Who publishes agent cards, server cards and bot-auth keys?
Of the 16,356 origins behind the official MCP registry’s remote listings asked on 9 October 2026, 1,485 publish an A2A agent card (450 validate against A2A 1.0.1), 393 an MCP server card where SEP-2127 puts it (227 valid), 2,506 one at /.well-known/mcp/server-card.json, the location of the superseded SEP-1649 draft (229 valid), and 177 a Web Bot Auth key directory (28 valid).
| Document | Where | Publish | Validate |
|---|---|---|---|
| A2A agent card | /.well-known/agent-card.json | 1,485 | 450 |
| MCP server card (SEP-2127) | <endpoint>/server-card, one endpoint per origin | 393 | 227 |
| MCP server card (SEP-1649 location) | /.well-known/mcp/server-card.jsonSEP-1649, a draft superseded by SEP-2127 on 21 January 2026 | 2,506 | 229 |
| Web Bot Auth key directory | /.well-known/http-message-signatures-directory | 177 | 28 |
Counted once per origin, however many listings it serves. “Publish” counts a document that is recognisably there, valid or not (9.1% of origins for agent cards). Of the agent cards, 649 have the A2A 1.0 shape and 797 the 0.3 shape; 65 carry a JWS signature. Of the cards at SEP-1649’s location, 1,735 have that draft’s shape and 771 SEP-2127’s. The key directories hold 159 keys in all, and 73 sign their own response. 865 origins were not asked, because the census could not connect to any listing there; 1,282 could not be told for the agent card (no answer, 401, 403, 429 or a 5xx). 63,976 requests in all.
How each is read
- A2A agent card at
/.well-known/agent-card.json. Valid when every field A2A v1.0.1 marksREQUIREDis present and set and every required list has an element (§5.7): name, description, version, at least one supported interface with its URL, binding and protocol version, capabilities, default input and output modes, and at least one skill with an id, name, description and tag. Members it does not name are ignored, as §5.7 says to. A card still in the 0.3 shape (urlandprotocolVersion, nosupportedInterfaces) is published and does not validate. Signatures are counted and their header read, never verified. There is no A2A 1.2: the latest release is 1.0.1. - MCP server card (SEP-2127) at
<endpoint>/server-card, the location the MCP Server Card extension reserves (SEP-2127, Final). The 2026-07-28 revision and the registry define no other, and the extension rejected a.well-knownURI because a card describes an endpoint, not a site. One endpoint per origin, a live server’s first. Valid against the extension’sschema.json. - MCP server card (SEP-1649 location) at
/.well-known/mcp/server-card.json: SEP-1649, a draft superseded by SEP-2127 on 21 January 2026, which dropped this path. Publishers still serve it, so it is counted in its own row, to show which path the market uses. A card there in the draft’s shape is valid when it has everything the draft requires —$schema,version,protocolVersion,serverInfowith a name and version, atransport(with an endpoint for HTTP) andcapabilities— and is served over HTTPS asapplication/jsonwithAccess-Control-Allow-Origin: *, as the draft requires at this path. A card there in SEP-2127’s shape is held to that schema. - Web Bot Auth key directory at
/.well-known/http-message-signatures-directory, reached without a redirect (a verifier must not follow one, §5.5). Valid when it is a JWK Set served asapplication/http-message-signatures-directory+json(§5.5.1), every key is a public signing key with a registeredalgif it names one, everykidis the key’s thumbprint (§5.5), not every key has expired, and — when the response is signed — the signature covers@authorityandcontent-digestand carriescreated,expiresand akeyidfrom the directory (Appendix B.1). Discovery only: no request is ever signed. - One GET each, ten seconds and 512 KB each, with the census’s user-agent (
agentwares-mcp-liveness/0.1 (+https://agentwares-agentcheck.vercel.app/bot)), no credential and no retry. An origin the census could not connect to is not asked; one that does not answer the first GET is not sent the other three; and a run that did not finish is not recorded.
Sources
- A2A agent card: A2A Protocol v1.0.1 (released 28 May 2026), §4.4 AgentCard, §8.2 discovery, §8.4 signing (read 9 October 2026)
- A2A JSON Schema bundle: a2a.json for v1.0.1, generated from specification/a2a.proto at tag v1.0.1 (read 9 October 2026)
- MCP server card: SEP-2127 MCP Server Cards (Final, Extensions Track); ext-server-card schema.json and docs/discovery.md at 526201bb (12 Aug 2026) (read 9 October 2026)
- MCP server card schema: ext-server-card schema.json, ServerCard (read 9 October 2026)
- MCP server card at /.well-known/mcp/server-card.json: SEP-1649 (draft; issue closed 26 January 2026, continued as SEP-2127 on 21 January 2026, which dropped this location), Field Descriptions and .well-known URI (read 9 October 2026)
- MCP 2026-07-28 changelog: names no server-card location (read 9 October 2026)
- Web Bot Auth key directory: draft-ietf-webbotauth-httpsig-protocol-00 (1 September 2026), §5.5 discovery, §5.5.1 format, §8.1 well-known URI, Appendix B.1 directory signature (read 9 October 2026)
The data
/v1/survey carries every reading under discovery, with the change since the one before. discovery.ndjson has one line per origin: each document’s verdict, why, and what it says about itself. Each server’s status page, at /servers/<registry name>, shows its origin’s four verdicts.
MCP Liveness · llms.txt · Free, no key, no signup. Terms · Privacy