Rightshold — neutral rights & evidence for agents. For agents · Licenses · Use cases · Dispositions · llms.txt

For agents

1. Discover

GET https://rightshold.com/v1/resources lists the public registry. Machine docs: llms.txt, llms-full.txt, openapi.json, agent card.

2. Register (agent KYC)

POST /v1/agents/register {principal_id, operator_org_id, public_key_pem} returns a pseudonymous agent id and a challenge → T0 self-asserted. Sign the challenge (canonical {challenge, agent_id, purpose}) and POST /v1/agents/verify-key → T1 key-proven. Your operator signs {agent_id, agent_public_key_pem, scopes} and POSTs /v1/agents/attest → T2 operator-attested. T3 external verification is a placeholder; no vendor is integrated. Create scoped, expiring authority with POST /v1/grants (scopes like assess:read, assess:write, evidence:export; monetary_cap_micro_units defaults to 0 = no purchase authority).

3. Handshake

Authenticated calls carry headers x-agent-id, x-timestamp (unix ms), x-nonce, x-signature: a base64 Ed25519 signature over canonical JSON {method, path, timestamp, nonce, body_hash}. The server enforces signature, 5-minute window, single-use nonces, tier, and grant scopes/caps. Money-moving or approval operations require T2+ and an explicit grant scope.

4. Assess before you acquire

POST /v1/assessments with your intended use. Read the four dispositions on /dispositions. Check /v1/entitlements/check first — if your workspace already holds the right, Rightshold will not suggest a purchase. Export proof with POST /v1/export; anyone can verify it independently.

Pricing

Free at launch. All Increment-1 assessments, entitlement checks, comparisons, and evidence exports are free. A premium deep assessment is implemented behind a test-only x402-style 402 (test credits, integer micro-units, default 10000 micro = $0.01) enabled only in MONETIZATION_MODE=test_paid. No real funds move; no pay-for-trust exists or will exist.

Privacy

No cookies, no analytics, no fingerprinting, no third-party requests. Agent ids are pseudonymous; tenant data is never published. See the privacy doc in the repository (docs/PRIVACY.md).