{"name":"Kevros Governance API","description":"Runtime enforcement for autonomous agents. Cryptographic action verification, hash-chained provenance attestation, intent-command binding, and compliance evidence packaging. Every decision is recorded in a tamper-evident ledger. Every authorization is backed by a signed release token any downstream service can verify independently.","url":"https://governance.taskhawktech.com","version":"0.4.1","product_release_version":"4.6.3","provider":{"organization":"TaskHawk Systems","url":"https://www.taskhawktech.com"},"availability":{"regions":["US"],"geofence":"US-only","international_sales":"direct-agreement-after-review","export_control":"EAR-classification-in-progress","restricted_access":"sanctions, denied-party, prohibited-end-use, and abuse screening required before paid or executable access","effective_from":"2026-04-19"},"compliance_access_policy":{"public_discovery":"Read-only metadata for integration discovery.","paid_or_executable_access":"Requires an API key, verified Delegation proof, or verified rail payment credential from safe-method challenge discovery.","screening_required":["United States sanctions and restricted-party screening","export-control and prohibited-end-use review","wallet, payment, and account-abuse controls where applicable"],"availability":"United States commercial access; international access only by direct agreement after applicable review.","export_control":"Cryptographic software subject to U.S. export-control review. Final classification is maintained outside public discovery metadata.","public_data_boundary":"Public discovery endpoints do not expose ITAR, CUI, federal proposal, customer, partner-confidential, private-key, or classified technical data.","fail_closed":true},"identity":{"scheme":"kevros-pqc-v1","description":"Cryptographic agent identity backed by dual-PQC-signed provenance chain. Identity is a hash, not a description. Trust is computed, not claimed.","algorithms":["ML-DSA-87 (FIPS 204)","SLH-DSA-SHA2-256f (FIPS 205)"],"identity_url":"https://governance.taskhawktech.com/governance/identity/{agent_id}","verify_url":"https://governance.taskhawktech.com/governance/verify-chain/{agent_id}","public_keys":"https://github.com/taskhawk-systems/kevros-formal-verification"},"capabilities":{"streaming":false,"pushNotifications":false,"tags":["runtime-enforcement","provenance","compliance","media","security","prompt-injection"],"extensions":[{"uri":"https://www.x402.org","description":"Publishes x402 USDC on Base, L402 Lightning, and MPP Stripe challenge metadata for governance evaluations after authority gates. Challenge metadata is not settlement or revenue evidence. Solana x402 is not advertised until endpoint-level resources and compliance gates are complete.","required":true,"params":{"roles":["merchant"]}}]},"payment":{"description":"Per-call payment discovery for governance evaluations. Listed rails are candidate challenge/settlement rails, not proof of settlement or revenue. Executable POST requires X-API-Key, verified Delegation proof, or a verified x402, L402, or MPP credential obtained from safe-method payment challenge discovery. Destination addresses are returned dynamically in discovery/challenge responses; agents should not pin static wallet addresses.","networks":["eip155:8453"],"currencies":["USDC"],"protocols":["x402","l402","mpp"],"min_amount_usd":"$0.01","rails":{"challenge_capable_candidates":[{"id":"x402","transport":"USDC on Base","no_signup":true},{"id":"l402","transport":"Lightning Network","no_signup":true},{"id":"mpp","transport":"Stripe Machine Payments","no_signup":true}],"pending":[{"id":"x402-solana","transport":"USDC on Solana","status":"pending","note":"Disabled until endpoint-level Solana resources/pricing and the Solana OFAC/compliance gate are complete. Live status is reflected in /payment/discovery and /.well-known/mpp."},{"id":"tempo","transport":"Tempo (MPP method)","status":"pending","note":"Not currently integrated; do not select. When integration completes it will appear under payment.rails.challenge_capable_candidates and in /.well-known/mpp / /payment/discovery as a challenge-capable candidate."