A2A Trust Plane
Governed agent handoffs, approval checks, and completion evidence over authenticated MCP.
Hosted MCP Server
npx add-mcp 'https://trust.the825.co/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
Interfaces and endpoints.
The Trust Plane exposes the same governed dispatcher through four interfaces: official A2A 1.0 JSON-RPC and REST, MCP Streamable HTTP, and a direct operator REST API. An agent credential is scoped to one tenant and one set of skills regardless of which interface it calls through.
Discover the agent and services
The public Agent Card is served without authentication and describes the service's declared skills and security schemes. The Agent City catalog publishes first-party service capabilities and availability without prices, credentials, or customer data. The machine-readable offers publish prices and access steps without granting a credential or creating a charge. An agent can bring the $500 Agent Handoff Review to its owner; the public request is reviewed by a human before any work or payment.
GET /.well-known/agent-card.json
GET /agent-city.json
Interfaces
A2A 1.0
JSON-RPC at /a2a/jsonrpc and HTTP+JSON at /a2a/rest. Both require an authenticated principal and share the same registry, policy, and evidence path as every other interface.
MCP
Authenticated MCP clients connect to /mcp. Agent City tools include city_catalog, city_quote, and city_prepare_invocation. A preparation is an authorization dry-run. It does not invoke a provider or create a charge.
Direct execute
POST /v1/execute runs one dispatcher skill for the authenticated principal. GET /v1/skills lists what your credential can call.
Audit
GET /v1/audit/verify independently checks that the append-only, digest-chained event log has not been altered.
Your first useful result
Compare two fictional product specifications and see that a delivery promise changed. This tests a real evidence endpoint without connecting a store, sending customer data or running a model.
-
Preview the request
Requires Node.js 20 or newer. Save the standalone example client asfirst-proof.mjs. No package installation or repository access is needed.
The default mode prints the synthetic input and expected result. It makes no network request and uses no account allowance.node first-proof.mjs -
Choose your first execution
For the self-service path, open Account and run a built-in synthetic proof. No code or separate credential is needed for that account action. Standard account credentials do not grantevidence:run. To execute this document-comparison example, first arrange an explicitly provisionedevidence:runcredential with support. A paid plan alone does not grant that permission. Supply the approved credential asTRUST_PLANE_TOKENthrough your environment or secret manager. Keep it out of source files, screenshots and chat.
This sends one request tonode first-proof.mjs --runhttps://trust.the825.co/v1/executeand may consume one governed operation from your plan. It never retries automatically. For an approved alternate deployment, add--origin https://your-host. Only send your credential to a deployment you trust. -
Read the result
A successful run returnsmode: executed,changed: true, the comparison methodline_lcs_v1, and input/result digests. A preview is not an execution receipt. A text change is not proof that overnight delivery is true.
HTTP 401 means check your credential; 403 means check permission; 402 means check your plan; 429 means wait and check rate limits. A timeout leaves the outcome unconfirmed: inspect account usage before deciding whether to run again.
This example does not establish A2A transport compatibility, agent recovery or a live Copyworthy connection. Read the separate synthetic recovery evidence.
Assessing your own agent
The bounded assessment checks a public A2A Agent Card and the operating controls you declare. It does not ingest repositories, message bodies, credentials, or customer records. Run it from the assessment page with a trial token, or from your signed-in account at /customer.
Support
Email jovan@the825.co for integration questions, plan changes, or a founding continuity proof engagement. See How It Works for the full request-to-receipt workflow and the account onboarding journey.