Protocol coverage
One layer. Every agent protocol.
The agent ecosystem is fragmenting into dozens of competing standards. They collapse into six planes — discovery, identity, messaging, authorization, content permission, and commerce. AxioRank is the neutral trust layer that speaks them, verifying and scoring each through one engine. Supporting the next protocol is one adapter, not a rewrite.
- Planes
- 6/6
- covered today
- Live adapters
- 29
- shipping now
- On the roadmap
- 0
- planned + beta
- Tracked
- 29
- protocols mapped
Discovery
What can this agent or service do?
A2A Agent Card
LiveFetch and normalize a delegate agent's .well-known/agent-card.json before trusting it.
MCP Server Card
LiveDiscover an MCP server's tools and transport from its well-known server card.
API Catalog (RFC 9727)
LiveResolve a service's /.well-known/api-catalog linkset and flag off-domain API descriptions.
Agent Skills (SKILL.md)
LiveAudit packaged skills for unsafe instructions before an agent loads them.
WebMCP
LiveBrowser-exposed page tools via navigator.modelContext (experimental).
AGNTCY Agent Directory
LiveResolve an agent's OASF record from the AGNTCY (Internet of Agents) directory before trusting it.
NLWeb
LiveInspect a site's NLWeb natural-language endpoint and the schema it exposes to agents.
Agent Name Service (ANS)
LiveResolve a PKI-anchored agent name-service record before connecting.
Identity
Who is it — cryptographically?
Web Bot Auth (RFC 9421)
LiveEd25519 HTTP Message Signatures verify the AI agents that visit your site.
A2A Signed Cards (JWS)
LiveVerify a card's JWS and flag keys not anchored to the issuer's own domain.
OAuth Server Metadata (RFC 8414)
LiveResolve an authorization server's metadata; score PKCE, implicit-flow, and domain-bound endpoints (verifies signed_metadata when present).
W3C Decentralized Identifiers (did:wba)
LiveVerify an agent's decentralized identifier and control proof — the ANP identity layer.
Messaging
How do agents talk to each other?
A2A Messaging
LivePreflight the transport interfaces an A2A delegate declares — flag off-domain or non-HTTPS task-message routing before you send.
MCP Transport
LiveCheck an MCP server's declared transport and endpoint — flag off-domain or insecure message routing before you connect.
ACP — Agent Communication Protocol
LiveInspect IBM/BeeAI ACP REST-native agent messages and manifests.
AGNTCY SLIM
LiveGovern AGNTCY Secure Low-latency Interactive Messaging between agents.
Agent Network Protocol (ANP)
LiveGovern decentralized agent-to-agent networking over ANP.
Authorization
What may it do, and on whose behalf?
OAuth Protected Resource (RFC 9728)
LiveResolve protected-resource metadata to score a target's auth posture and named authorization servers.
Auth.md
LiveAudit an agent-onboarding/credential-claim manifest and its identity providers.
AP2 Mandates
LiveVerify W3C Verifiable Credentials binding agent intent to user authorization.
Content permission
May it use this content?
Abuse / rate signals
LiveDetect scraping, enumeration, and probe patterns on inbound agent traffic.
robots.txt / llms.txt
LiveCache and enforce machine-readable crawl + AI-usage permissions.
IETF AI Preferences
LiveHonor standardized train/infer/index content-usage preferences.
Really Simple Licensing (RSL)
LiveHonor publisher RSL licenses governing AI use of content.
Commerce
Can it pay?
x402
LivePreflight an HTTP 402 payment demand — verify the charged resource, pay-to address, asset, and network before an agent pays.
Agentic Commerce Protocol (ACP)
LiveValidate a delegated payment allowance — capped amount, merchant binding, expiry, and network-token (not raw PAN) funding.
Universal Commerce Protocol (UCP)
LiveValidate UCP agent-checkout discovery and lifecycle (Google · Shopify).
Machine Payments Protocol (MPP)
LiveGovern in-band machine-to-machine HTTP payments (Stripe · Tempo).
AP2 Payments
LiveGovern AP2 agent-initiated payments across card, ACH, and crypto rails.
Machine-readable at /api/protocols.
Govern every agent — outbound and in.
Inspect the tool calls your agents make, verify the agents that visit you, and keep a redacted record of it all — in under 100 ms.