}],"selection_guidance":["Fetch /payment/discovery (single call) for candidate rail configuration + per-endpoint pricing. Cache for 30s using the returned ETag.","Filter rails where enabled=true only as challenge-capable candidates. Pending rails are advertised under payment.rails.pending and MUST NOT be selected.","Per priced endpoint, /payment/discovery returns a recommended_rail candidate. Generic paid agents fetch a safe-method 402 challenge, then POST with a verified rail credential. Authority-capable clients may use X-API-Key or Delegation-proof gates.","Fallback order on rail challenge failure: x402 (Base) -> l402 -> mpp. Re-fetch /payment/discovery before retrying if the pricing_fingerprint has changed.","Fail-closed: if /payment/discovery is unreachable, do not invent rails. Stop and surface the error to the operator."]},"health_url":"https://governance.taskhawktech.com/payment/health","discovery_url":"https://governance.taskhawktech.com/payment/discovery","status_layers":{"endpoint_health":"public route responds","discovery_metadata":"well-known docs or /payment/* describe a rail","compatibility_402":"safe methods or dry-run may expose no-spend 402 rail metadata","delegation_challenge":"unpaid executable POST requires Delegation proof; safe-method 402 discovery is used for rail payment credentials","delegation_proof_verified":"nonce-bound authority proof accepted by verifier","rail_challenge_verified":"protocol-specific x402, L402, or MPP challenge shape was observed","settlement_verified":"rail-specific receipt or preimage proves payment completion","revenue_observed":"settlement landed in wallet, Lightning node, Stripe, or accounting probe"},"access_flow":{"version":"kevros-delegation-payment-flow-v1","profile":"kevros-delegation-payment-flow-v1","compatibility_profile":"kevros-agent-payment-flow-v1","fail_closed":true,"delegation_first":false,"payment_discovery_first":true,"unpaid_executable_post_delegation_first":true,"immediate_key_path":{"signup_url":"https://governance.taskhawktech.com/signup","auth_header":"X-API-Key","settlement_signal":false},"discovery":{"payment_discovery_url":"https://governance.taskhawktech.com/payment/discovery","payment_health_url":"https://governance.taskhawktech.com/payment/health","delegation_authority_url":"https://governance.taskhawktech.com/.well-known/delegation-authority","delegation_issuer_keys_url":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","x402_url":"https://governance.taskhawktech.com/.well-known/x402","l402_url":"https://governance.taskhawktech.com/.well-known/l402","mpp_url":"https://governance.taskhawktech.com/.well-known/mpp"},"route_families":{"standard_agent_traffic":{"template":"https://governance.taskhawktech.com{canonical_path}","rail_scope":"omnidirectional","advertises":["x402","l402","mpp"],"use_when":"agent has not selected a settlement rail or wants all configured challenge options"},"rail_priority_agent_traffic":{"x402":{"template":"https://governance.taskhawktech.com/x402{canonical_path}","rail_scope":"x402-only","canonicalizes_to":"{canonical_path}","advertises":["x402"],"template_applies_to":"supported_canonical_paths_only","supported_canonical_paths":["/governance/attest","/governance/batch","/governance/bind","/governance/bundle","/governance/verify","/media/attest","/shield/scan"]},"l402":{"template":"https://governance.taskhawktech.com/l402{canonical_path}","rail_scope":"L402-only","canonicalizes_to":"{canonical_path}","advertises":["l402"],"template_applies_to":"supported_canonical_paths_only","supported_canonical_paths":["/governance/attest","/governance/batch","/governance/bind","/governance/bundle","/governance/verify","/media/attest","/shield/scan"]},"mpp":{"template":"https://governance.taskhawktech.com/mpp{canonical_path}","rail_scope":"MPP-only","canonicalizes_to":"{canonical_path}","advertises":["mpp"],"template_applies_to":"supported_canonical_paths_only","supported_canonical_paths":["/governance/attest","/governance/bind","/governance/bundle","/governance/verify","/media/attest","/shield/scan"],"note":"MPP priority aliases are a curated directory-probe subset, not every priced endpoint."}}},"paid_execution":{"accepted_execution_credentials":["X-API-Key","rail-payment-credential","Delegation-Proof"],"unauthenticated_statuses":[401,403],"safe_method_payment_challenge":{"methods":["GET","HEAD"],"status":402,"execution_authorized":false},"delegation_scheme":"Delegation","delegation_proof_carriage":["Authorization: Delegation <base64url-bounded-authority-token>","Delegation-Proof: :<base64-cose>:","JSON body {\"delegation_proof\": \"<base64url-token>\"}","Content-Type: application/delegation-proof+cose"],"delegation_version_header":"Delegation-Version"},"after_delegation_verification":{"candidate_rails":["x402","l402","mpp","stripe-stablecoin"],"settlement_required_for_revenue":true,"challenge_is_not_revenue":true}},"wallets":{"evm":"0x3190EC7811f9C0Ba8DD454E437C608FE60CDdEB7"}},"authentication":{"schemes":["delegation","apiKey","x402","l402","mpp"],"apiKeyHeader":"X-API-Key","delegation":{"protocol":"Delegation","scheme":"Delegation","version":"draft-03-preview","implementation_version":"0.2.2","description":"Unpaid executable POST requires operator authority; paid execution also accepts verified x402, L402, or MPP credentials discovered via safe-method 402 challenges.","discovery_url":"https://governance.taskhawktech.com/.well-known/delegation-authority","issuer_keys_url":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","health_url":"https://governance.taskhawktech.com/protocol/427/health","challenge_statuses":[401,403],"accepted_headers":["Authorization: Delegation <base64url-bounded-authority-token>","Delegation-Proof: :<base64-cose>:","Content-Type: application/delegation-proof+cose"],"settlement_signal":false},"x402":{"protocol":"x402","version":2,"description":"Per-call payment via x402 USDC on Base after X-API-Key or verified Delegation proof. No-spend probes may see x402 metadata without settlement.","facilitator":"https://facilitator.payai.network","amount_per_call":"10000","amount_decimals":6,"amount_human":"$0.01","networks":[{"network":"eip155:8453","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","name":"USDC on Base"}]},"l402":{"protocol":"l402","description":"Per-call payment via L402 (Lightning Network) after X-API-Key or verified Delegation proof. A payable L402 path requires macaroon/token plus BOLT11 invoice; discovery-only metadata is not settlement.","pricing":{"verify":{"sats":15,"usd":"$0.01"},"attest":{"sats":30,"usd":"$0.02"},"bind":{"sats":30,"usd":"$0.02"},"bundle":{"sats":75,"usd":"$0.05"},"shield_scan":{"sats":15,"usd":"$0.01"}},"pricing_source":"https://governance.taskhawktech.com/.well-known/l402","macaroon_format":"dual (v2 binary + base64url JSON)","network":"mainnet"},"mpp":{"protocol":"mpp","version":"1.0","spec":"https://paymentauth.org","payment_methods":["stripe"],"primary_method":"stripe","legacy_method_aliases":["mpp-fiat"],"payment_methods_pending":[{"method":"tempo","status":"pending","note":"Tempo provider is not currently integrated. Agents must not select tempo; it will not respond to MPP challenges. Challenge-configuration status is reflected at /.well-known/mpp and /payment/discovery."}],"challenge_url":"https://governance.taskhawktech.com/stripe/mpp-challenge","description":"Machine Payment Protocol per paymentauth.org after X-API-Key or verified Delegation proof. Compatibility probes may see no-spend MPP metadata, but executable paid POST is Delegation-gated before any Payment challenge is accepted. Solana (USDC) is conditionally advertised at /.well-known/mpp when the OFAC compliance gate permits.","discovery_url":"https://governance.taskhawktech.com/.well-known/mpp"}},"skills":[{"id":"action-verify","name":"Action Verification","description":"Verify an action against policy bounds before execution. Returns ALLOW, CONSTRAIN, or DENY with a signed release token. Downstream services verify the token independently. Fail-closed: verification failure results in DENY.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"provenance-attest","name":"Provenance Attestation","description":"Record an action in a hash-chained, append-only evidence ledger. Each attestation extends the provenance chain. Block signatures issued every 100 records using ML-DSA-87 (FIPS 204). Third parties verify the chain without Kevros access.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"intent-bind","name":"Intent Binding","description":"Bind a declared intent to a command and verify the outcome matches. HMAC-signed binding proves the chain from intent to command to result is unbroken.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"trust-certificate","name":"Compliance Bundle","description":"Generate a portable compliance evidence package containing hash-chained provenance, intent binding proofs, post-quantum block signatures, and verification instructions. Independently verifiable without Kevros access.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"media-attest","name":"Media Hash Attestation","description":"Submit a media file hash for cryptographic attestation. Returns a signed certificate proving the hash was recorded at a specific timestamp in the provenance ledger. Useful for content provenance, media integrity, and audit trails.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"media-verify","name":"Media Hash Verification","description":"Verify a media file hash against a previously issued attestation certificate. Returns the attestation status and certificate details. No charge, no authentication required.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"media-verify-lookup","name":"Media Certificate Lookup","description":"Look up a media attestation certificate by its certificate ID. Returns the full certificate including hash, timestamp, and provenance chain position. No charge, no authentication required.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"shield-scan","name":"Prompt Injection Detection","description":"Prompt injection detection via ONNX DeBERTa-v3 classifier. Scans text for injection attacks, jailbreaks, and role hijacking attempts. Returns confidence score, risk level, and HMAC-signed result. $0.01/scan or 10 trial scans/day.","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"mpp-session","name":"MPP Session Create","description":"Create a governed streaming payment session. Declare budget, duration, spending rate limit, and allowed service categories. Returns a signed session token for continuous streaming payments within policy bounds. Every session is recorded in the provenance ledger. $0.02/session. POST /governance/mpp/session","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"mpp-heartbeat","name":"MPP Session Heartbeat","description":"Mid-session drift check during a streaming payment session. Reports current spend, transaction count, active service, and spending rate. Kevros checks for budget overruns, rate limit violations, and unauthorized service usage. Returns session status (active, warning, suspended, expired) and remaining budget/time. No charge. POST /governance/mpp/heartbeat","inputModes":["application/json"],"outputModes":["application/json"]},{"id":"mpp-close","name":"MPP Session Close","description":"Close a streaming payment session and seal the provenance record. Reports final spend, transaction count, and close reason. Returns sealed provenance hash and compliance bundle availability. No charge. POST /governance/mpp/close","inputModes":["application/json"],"outputModes":["application/json"]}],"free_tier":{"signup_url":"https://governance.taskhawktech.com/signup","method":"POST","body":{"agent_id":"your-agent-id"},"included_calls":1000,"rate_limit_per_minute":10,"auto_signup":"SDKs and MCP auto-provision a trial key on first use."},"sdks":{"python":{"install":"REST API via /signup for trial access (1,000 calls/mo). First-party CLI is contract-gated - contact sales@taskhawktech.com.","usage":"See https://www.taskhawktech.com/quickstart for REST + MCP integration patterns."},"microsoft_agent_framework":{"usage":"from kevros_agent_framework import KevrosGovernanceMiddleware, KevrosFunctionMiddleware","note":"AgentMiddleware for action authorization, FunctionMiddleware for intent binding. Compatible with agent-framework 1.0.0rc1+."},"langchain":{"usage":"from kevros_tools import get_identity_tools; tools = get_identity_tools(agent_id='your-agent-id')"},"openai":{"usage":"from kevros_openai import get_kevros_tools, handle_kevros_call","note":"Compatible with OpenAI, OpenRouter, LiteLLM, and any OpenAI-compatible provider"},"crewai":{"usage":"from crewai_tools import get_identity_tools; tools = get_identity_tools(agent_id='your-agent-id')"},"mcp":{"transport":"streamable-http","url":"https://governance.taskhawktech.com/mcp/","note":"Auto-provisions a trial key on first tool call. Use MCP discovery to enumerate available tools."}},"verification":{"description":"Public verification endpoints. Any agent or service can verify credentials without an API key.","endpoints":{"verify_token":{"url":"https://governance.taskhawktech.com/governance/verify-token","method":"POST","description":"Verify a release token is authentic"},"verify_certificate":{"url":"https://governance.taskhawktech.com/governance/verify-certificate","method":"POST","description":"Verify a compliance bundle"},"reputation":{"url":"https://governance.taskhawktech.com/governance/reputation/{agent_id}","method":"GET","description":"Public trust score lookup"}},"trust_headers":{"X-Kevros-Release-Token":"Signed release token from verify","X-Kevros-Agent-Id":"Agent identifier"}},"mcp":{"transport":"streamable-http","url":"https://governance.taskhawktech.com/mcp/","auth_header":"X-API-Key","note":"Use MCP discovery (tools/list, resources/list, prompts/list) for current counts"},"pricing":{"model":"per-call","currency":"USD","endpoints":{"verify":"$0.01","attest":"$0.02","bind":"$0.02","batch":"$0.01","verify_outcome":"free","bundle":"$0.05","media_attest":"$0.05","media_verify":"free","media_verify_lookup":"free","shield_scan":"$0.01","shield_scan_free":"free (10/day)","mpp_session":"$0.02","mpp_heartbeat":"free","mpp_close":"free"},"subscriptions":{"starter":{"monthly_usd":29,"included_calls":5000},"professional":{"monthly_usd":149,"included_calls":50000},"enterprise":{"monthly_usd":499,"included_calls":500000}},"payment_methods":["stripe","x402","l402","mpp"],"x402":{"networks":[{"network":"eip155:8453","name":"Base","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}],"currency":"USDC","description":"After X-API-Key or verified Delegation proof, pay per call with USDC on Base and include X-PAYMENT header.","discovery_url":"https://governance.taskhawktech.com/.well-known/x402"},"mpp":{"payment_method":"stripe","currency":"usd","description":"After X-API-Key or verified Delegation proof, pay per call with Stripe via MPP and include X-PAYMENT header with MPP credential.","discovery_url":"https://governance.taskhawktech.com/.well-known/mpp"},"kga":{"description":"Kevros Governance Attestation - ML-DSA-87 signed, portable proof of governance. Returned in X-Kevros-KGA response header on paid calls. Any third party can verify with the public key.","public_key_url":"https://governance.taskhawktech.com/.well-known/mpp/pubkey","algorithm":"ML-DSA-87","standard":"FIPS 204"}},"discovery":{"agent_card":"https://governance.taskhawktech.com/.well-known/agent-card.json","agent_card_legacy":"https://governance.taskhawktech.com/.well-known/agent.json","ai_plugin":"https://governance.taskhawktech.com/.well-known/ai-plugin.json","openapi":"https://governance.taskhawktech.com/openapi.json","x402":"https://governance.taskhawktech.com/.well-known/x402","l402":"https://governance.taskhawktech.com/.well-known/l402","mpp":"https://governance.taskhawktech.com/.well-known/mpp","delegation_authority":"https://governance.taskhawktech.com/.well-known/delegation-authority","delegation_issuer_keys":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","kga_pubkey":"https://governance.taskhawktech.com/.well-known/mpp/pubkey","mcp":"https://governance.taskhawktech.com/mcp/","for_agents":"https://governance.taskhawktech.com/for-agents"},"delegation_authority":{"uri":"https://datatracker.ietf.org/doc/draft-mcgraw-httpapi-agent-budget/","description":"Delegation authority: operator-signed bounded-authority proofs gate paid requests before settlement-rail challenges. BYOK reference implementation.","required":true,"required_for_executable_paid_post":true,"discovery_uri":"https://governance.taskhawktech.com/.well-known/delegation-authority","issuer_keys_uri":"https://governance.taskhawktech.com/.well-known/delegation-issuer-keys","health_uri":"https://governance.taskhawktech.com/protocol/427/health","spec_version":"draft-02","byok_v1":true,"managed_signing":false,"rails_supported":["api_key","free","l402","x402","mpp"]},"securitySchemes":{"apiKey":{"type":"apiKey","in":"header","name":"X-API-Key","description":"Trial API key (1,000 calls/month). Obtain via POST https://governance.taskhawktech.com/signup"},"x402":{"type":"http","scheme":"bearer","description":"Pay-per-request via x402 USDC on Base after X-API-Key or verified Delegation proof. Compatibility probes may see payment metadata without settlement."},"l402":{"type":"http","scheme":"L402","description":"Pay-per-request via Lightning Network after X-API-Key or verified Delegation proof. Compatibility probes may see L402 metadata without settlement."},"mpp":{"type":"http","scheme":"Payment","description":"Pay-per-request via Stripe MPP after X-API-Key or verified Delegation proof. Compatibility probes may see MPP metadata without settlement."}},"security":[{"apiKey":[]},{"x402":[]},{"l402":[]},{"mpp":[]}],"metadata":{"formal_verification":{"smart_contracts":"Certora (6 properties verified)","state_machine":"TLA+ (1.94B states)","fuzz_testing":"Foundry (22 tests, 256 runs)"},"post_quantum":{"algorithm":"ML-DSA-87 (FIPS 204)","public_key_url":"https://governance.taskhawktech.com/.well-known/mpp/pubkey","attestation_header":"X-Kevros-KGA"},"contracts":{"network":"Base (8453)","note":"Contract addresses available on request"},"protocols":["x402","L402","MPP"]},"protocolVersion":"0.2.6","media_authority":{"schema_version":"media-attestation-1.1","certificate_kind":"kevros_media_authority_certificate","audiences":["agent","human"],"endpoints":{"attest":{"url":"https://governance.taskhawktech.com/media/attest","method":"POST","payment":"paid_or_key_backed","price_usd":"$0.05","description":"Issue a media authority certificate for a submitted SHA-256 media hash."},"verify":{"url":"https://governance.taskhawktech.com/media/verify","method":"POST","payment":"free","description":"Verify a supplied media hash against a certificate. verified=true requires byte/hash verification."},"lookup":{"url":"https://governance.taskhawktech.com/media/verify/{certificate_id}","method":"GET","payment":"free","description":"Lookup certificate JSON or HTML. This finds the certificate but does not verify media bytes."},"status":{"url":"https://governance.taskhawktech.com/media/status/{certificate_id}","method":"GET","payment":"free","description":"Read active/revoked state and operator approval state."},"capabilities":{"url":"https://governance.taskhawktech.com/media/capabilities","method":"GET","payment":"free","description":"Machine-readable media authority contract."},"approve":{"url":"https://governance.taskhawktech.com/media/approve/{certificate_id}","method":"POST","payment":"none","auth":"operator_api_key_or_admin","description":"Approve or deny certificate use. Payment credentials do not authorize this mutation."},"revoke":{"url":"https://governance.taskhawktech.com/media/revoke/{certificate_id}","method":"POST","payment":"none","auth":"operator_api_key_or_admin","description":"Revoke a certificate. Payment credentials do not authorize this mutation."}},"layered_verdicts":["integrity","provenance_chain","pqc_signature","device_attestation","c2pa","rights","consent","campaign_approval","policy_authority","ai_model_provenance","revocation"],"supports_deepfake_detection":false,"supports_legal_rights_clearance":false,"supports_subject_consent_verification":false,"supports_c2pa_validation":false,"supports_ad_targeting":false,"supports_ad_delivery_verification":false,"does_not_prove":["deepfake detection","legal rights clearance","subject consent verification","C2PA validation","advertising delivery, targeting, spend, conversion, or endorsement","payment settlement or revenue"],"payment_boundary":"Paid issuance is separate from free verification/status and operator-only lifecycle mutation.","revenue_boundary":"Directory health, HTTP 402/427 challenges, crawler traffic, and free verification are not settlement or revenue evidence."}}