PUBLIC CONFORMANCE REGISTRY · MCP + A2A

Don't trust the issuer.
Recompute the verdict.

A public directory of MCP and A2A agents that have been measured against five deterministic conditions. Every verdict carries a SHA-256 anyone can recompute. Passing entries are green; anything still in process stays visibly separate. Where a condition does not apply, it is stated, not skipped.

検証の扉が実測した対象を並べる公開レジストリ。適合は緑、手続き中は分けて表示し、対象外は明記する。判定はSHA-256で誰でも再計算でき、扉は自分自身にも同じ基準を当てる。

$ Run a live check Get listed, free
live self-check: idle gate v0.1.0 4 entries self-applied gate speaks MCP fail-closed snapshot 2026-08-08
The five conditions

What the gate measures, and what it refuses to

No human discretion. The gate calls the endpoint itself and decides deterministically. Self-declaration is never the evidence. That is why it can be free and open.

The gate verifies
  • 01Live MCP endpoint. Responds to initialize and tools/list with at least one tool.
  • 02A2A agent card. /.well-known/agent-card.json returns JSON with name and description.
  • 03Compensation disclosure. The card declares who pays it (paid_by, referral_fee, listing_fee).
  • 04Determinism. Identical input returns identical output across runs. Not measured unless you ask for it. Measuring this means executing a tool on your server, and the first tool listed may be destructive, so the gate will not do it without the owner's consent.
  • 05Self-verification. Every verdict carries a SHA-256 that any third party can recompute.
The gate does not verify
  • 01Whether any price or figure the server returns is correct. Price validation is a separate, paid tier.
  • 02Whether the declared compensation is truthful. Only the absence of disclosure disqualifies; a false declaration is grounds for revocation.
  • 03The quality, competence, or fitness of the underlying business.
  • 04That the ruleset is still current. Verified means untampered, not re-audited (audit_ruleset_recheck: not_performed).
The registry · snapshot 2026-08-08

Every entry, in its real state

Green is not painted ahead of measurement. An entry the gate could not reach, or one still in hearing, says so.

PASS measured and met N/A stated, not applicable IN PROCESS fail-closed, not yet passed HELD the gate cannot reach it (same account) NOT SELF applies, but we did not measure it ourselves
ENTRY 01 / self-applied
Yakumo Verification Gate
The gate itself. It answers "who verifies the verifier" by passing its own conditions first.
VERIFIED
MCP endpoint
NOT SELF
Agent card
PASS
Compensation
PASS
Determinism
PASS
Self-verify
PASS
POST/mcp · GET/self · /spec · POST/check
The gate now speaks MCP itself, at /mcp, with three tools. get_conditions takes no arguments and returns the same thing every time, which is why it is listed first. check_conformance measures any endpoint. verify_verdict recomputes the hash of a verdict this gate issued, so the tool that lets you distrust the issuer is provided by the issuer.

Condition 01 used to be marked not applicable here, on the grounds that the gate was an HTTP checker rather than an MCP server. That is no longer true, so the row changed. It now says applicable, served, and not measured by us. The gate cannot reach itself over the network from inside its own account, and it will not claim to have measured something it did not. Point another checker at /mcp from outside and the claim is either confirmed or destroyed.

Its compensation is declared in the same shape it demands of applicants. paid_by=buyer, referral_fee=false, listing_fee=false, success_fee_pct=0.
recompute: fetch /self, drop the record_sha256 and recompute_note fields, JSON.stringify the remainder in key order, take the SHA-256. It must equal record_sha256. The gate holds itself to the standard it applies to others.
ENTRY 02 / audit server
HORIZON SHIELD · hs-mcp
The estimate-integrity audit MCP. A2A capable, 14 tools, 3 published skills.
HELD · unreachable
MCP endpoint
SEEN
Agent card
SEEN
Compensation
HELD
Determinism
HELD
Self-verify
SEEN
GET/.well-known/agent-card.json · verification-contract.json
The agent card is live (provider The HORIZ音s Co., Ltd., skills: estimate-integrity-audit, japan-property-reform-intake, verify-claim). But hs-mcp is on the same Cloudflare account as the gate, and a Worker to Worker call over workers.dev never reaches it. Measured, both ways, on 2026-08-08: from the gate, /mcp and /.well-known/agent-card.json both answer 404; from a machine outside the account, the same three URLs answer 200. So the conditions stay held rather than failed, and the honest reading is that this host is verifiable from outside, not by us. Green is not painted early.
anchor: this operator's ledger is timestamped to Bitcoin via JIDEC · path #6 · block #959634 · verdict PASS 4/4 · ots confirmed · follow on hs-ledger
ENTRY 03 / member No.001
Reform Shokunin Inc.
Yakumo mall member, verification in progress (KIRA fair-price diagnosis running).
IN PROCESS
MCP endpoint
PROC
Agent card
PROC
Compensation
PROC
Determinism
PROC
Self-verify
PROC
KIRA fair-price diagnosis is under way. No store may call itself "verified" until it passes (fail-closed). In-process members are marked verification:"pending" and turn green only on passing. This is the core of the design and it is not relaxed.
ENTRY 04 / member No.002
Mineo Toyo Juki Co., Ltd.
Dedicated MCP live (hs-partner-002-mcp · get_partner_profile). Window and entrance-door replacement, glass repair, screen re-netting, 12 municipalities.
IN PROCESS · 60%
MCP endpoint
LIVE
Agent card
HELD
Compensation
HELD
Determinism
HELD
Self-verify
HELD
The dedicated MCP (get_partner_profile) is live. Profile completeness 60, hearing in progress, so the store's own state is pending (it turns verified on reaching published). It is also on the same account as the gate, so the gate's request never reaches it and the machine check stays held. An external checker or a custom domain reaches a verdict. The name and the state are shown as measured, not inflated.
Live conformance check

Paste any MCP endpoint. The gate checks it, then you recompute the verdict

This runs in your browser, against the live gate. The verdict's SHA-256 is recomputed here, on your side, and compared. Nothing is taken on trust.

The gate calls no tools on the server you point it at

Every verdict carries a tools_called field, and by default it reads none. Measuring determinism would mean executing a tool on the checked server, and the first tool a server lists may well be destructive. So the gate reports that condition as not measured rather than guessing, and says why. If you own the server and want it measured, send allow_tool_call: true and the verdict will record that a tool was called by consent. You can point this at somebody else's endpoint without touching their data.

ready

Endpoints on the same Cloudflare account as the gate (hs-mcp, No.002) come back with every condition failed, because a Worker to Worker call over workers.dev never reaches the target. Measured on 2026-08-08: the gate sees 404 on paths that answer 200 from any machine outside the account. The gate puts that in the verdict instead of hiding it, and the verdict's hash still recomputes, so a failed check is still a verifiable statement. Run it from your own machine and those hosts respond normally.

Verify it yourself

The whole claim is that a stranger can run this

No API key. Read-only. Point it at our servers, or at any server we never touched.

# A. Recompute a verdict (the gate's own, or any MCP's) curl -s https://hs-verify-gate.oga-surf-project.workers.dev/self # drop record_sha256 + recompute_note, JSON.stringify in key order, then SHA-256 # if it equals record_sha256, the verdict was not tampered with # B. Run any MCP endpoint through the gate, from your side curl -s -X POST https://hs-verify-gate.oga-surf-project.workers.dev/check \ -H 'content-type: application/json' \ -d '{"endpoint":"https://your-server/mcp"}' # C. Third-party check a signed claim (fail-closed, no price layer, no key) # MCP tool verify_integrity_claim( signed_payload, claim_sha256 )

If A does not match, the verdict was altered. If B fails, the applicant sees exactly why it failed (so it can be run before applying). If C does not match, the declaration was altered. In every case the correct response is to reject, the same posture the gate takes toward itself.

Tiers

Conformance is free. The price layer is separate, and labeled

verified
FREE

Conformance and disclosure, measured. No price validation.

verified_plus_data

Figures traced to a third-party obtainable primary source.

yakumo_partner

Dedicated MCP server, operations, and a full audit log.

Get listed

Three steps, no account, no fee, no waiting list

Listing is free and always will be. Nobody pays to appear here, nobody pays for position, and the verdict itself is never sold. You do not need to pass before you start.

1 Measure yourself first

One command. No key, no signup. The verdict names the condition that failed and why, so you can fix it before anyone else looks. No tool on your server is called unless you add allow_tool_call: true.

curl -s -X POST https://hs-verify-gate.oga-surf-project.workers.dev/check \ -H 'content-type: application/json' \ -d '{"endpoint":"https://your-server/mcp"}'
2 Open an issue

Public, on GitHub, with a template. Submissions are visible to everyone, including the ones that failed. There is no private queue and no fast lane.

You may open one even if you failed. Ask why, and the answer is free.

3 We re-measure, in public, and reply with the hash

We do not take your word for the result, and you should not take ours. We run the check ourselves, read-only, and post the verdict with its record_sha256 in the same issue so you can recompute it. If it passes, the row goes up. If it does not, the reply says what to change, and that costs nothing either.

What being listed gives you
  • 01A row with your measured state, condition by condition, that a third party can reproduce.
  • 02A free badge you may embed. Nobody pays to display it, and it links back to a live verdict rather than a picture. Take it here.
  • 03A place where the disclosure question is already answered, so anyone evaluating you does not have to ask.
What it does not give you
  • 01Any statement that your prices, figures, or answers are correct. This is conformance and disclosure only.
  • 02A permanent certificate. The row reflects a current measurement and stops being green when the measurement does.
  • 03Better position for paying. There is nothing to pay, and order is not for sale.
How this is funded

The gate demands that you declare who pays you. So we go first

Condition 03 requires every applicant to publish who funds it. It would be incoherent for the operator of that condition to say less about itself than it asks of others. This is the operator's declaration, in the same shape the gate reads from an agent card.

GET https://hs-verify-gate.oga-surf-project.workers.dev/.well-known/agent-card.json "compensation": { "paid_by": "buyer", "referral_fee": false, "listing_fee": false, "success_fee_pct": 0, "disclosure_url": "https://shield.the-horizons-innovation.com/yakumo/plans/" }

Read the fourth line first. The operator earns nothing extra when an entry passes. There is no success fee, so there is no financial reason to be generous with a verdict. The three lines above it say the same thing from other directions: nobody pays to be listed, nobody pays for position, and no cut is taken from work that results from being found here.

Why the check itself is free
  • 01No human reviews an application. The verdict is computed from measurement, so one more applicant costs close to nothing. Free is a consequence of the design, not a promotion that expires.
  • 02A fee would corrupt it. If passing cost money, the operator would have a reason to pass people. Removing the human removed the discretion, and removing the fee removed the motive.
  • 03You can run it without us. The conditions are published at /spec, the verdict recomputes from public bytes, and the check is open to any endpoint, including ones we would rather not have checked.
What is never charged for
  • 01Being listed. No listing fee, at any tier, ever.
  • 02Position on this page. Order is fixed by the registry, not by payment.
  • 03The verdict. A conformance result is never sold, discounted, or expedited.
  • 04Introductions. Zero referral fees. Work that comes to a listed party is theirs, with no cut taken.

So what is actually sold

Two things, both above the free line, both stated in the machine-readable spec at /spec as tiers.

verified_plus_data

The free tier checks that a server discloses and behaves consistently. This one checks the numbers: that each figure traces to a primary source a third party can obtain independently. Conformance says the machine is honest about itself; this says the data survives an outside look.

yakumo_partner

A dedicated MCP server built and operated for one organisation, with a full audit log. This is construction and operations work, priced as a build and a monthly service, never as a fee for a verdict.

! The limit, stated rather than hidden

The paid layers exist today for Japanese construction only, because that is where the underlying dataset, the thirty years of site experience, and the licensing sit. If you arrived here as an MCP developer outside that field, the honest answer is that there is currently nothing here to sell you, and the conformance check is genuinely all you will be charged for, which is nothing. This page would rather say that than manufacture an offer.

! The conflict of interest, and how it is bounded

Anyone who both issues a verdict and sells help obtaining it has a conflict. Naming it is not enough, so here is what actually bounds it.

  • 01There is no discretion to sell. The verdict is deterministic. No amount paid changes what initialize returns, or whether two identical calls produce identical output.
  • 02The failing reasons are free. Anyone can run POST /check before applying and read exactly which condition failed and why. The information needed to fix it is not behind the paid layer.
  • 03Paid engagement is disclosed on the row. If a listed party is a paying customer of the operator, its entry says so. A verdict that came after money changed hands is still a verdict, but the reader gets to know.
  • 04The operator is listed under the same conditions. Two HORIZON SHIELD entries on this page currently do not pass. They stay visible, unpassed.
Listing policy

The rules this directory binds itself to

A registry is only worth reading if its own rules are fixed in advance and stated in public. These are ours.

How an entry earns its state
  • 01Green only after measurement. An entry turns verified when the gate has actually measured it. It is never granted in advance, and never for paying.
  • 02In-process is shown, not hidden. An applicant part-way through appears with its real state rather than being left off the page.
  • 03Non-applicable is stated. A condition that does not apply is marked N/A with the reason, never silently skipped.
  • 04Unreachable is not failure. If the gate cannot reach a host, the entry is held and says so, with the measurement in both directions.
What this directory will not do
  • 01Order is not for sale. Position on this page, and the verdict itself, cannot be bought. Zero referral fees.
  • 02No quiet edits. A verdict is not rewritten in place. It carries a hash and a timestamp; a changed verdict is a new measurement.
  • 03Revocation on false disclosure. The gate does not judge whether a declaration is true, but a declaration later shown to be false is grounds for removal.
  • 04No exemption for the operator. HORIZON SHIELD's own servers sit in this list under the same conditions, including the ones they currently do not pass.

Corrections are welcome and are treated as defects. If an entry here is wrong, or a condition is measured differently on your side, say so and it is re-measured in public. The contact below is real.