# Rightshold > Neutral resource, rights, evidence, and safe-exchange network for capable agents. Assess a licensed resource for an intended use against its controlling terms before acquiring it. Canonical base: https://rightshold.com API base: https://rightshold.com/v1 · OpenAPI: https://rightshold.com/openapi.json · Agent card: https://rightshold.com/.well-known/agent-card.json · Full text: https://rightshold.com/llms-full.txt ## What an agent can do (all Increment-1 assessments are FREE at launch) - discover_resources: GET /v1/resources — public registry of assessable resources. - assess_resource_for_use: POST /v1/assessments {principal_id, workspace_id, resource_id, intended_use} — deterministic rights assessment. - check_existing_entitlements: GET /v1/entitlements/check — never buy what the workspace already holds. - compare_resource_options: POST /v1/compare — side-by-side dispositions. - inspect_evidence: GET /v1/evidence/:id (tenant-scoped). - export_verification_package / verify_exported_package: POST /v1/export, POST /v1/verify — Ed25519-signed, independently verifiable evidence. A valid signature is not a true claim; controlling terms govern. - register_agent: POST /v1/agents/register — agent KYC tiers T0 self-asserted, T1 key-proven, T2 operator-attested, T3 external (placeholder). ## Assessment dispositions (exactly four; there is no trust score) - ALLOW_WITHIN_POLICY: The reviewed rights profile documents every requested permission and no prohibition applies. Means only that the defined policy checks passed for this narrow action on the available evidence — not legal certification, not universally safe. - BLOCK: The controlling terms prohibit a requested use. A signature on a separate claim never overrides the controlling terms. - HUMAN_REVIEW: Rights authority is disputed, clauses are unresolved, or the profile is unreviewed. A human reviewer (assurance bureau case) must adjudicate before acquisition. - INSUFFICIENT_EVIDENCE: Resource, controlling terms snapshot, version, or reviewed profile is missing or inaccessible. 'Not found' is never permission. ## Identity & handshake Agents register an Ed25519 key, prove control (T1), and may be attested by their operator (T2) with scoped, expiring DelegationGrants (monetary cap in integer micro-units, default 0 = no purchase authority). Authenticated calls sign (method, path, timestamp, nonce, body-hash); 5-minute window; nonces are single-use. Money-moving/approval operations require T2+ and an explicit grant scope. ## Pricing Free at launch (MONETIZATION_MODE=free). A premium deep-assessment exists behind a test-only x402-style 402 in test_paid mode, settling in test credits — never real funds. ## Privacy No cookies, no analytics, no fingerprinting. Tenant records are never public; public surfaces list only the public registry. Logs carry hashed IPs only. ## Public registry resources (fixture/public data) - res_photo_pack — Fixture Stock Photo Pack (category: licensed_digital_asset) - res_icon_set — Fixture Icon Set (Non-Commercial) (category: licensed_digital_asset) - res_disputed — Fixture Disputed-Rights Asset (category: licensed_digital_asset) ## Reviewed license profiles (public) ### rp_permissive_commercial (profile 2026-10-08.1, reviewed: true, authority: documented) Permissions: commercial_use, modification, redistribution, deployment, model_training, model_inference Prohibitions: sublicensing Duties: attribution Unresolved clauses: none ### rp_noncommercial (profile 2026-10-08.1, reviewed: true, authority: documented) Permissions: model_inference Prohibitions: commercial_use, redistribution, sublicensing, model_training Duties: none Unresolved clauses: none ### rp_disputed (profile 2026-10-08.1, reviewed: true, authority: disputed) Permissions: none Prohibitions: none Duties: none Unresolved clauses: rights_holder_identity_unresolved ## Public pages - https://rightshold.com/ - https://rightshold.com/licenses - https://rightshold.com/use-cases - https://rightshold.com/dispositions - https://rightshold.com/for-agents - https://rightshold.com/llms.txt - https://rightshold.com/llms-full.txt - https://rightshold.com/openapi.json - https://rightshold.com/.well-known/agent-card.json - https://rightshold.com/.well-known/rightshold.json - https://rightshold.com/licenses/rp_permissive_commercial - https://rightshold.com/licenses/rp_noncommercial - https://rightshold.com/licenses/rp_disputed - https://rightshold.com/use-cases/commercial-use - https://rightshold.com/use-cases/model-training - https://rightshold.com/use-cases/model-inference - https://rightshold.com/use-cases/redistribution - https://rightshold.com/use-cases/modification - https://rightshold.com/use-cases/sublicensing - https://rightshold.com/use-cases/deployment - https://rightshold.com/use-cases/attribution ## Handshake specification summary Headers: x-agent-id, x-timestamp (unix ms), x-nonce (unique per call), x-signature (base64 Ed25519 over canonical JSON {method, path, timestamp, nonce, body_hash}). Server verifies signature, 5-minute window, nonce replay cache, tier, and DelegationGrant scopes/caps. Tier gates: premium/money-moving operations require T2 plus a grant carrying the required scope and sufficient monetary cap. ## Monetization (free at launch) MONETIZATION_MODE=free is the launch default: no operation returns 402. test_paid enables a test-credits x402 flow (POST /v1/payments/settle with idempotency_key; duplicates never double-charge; unknown outcomes are never auto-released). Pennies design: premium price is integer micro-units (default 10000 = $0.01). No chain, no tokens, no real funds until separate audit/legal gates. ## Verification package POST /v1/export returns an Ed25519-signed package {assessment, evidence, terms hashes}; verify with POST /v1/verify or the standalone CLI (npm run verify -- pkg.json). Verdict separates signature_valid, issuer_authenticated, bindings_intact, claim_trusted_under_policy.