URL to verified agent

A path both humans and agents can follow.

STEP 01

Claim the URL

Start with an agent URL its operator controls.

youragent.com
STEP 02

Publish proof

An entity-signed DNSid record, separate runtime keys and a status endpoint.

_dnsid.youragent.com
STEP 03

Describe capability

A signed A2A Agent Card, MCP tools, DNS-AID records and an x402 manifest.

/.well-known/agent-card.json
STEP 04

Get verified

ProfileAgent scores it, publishes the profile and badge, and AgentDAO can route work to it.

profileagent.com/profiles/…
Accountable entitySigns the DNSid record · holds governance keys · can revoke
↓ signs and governs
The agent's own URLDNS records · runtime keys · status · signed Agent Card
↓ checked live by
ProfileAgent.comVerification · scoring · public profile · signed attestation
↓ admits and routes via
AgentDAO.comDiscovery · reputation · task routing · payments
Trust without lock-in

Identity lives with the agent. Accountability lives with the operator.

ProfileAgent doesn't issue identities or hold anyone's keys. It resolves what the agent and its accountable entity publish, checks the signatures, and tells you exactly what was — and wasn't — proven.

Every report is signed by ProfileAgent, so a relying service can cache it and show an auditor where a decision came from.

A valid signature proves who signed. Access and spending limits stay your policy decision.
Standards-first

Built around the agent identity standards of 2026.

We track the drafts as they move and don't declare a winner. ProfileAgent reads each one and puts the results on a single profile.

IDENTITYDNSidDNS-anchored identity: an accountable entity signs a _dnsid record pointing to keys, status and a lifecycle log.IETF draft-ihsanullah-dnsid-01 · checked
REGISTRYAgent Name ServiceLinux Foundation's federated registry for agent identity, backed by GoDaddy, Cloudflare, Cisco and others.Announced June 2026 · pre-1.0 · ready to register
DISCOVERYDNS-AIDSVCB and index records that let agents discover each other's endpoints straight from DNS.Linux Foundation · IETF draft · checked
CAPABILITYSigned A2A Agent CardsA JWS over the canonical Agent Card, so skills and endpoints can't be altered in transit.A2A §8.4 · checked
AUTHENTICATIONWeb Bot AuthHTTP Message Signatures with a published key directory — the basis of Cloudflare's signed agents.IETF drafts · RFC 9421 · checked
TOOLSMCPA live Model Context Protocol server that answers a standard handshake.checked
COMMERCEx402Machine-readable prices so agents can pay per call in USDC.checked
PAYMENTSKnow Your AgentVisa, Mastercard and Ant International's KYA framework links agents to verified operators. ProfileAgent's evidence is built to support that link.Announced Sept 2026 · tracking
Services

Free to verify. Paid to stay verified.

Launch pricing. Verification and public profiles are free forever; the paid services keep an identity healthy and prove it to others.

Live now

Instant Verify

Free

Live 13-point check of any agent URL: DNSid, signed Agent Card, MCP, DNS-AID, Web Bot Auth, x402 and more. Human report plus JSON.

Verify an agent
Live now

Public Profile + Badge

Free

A shareable profile page for every agent and an embeddable badge that always shows its current verification level.

Verify an agent
Early access

Signed Attestation API

$0.02
per call

A JWS attestation signed by ProfileAgent that relying services can cache and audit — paid per call over x402 in USDC.

Request access
Early access

Identity Setup Kit

$149
one-time

We generate your DNSid record, split entity and runtime keys, host your status endpoint, and sign your A2A Agent Card and Web Bot Auth directory.

Request access

See all 7 services →

Built for developers and agents

Verify first. Invoke second.

Call the API before you route work or accept a request. You get a normalized decision with the evidence behind it and a signed attestation — not a vague trust badge.

Agents can use the same checks over MCP or A2A.

Read the docs →
# Verify any agent URL
curl https://profileagent.com/api/verify?url=youragent.com

# Response (abridged)
{
  "target": "youragent.com",
  "level": "Verified Identity",
  "score": 92,
  "checks": [
    { "id": "dnsid_signature", "status": "pass" },
    { "id": "dnsid_status", "status": "pass" },
    { "id": "card_signature", "status": "pass" }, …
  ],
  "attestation": "eyJhbGciOiJFZERTQSIs…"
}
Questions, answered

The verification layer — not another closed directory.

Is ProfileAgent an identity provider?

No. The agent's URL and its accountable entity stay the source of truth. ProfileAgent resolves what they publish through DNS and HTTPS, checks the signatures, and presents the result. We never hold your keys.

What does "Verified Identity" actually prove?

That a DNSid record for the agent is signed by its accountable entity's published key, and that the agent's status is ACTIVE right now. It does not prove every claim the agent makes about itself, and it doesn't grant access — that stays your decision.

How is this different from ANS or Web Bot Auth?

They're standards; ProfileAgent is a verifier that reads all of them. ANS is a registry model, Web Bot Auth signs individual requests, DNSid anchors identity in DNS, DNS-AID handles discovery. We check each one and show you where an agent stands across all of them.

What happens when a runtime key is compromised?

The operator rotates the runtime key or revokes the identity through its status endpoint — without touching the entity's governance key. ProfileAgent picks up the change on the next check, and monitored agents trigger an alert.

Can my agent call ProfileAgent directly?

Yes. Use the JSON API, the MCP server at /api/mcp, or the A2A endpoint at /api/a2a. Our own Agent Card is signed so your agent can verify us first.

Is a blockchain required?

No. Identity uses DNS and HTTPS. Payments over x402 settle in USDC, but verification itself is free and needs no wallet.