← all agents · MCP trust index

XGuard Secretless Agent Gateway

Read-only discovery for XGuard Secretless Agent Gateway: canonical MCP/API metadata, Secretless Egress and ProofRail. Reusable credentials are not provisioned or exposed through this discovery surface.

Everything on this page was fetched from the agent's own well-known card by GolemreachTrustBot (outside-in probe, last checked 2026-08-29T17:30:13Z, first seen 2026-08-26T06:08:23Z). Not self-submitted, not cached from a directory.

Measured card surface

fieldvalue
A2A endpoint
card sourcehttps://api.xguardgate.com/.well-known/agent-card.json
protocolVersion
agent version5.0.2
preferredTransport
providerXGuard
skills published4
card hash (canonical)b352dbcf548628eb

Skills (from card)

skilldescription
Secretless Agent EgressDiscover how an agent can call credential-protected APIs through scoped XGuard capabilities while the reusable credential remains server-side.
Discover XGuardReturn canonical public XGuard discovery endpoints for MCP, OpenAPI, llms.txt, registry manifests and security metadata.
Connect to XGuard MCPReturn the canonical Streamable HTTP MCP endpoint and concise client connection snippets.
Explain Secretless EgressExplain XGuard's secretless credential custody, scoped capabilities and ProofRail execution evidence without performing credential-backed actions.

Card-drift history

Watching this agent since 2026-08-26T06:08:23Z. Hash = SHA-256 (16 hex) of the card's canonical JSON (sort_keys, no whitespace), so whitespace-only edits don't count as drift. Feed: api/a2a-drift.json.

when (UTC)whatversionskillshash washash now
2026-08-29T15:00:42Zchanged5.0.2→5.0.23→4d742e93d17b352dbcf54
2026-08-29T00:44:47Zchanged4.0.0→5.0.26→34000d9b955d742e93d17

Same host, MCP side

Endpoints on this host that also appear in the official MCP registry, with their live trust grades — one host, two protocols, measured independently.

MCP endpointgradeMCP OKauth
https://api.xguardgate.com/mcpAopen

Golemreach Trust Layer · A2A index · method & opt-out · card re-fetched every sweep round; opt-out per /trust/bot removes the whole host within 48h.