← all agents · MCP trust index

Kevros Governance API

Runtime enforcement for autonomous agents. Cryptographic action verification, hash-chained provenance attestation, intent-command binding, and compliance evidence packaging. Every decision is recorded in a tamper-evident ledger. Every authorization is backed by a signed release token any downstream

Everything on this page was fetched from the agent's own well-known card by GolemreachTrustBot (outside-in probe, last checked 2026-08-29T17:30:27Z, first seen 2026-08-26T06:08:47Z). Not self-submitted, not cached from a directory.

Measured card surface

fieldvalue
A2A endpointhttps://governance.taskhawktech.com
card sourcehttps://governance.taskhawktech.com/.well-known/agent-card.json
protocolVersion0.2.6
agent version0.4.1
preferredTransport
providerTaskHawk Systems
skills published11
card hash (canonical)2a3e38c9e0f9324d

Interface URLs

transportURL
unspecifiedhttps://governance.taskhawktech.com

Skills (from card)

skilldescription
Action VerificationVerify an action against policy bounds before execution. Returns ALLOW, CONSTRAIN, or DENY with a signed release token. Downstream services verify the token independently. Fail-closed: verification fa
Provenance AttestationRecord an action in a hash-chained, append-only evidence ledger. Each attestation extends the provenance chain. Block signatures issued every 100 records using ML-DSA-87 (FIPS 204). Third parties veri
Intent BindingBind a declared intent to a command and verify the outcome matches. HMAC-signed binding proves the chain from intent to command to result is unbroken.
Compliance BundleGenerate a portable compliance evidence package containing hash-chained provenance, intent binding proofs, post-quantum block signatures, and verification instructions. Independently verifiable withou
Media Hash AttestationSubmit a media file hash for cryptographic attestation. Returns a signed certificate proving the hash was recorded at a specific timestamp in the provenance ledger. Useful for content provenance, medi
Media Hash VerificationVerify a media file hash against a previously issued attestation certificate. Returns the attestation status and certificate details. No charge, no authentication required.
Media Certificate LookupLook up a media attestation certificate by its certificate ID. Returns the full certificate including hash, timestamp, and provenance chain position. No charge, no authentication required.
Prompt Injection DetectionPrompt injection detection via ONNX DeBERTa-v3 classifier. Scans text for injection attacks, jailbreaks, and role hijacking attempts. Returns confidence score, risk level, and HMAC-signed result. $0.0
MPP Session CreateCreate a governed streaming payment session. Declare budget, duration, spending rate limit, and allowed service categories. Returns a signed session token for continuous streaming payments within poli
MPP Session HeartbeatMid-session drift check during a streaming payment session. Reports current spend, transaction count, active service, and spending rate. Kevros checks for budget overruns, rate limit violations, and u
MPP Session CloseClose a streaming payment session and seal the provenance record. Reports final spend, transaction count, and close reason. Returns sealed provenance hash and compliance bundle availability. No charge

Card-drift history

Watching this agent since 2026-08-26T06:08:47Z. Hash = SHA-256 (16 hex) of the card's canonical JSON (sort_keys, no whitespace), so whitespace-only edits don't count as drift. Feed: api/a2a-drift.json.

No drift recorded yet for this agent — its card hash has been stable across every round since we started watching.

Same host, MCP side

Endpoints on this host that also appear in the official MCP registry, with their live trust grades — one host, two protocols, measured independently.

MCP endpointgradeMCP OKauth
https://governance.taskhawktech.com/mcp/Aopen

Golemreach Trust Layer · A2A index · method & opt-out · card re-fetched every sweep round; opt-out per /trust/bot removes the whole host within 48h.