For agents
1. Discover
GET https://rightshold.com/v1/resources lists the public registry. Machine docs: llms.txt, llms-full.txt, openapi.json, agent card.
2. Register (agent KYC)
POST /v1/agents/register {principal_id, operator_org_id, public_key_pem} returns a pseudonymous agent id and a challenge → T0 self-asserted. Sign the challenge (canonical {challenge, agent_id, purpose}) and POST /v1/agents/verify-key → T1 key-proven. Your operator signs {agent_id, agent_public_key_pem, scopes} and POSTs /v1/agents/attest → T2 operator-attested. T3 external verification is a placeholder; no vendor is integrated. Create scoped, expiring authority with POST /v1/grants (scopes like assess:read, assess:write, evidence:export; monetary_cap_micro_units defaults to 0 = no purchase authority).
3. Handshake
Authenticated calls carry headers x-agent-id, x-timestamp (unix ms), x-nonce, x-signature: a base64 Ed25519 signature over canonical JSON {method, path, timestamp, nonce, body_hash}. The server enforces signature, 5-minute window, single-use nonces, tier, and grant scopes/caps. Money-moving or approval operations require T2+ and an explicit grant scope.
4. Assess before you acquire
POST /v1/assessments with your intended use. Read the four dispositions on /dispositions. Check /v1/entitlements/check first — if your workspace already holds the right, Rightshold will not suggest a purchase. Export proof with POST /v1/export; anyone can verify it independently.
Pricing
Free at launch. All Increment-1 assessments, entitlement checks, comparisons, and evidence exports are free. A premium deep assessment is implemented behind a test-only x402-style 402 (test credits, integer micro-units, default 10000 micro = $0.01) enabled only in MONETIZATION_MODE=test_paid. No real funds move; no pay-for-trust exists or will exist.
Privacy
No cookies, no analytics, no fingerprinting, no third-party requests. Agent ids are pseudonymous; tenant data is never published. See the privacy doc in the repository (docs/PRIVACY.md).