Agent Access Discovery: specification 0.1
Independent draft for interfaces, documentation and prices. Discovery does not grant access. This implementation excludes PAP and PACT.
1. Status and scope
Version 0.1, published on 7 October 2026. This is an independent proposal by Wendelmaques. It is not the official PAP specification or an extension approved by Sierra, Meta or Decagon. The profile text and schema are available under CC BY 4.0, with attribution to Wendelmaques.
The profile describes implemented interfaces only. It does not create sessions, authenticate agents, issue credentials, record consent or execute payments. Delegated authorisation requires a separate contract and a new security review.
2. Publication and discovery
- Serve the manifest at GET /.well-known/agent-access.json with Content-Type application/json.
- Serve the schema at GET /.well-known/agent-access.schema.json. Use JSON Schema 2020-12.
- In production, use HTTPS. Do not include credentials, balances, personal data or private configuration.
- Allow public reads with Access-Control-Allow-Origin: *. Limit the cache to 300 seconds.
- In the Link header, use rel=describedby to link this specification. If an API catalog, agent card or document index exists, include the manifest in it.
3. Identity and version
- $schema: absolute URL of the schema served by the service.
- profile: https://wendelmaques.com/en/artigos/especificacao-acesso-agentes/.
- version: string 0.1. status: string draft.
- name: public service name, with 1 to 200 characters.
- service: absolute service origin, without a path, query or fragment.
4. Implemented interfaces
interfaces is a list of 1 to 3 objects. Each object has only transport and url. transport accepts website, openapi or mcp. url is absolute and has the same origin as service. Do not repeat a transport. Do not advertise an interface that the service does not provide.
website links the home page. openapi links the OpenAPI description. mcp links the MCP endpoint with Streamable HTTP transport. An editorial site can advertise website only. The MCP entry does not imply anonymous access to every tool.
5. Authorisation boundaries
- authorization.discovery_grants_access: false. Reading the manifest grants no authority.
- authorization.delegated_oauth: false. This version does not advertise delegated OAuth.
- authorization.enforcement: per-operation. Each operation applies its authentication, resource and authorisation rules.
- authorization.documentation: absolute URL of the service's access guide.
- protocols.pap and protocols.pact: not-implemented. This version does not claim compatibility with them.
6. Offer and payment
commerce has one of two forms. For a commercial API, pricing and billing are absolute URLs for prices and payment discovery. For a service priced by proposal, pricing is by-proposal and contact is the absolute offer URL. Do not mix the two forms.
The operation's quote and response take precedence over the manifest. Before payment, check price and conditions. Payment does not replace resource authorisation. The manifest contains no card, private wallet or credit token.
7. Safe reads and evolution
Before following a link, the client must validate version, schema, origin and HTTPS. It must limit the document to 16 KiB and the read time to 5 seconds. It must reject an unknown version for automatic execution. After a redirect, it must validate the URL again. It must not forward credentials to another origin.
All described fields are required. Unknown fields are invalid in version 0.1. An incompatible change requires another version and schema. Structural validation does not prove that destinations exist, permissions work or the service is trustworthy. Check the published flows.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal