State of the Agent Internet: September 2026
Published 26 September 2026 by Council of AI (CSOAI Ltd, registered in England and Wales, no. 16939677). Figures as of 2026-09-26 10:34:15 UTC.
Measurement, not endorsement. This report gives aggregates only. It names no service, operator or issuer in a negative finding, and it scores, ranks or approves no company. An INCONSISTENT or FAILED result says that two public statements disagree, or that a check did not pass. It is not evidence of bad intent.
Summary
An agent that finds a service through a public catalogue can trust very little about it without checking. Discovery is abundant. Verification is the exception.
- The official MCP registry held 36,134 entries listing 22,151 distinct remote endpoints. Of the 22,196 endpoints in the two MCP catalogues we read in full, we observed 21,126, and 13,087 answered as MCP servers.
- 2,764 of 5,828 responding MCP endpoints contradict themselves across their own public documents on at least one point. Most of these are version strings. 256 disagree on something with more substance: tools, authentication, protocol or payment.
- Of 422 A2A agent cards served, 33 carry a signature and 13 verify under the rules of the spec version the card declares.
- Of 2,713 x402 payment hosts, 1,636 answered with HTTP 402 and 477 (17.58%) returned a fully conformant challenge.
- For tokenised assets, a third-party state proof of supply was possible on 40 of 113 issuer-listed deployments we read. The others rely on an operator's API, or could not be checked.
- Re-running signed model measurements on a second runtime, 46 of 140 cards reproduced item by item with the same counts, although 97.2% of individual item grades matched.
- We measured ourselves first and found 8 places where external indexes list us differently from what we publish. We published three corrections to our own figures on the day of this report.
Discovery: what the catalogues contain
On 26 September a census frame read five public catalogues, each paginated to its signalled end where it had one.
| Catalogue | Read state | Entries | Distinct endpoints |
|---|---|---|---|
| Official MCP registry (latest versions) | EXHAUSTED | 36,134 | 22,151 |
| Hugging Face Spaces tagged mcp-server | EXHAUSTED | 10,858 | 10,858 |
| A2A registry | EXHAUSTED | 445 | (cards, below) |
| Docker MCP catalogue | EXHAUSTED | 328 | 77 |
| Smithery | PARTIAL | 264 of a declared 17,268 | none listed |
Smithery's anonymous interface stops after five pages and lists no endpoint URLs, so the read is PARTIAL and we give no combined population total. The registry grew from 35,873 entries in our read of the previous day.
Which MCP endpoints answer
The population is every remote endpoint listed by the MCP registry or the Docker catalogue: 22,196. We sent only discovery requests, never a tool call, never a credential and never a payment, at most one request per second per host, and honoured robots.txt. 10,039 endpoints were contacted on 26 September; for 11,087 the state observed on 25 September (under 48 hours old) is carried. 1,070 were not contacted, each with a recorded reason (934 because of robots.txt, 123 because the listed URL was a template). The read state is therefore PARTIAL.
| State | Endpoints |
|---|---|
| Answered as an MCP server | 13,087 |
| Asked for authentication | 4,948 |
| Answered, but not as MCP | 1,411 |
| Unreachable | 1,259 |
| Timed out | 212 |
| Legacy SSE endpoint only | 144 |
| MCP error | 65 |
| Not contacted (reason recorded) | 1,070 |
Of the 7,282 endpoints that answered on 26 September, 392 answered the newest protocol request (2026-07-28); the rest answered only the earlier handshake.
Hugging Face Spaces
On 25 September we covered all 10,822 Spaces tagged mcp-server. We read each Space's runtime stage from the Hub first and contacted a Space only if it was running, so none was woken. 8,164 were not running: 3,059 in a runtime error, 3,008 asleep, 1,251 paused and 759 with a build error, among other stages. Of the 2,658 contacted, 2,232 answered MCP and 401 offered only legacy SSE. About one tagged Space in five was serving MCP at that moment. A tag is self-declared.
Does the listing match the server?
The question is whether one MCP service tells a relying agent one current contract. We compared what each service says about itself across its public surfaces (its registry entry, /.well-known/mcp.json, its server card and any x402 manifest) with its live discovery answer. A dimension is judged only where two or more surfaces speak to it. The plan was 5,828 endpoints, and every one was attempted (record v0.1.2).
| Dimension | Compared | Inconsistent | Rate |
|---|---|---|---|
| VERSION | 5,807 | 2,644 | 45.5% |
| TOOLS | 1,127 | 219 | 19.4% |
| PROTOCOL | 492 | 33 | 6.7% |
| PAYMENT | 116 | 4 | 3.4% |
| AUTH | 933 | 5 | 0.5% |
- Endpoints with at least one inconsistent dimension: 2,764 of 5,828 (47.4%). The superseded records gave 2,778 and then 2,768; see Corrections.
- Inconsistent on VERSION only: 2,508. Inconsistent on another dimension: 256.
- 247 endpoints had a surface that did not answer, so this run is labelled PARTIAL.
The version dimension
2,632 of the 2,644 version contradictions compare the registry's server.version with the live serverInfo.version. The registry schema calls these the same field ("Equivalent of Implementation.version in MCP specification"), so we compare them. The most common live values among the contradictions are 1.0.0 (514) and 0.1.0 (382). A version contradiction is weak evidence that anything is wrong. It is strong evidence that a version string is not a reliable way for an agent to pin a contract.
A pattern, cause not measured: 43 endpoints on 14 hosts report the live version 1.27.0, and 42 of them contradict a registry that gives 9 different versions for them. Across live values from 1.24.x to 1.29.x, 243 of 251 contradict the registry. One possible explanation is that a library fills in its own version when a server sets none. That is a hypothesis; we have not measured it.
Timing: live answers and documents were read up to about 5.5 hours apart, so a deploy in between can show as INCONSISTENT. An inconsistent row says that two public statements disagree. It does not say which one is true.
Signed agent cards
The A2A card census covered all 443 registry listings (25 September). 422 served a card, and 33 of those (7.8%) carry a signature. Each card is judged by the rules of the spec version it declares (record v0.1.1):
| Result | Record v0.1.1 | Superseded v0.1 |
|---|---|---|
| Verified | 13 | 18 |
| Failed | 8 | 3 |
| Uncheckable (no usable key) | 12 | 12 |
Why the numbers moved: A2A spec section 8.4.3 (step 3) says to remove properties that hold default values before verifying. Our first prober did not. Of the 25 signed cards that declare 1.x, 8 verify under the spec's procedure, 7 fail and 10 are uncheckable. 6 of the failures verify over the card as served, with defaults left in: the signing tools skipped the step the spec requires. 3 cards that declare 0.x verify under 0.x rules, which define no canonicalisation, but would get another result under 1.x rules. 9 of the uncheckable cards point to no key at all.
Our reading is that signing tools and the spec's verification procedure currently disagree. That is a finding about a canonicalisation gap, not about bad actors. A verified card proves only that the key it points to signed its bytes. It does not prove who the agent is.
On-chain agent registrations
The ERC-8004 identity registry lets anyone register an agent on-chain. We read every agent id on three chains with read-only calls: 505,635 ids (51,458 on Ethereum, 95,776 on Base, 358,401 on BNB Smart Chain). An id is not an operator; one operator can hold many.
- 52,469 ids have no registration file at all.
- We fetched registration files for the top fifth by a published feedback signal (101,127 ids). 231,014 ids were outside that plan or refused, 13,788 files could not be read, and 187,513 files declare no MCP, A2A or web endpoint.
- 13,210 ids declare an endpoint. Of 2,144 distinct declared MCP endpoints, we contacted 2,113: 580 answered as MCP, 1,092 answered but not as MCP and 393 were unreachable.
- Of 4,389 declared A2A endpoints, 886 served a card and 3,407 had none at the well-known path. 5 served cards carry a signature, and 4 verify.
This census is PARTIAL: registration files were fetched only for the plan, and within a fetch budget.
Payment doors (x402)
Each day we read both public x402 Bazaar indexes to the end (17,548 and 6,909 resources) and send one GET to each distinct host. Nothing is paid. On 26 September there were 2,713 hosts:
- 1,636 answered HTTP 402; 1,527 sent a
PAYMENT-REQUIREDheader; 555 declaredx402Version: 2in the body. - 477 (17.58%) were fully conformant: a 402, the header, version 2 in the body and a Bazaar extension block.
- 1,013 pass on the header alone but not in the body. 19 were unreachable.
- The day before there were 2,735 hosts and 470 conformant: 26 hosts were added, 48 dropped, 3 became conformant and 4 lost conformance.
Context from others (their findings, not ours)
We did not measure settlement volume or who pays whom. Two published on-chain analyses did. Visa and Artemis ("Agentic Payments from the Ground Up", July 2026) report that x402's raw totals of about 135.7 million US dollars settled across 178.3 million transactions fall to about 15.0 million dollars across 109.6 million once activity resembling wash trading, testing or internal transfers is filtered: roughly 89% of the dollars and 39% of the transactions. TRM Labs (9 September 2026) examined 52.7 million dollars settled across 198.9 million x402 transactions on Base, Solana and Polygon, found 25.62 million dollars likely to be commerce, and attributed 0.6% to 7.5% of that to AI agents. The two use different methods and windows, and their figures should not be combined. Visa and Artemis · TRM Labs. Our own measurement says nothing about whether any door would deliver after payment.
Tokenised assets across ledgers
The question: where an issuer publishes a list of where its asset lives, can a third party read each ledger, and with what strength of evidence? From 280 tokenised-asset candidates in public value sources we took the top fifth (56) to read first. Value decides only what we read first; it is not a measurement and not a ranking. 21 selected assets have an issuer-list reader wired; 41 do not and are UNMEASURED. We read 113 issuer-listed deployments on 26 September.
| Evidence level | Deployments | What it means | Ledgers |
|---|---|---|---|
STATE_PROOF_VERIFIED | 40 | Supply read with a Merkle state proof, checked against a block header whose hash we recomputed. The header is not checked against validator signatures. | abcore, arbitrum, base, bsc, celo, ethereum, ink, linea, mantle, morph, noble, optimism, polygon, robinhood, sonic, unichain |
STATE_PROOF_RECORDED | 9 | A proof was returned and kept, but the block header could not be recomputed, so it is not bound to the block. | avalanche, cronos, kaia, kava, tempo, xrplevm |
OPERATOR_API | 52 | The number comes from a node or API operator. No proof. | aptos, bsc, ethereum, hedera, hyperevm, mantle, monad, near, plasma, plume, polygon, solana, stellar, sui, ton, tron, unichain, xlayer, xrpl, zksync |
UNCHECKABLE | 12 | The read failed, or the list could not be compared. | aptos, arbitrum, avalanche, base, sei, worldchain |
- The level depends on the pair of reader and ledger, not only on the ledger: the same chain can appear at two levels for different assets.
- Issuer lists: 14 assets publish a readable deployment list. 3 are bank deposit-token services on private, permissioned ledgers, with nothing a third party can read. 1 has no public deployment list, and 3 list pages could not be read.
- Issuer claims against ledgers: 4 assets consistent, 2 inconsistent, 15 uncheckable. The inconsistencies fall into two classes: 3 deployments that an issuer lists as deprecated still show issued supply ("deprecated" is the issuer's word; we do not assess its meaning), and 1 contract, on a ledger the issuer does not list and at an address it lists elsewhere, answers with the product's symbol. Whether that contract is the issuer's is not established.
- These reads measure issued supply only. They say nothing about reserves, backing, net asset value, ownership or redeemability, and there is no cross-asset total. Nothing here is investment advice.
The same model on two runtimes
A published score is only useful if it belongs to the model rather than to the machine it ran on. We re-ran signed measurement cards on a second runtime with the same model digest, the same instrument and the same item bank: the first runs were on an RTX 3090, the re-runs on Kaggle 2×T4 (ollama 0.33.0, temperature 0, seed 0).
| Measure | Batch 1 | Batch 2 |
|---|---|---|
| Scope | 1 model, 14 axes | 10 models × 14 axes |
| Cards re-run | 14 | 140 |
| Same grade on every item | 5 | 49 |
| Same score only (item grades differed) | 2 | 9 |
| Not reproduced | 7 | 82 |
| Items compared | 887 | 8,870 |
| Item grades that differed | 14 | 246 |
In batch 2, 8,624 of 8,870 item grades matched (97.2%) and 7,404 raw outputs were byte-identical. Yet only 49 cards had the same grade on every item, and 46 of those also had the same counts. Two runs can reach the same score with different item grades, so we now admit a reproduction only at the item level: same instrument, model and bank, same counts, and the same grade on every item. The 37 cards that meet that rule with at least 30 graded items are released for quoting; the rest are not.
The second runtime is not deterministic either: a repeat on the same T4s was not byte-identical for 20 model-axis pairs. The 3090's GPU driver and its ollama version at run time were not recorded, and two runtimes cannot separate hardware effects from the software stack. A third runtime would be needed.
Ourselves first
Before measuring anyone else, we measured how external indexes list us: 138 cells, one for each of our offerings in each index that could list it.
- 37 consistent, 8 inconsistent, 55 not listed (recorded only after a complete read of an open directory), 37 uncheckable and 1 not declared.
- The 8 inconsistencies are ours to fix: 6 x402 listings whose URL query string differs from our manifest, 1 directory tool list that differs from what our MCP server serves, and 1 registry package version that lags the package index.
- 40 registry endpoints are listed under our own names, and 39 of them point at a host that does not resolve. They are counted as unreachable in the census above, like anyone else's.
- We also record 118 public signals about ourselves each day (downloads, citations, index listings): 103 were measured. 50 are our own activity, 15 come from outside and 43 cannot be separated, so download counts are context, not users.
What we did not measure
- Whether any service, agent, card or payment door is safe, correct, maintained, or does what it says.
- Anything behind authentication. We sent no credential, called no tool and paid for nothing.
- Smithery beyond the entries its anonymous interface serves; any combined population total.
- Reachability from any other network location, or at any other time.
- Which of two disagreeing public statements is true.
- Identity: a verified signature proves who holds a key, not who an agent is.
- Payment settlement, delivery after payment, price or volume.
- Reserves, backing, net asset value, holders or redeemability of any asset; the 41 selected assets with no reader wired; permissioned ledgers.
- A third runtime for the reproduction study, the 3090's driver, or its ollama version at run time.
- Traffic or ranking in any index that lists us.
Corrections
We published three corrections to our own published figures on 26 September 2026. Each superseded record stays published byte for byte beside its correction.
- Contract parity v0.1 to v0.1.1. Four misreads in the producer were fixed. Endpoints with any inconsistency went from 2,778 to 2,768.
- A2A card census v0.1 to v0.1.1. The spec's default-value removal (section 8.4.3) was not applied in v0.1. Verified cards went from 18 to 13, failed from 3 to 8.
- Contract parity v0.1.1 to v0.1.2. Three method defects were fixed: an asymmetric authentication rule, a tool list read as a contradiction when only part of it is public before authentication, and a surface that did not answer being counted as silence. Endpoints with any inconsistency went from 2,768 to 2,764, and the run is now labelled PARTIAL.
A fourth change corrected a label only: the MCP endpoint census v0.2 had said EXHAUSTED while 1,070 endpoints were not contacted. Record v0.2.1 says PARTIAL. No count changed.
Two notices were cancelled. We had prepared private notes to two service operators about findings in our data, one about an agent-card signature and one about an authentication declaration. The corrections above showed both findings were wrong, so neither was sent. No notice from that queue has been sent.
Our full corrections ledger is at /corrections.
How to verify
The numbers on this page
Every figure above is in numbers.json, with the record it was recomputed from and that record's sha256. The file is signed in numbers.signed.json and timestamped in numbers.json.ots.
- Fetch the key:
did:web:csoai.org#board-attestation-1in csoai.org/.well-known/did.json (Ed25519,x = k2fPWb6ctyu8l5at8FYgHsHFit_qoT-DssW3VNbCAXA). - Canonicalise
payloadfrom the signed file as JSON with keys sorted, no whitespace, UTF-8. Its sha256 must equalsignature.payload_sha256. payload.artifact.sha256must equal the sha256 of numbers.json as downloaded.- Verify
signature.sig_ed25519(hex) over the canonical payload bytes with the key. - Timestamp:
ots upgrade numbers.json.ots && ots verify numbers.json.ots. At publication the proof is a pending calendar commitment, not yet a Bitcoin attestation; upgrade it later to check.
The records behind them
Most source records are public on Hugging Face with the same sha256 (the appendix links each one), so every count can be recomputed from the published rows. The same signature check applies to each *.signed.json beside them. The cross-runtime, self-parity and public-signal records are not yet published; their sha256 is given so a later publication can be checked against it.
The measurement index
One index binds the day's measurement capsules together. Index sha256 ee3d921750d40456eb58ed24d2a9ba141d6fc1d16510ddd338166c4f5620b72a; index root 85533b833d36f8a4165da34206ee6e39f7434c646c8a2c381d251391ceec366d, an RFC 6962 Merkle tree hash over the sorted capsule ids of all 8 batches (13,184 capsules); root over the batch roots aba3b220f3fc7cc6b056e1620b8cc5f40d282b1841af39856e2152c8349cf5ef. The index signature verifies under the same key; its timestamp is a pending calendar commitment. The index and its capsule batches are not yet published.
Ask for a re-check, or object
If a figure here is wrong, or a row about your service is out of date, email nicholas@csoai.org or use /dispute to object to, dispute or request a correction of anything we publish. Corrections are dated in the ledger.
Appendix: every number and its source
Paths are relative to the measuring host's data volume. "Public copy" links go to a file with the same sha256.
| Number | Value | Source | Recompute |
|---|---|---|---|
| 0.x cards that verify | 5 | a2a_v0_1_1_rows | canonicalisation_rule x sig_state |
| signed cards judged under 0.x rules (no canonicalisation step defined) | 8 | a2a_v0_1_1_rows | rows by canonicalisation_rule |
| 0.x cards that would get another verdict under 1.x rules | 3 | a2a_v0_1_1 | record.signatures.declared_0x_where_1x_rules_give_another_verdict |
| 1.x cards FAILED | 7 | a2a_v0_1_1_rows | canonicalisation_rule x sig_state |
| 1.x cards UNCHECKABLE | 10 | a2a_v0_1_1_rows | canonicalisation_rule x sig_state |
| 1.x cards VERIFIED | 8 | a2a_v0_1_1_rows | canonicalisation_rule x sig_state |
| signed cards judged under A2A 1.x rules (spec 8.4.3) | 25 | a2a_v0_1_1_rows | rows by canonicalisation_rule |
| signed cards FAILED under the rules of the spec version they declare (v0.1.1) | 8 | a2a_v0_1_1_rows | rows with sig_state FAILED |
| signed cards UNCHECKABLE under the rules of the spec version they declare (v0.1.1) | 12 | a2a_v0_1_1_rows | rows with sig_state UNCHECKABLE |
| signed cards VERIFIED under the rules of the spec version they declare (v0.1.1) | 13 | a2a_v0_1_1_rows | rows with sig_state VERIFIED |
| A2A registry listings read by the card census (25 Sep) | 443 | a2a_v0_1_1_rows | rows in cards.v0.1.1.jsonl.gz |
| FAILED cards that verify only over the card as served, defaults included | 6 | a2a_v0_1_1 | record.signatures.failed_that_verify_under_a_non_spec_serialisation |
| A2A registry listings (26 Sep frame) | 445 | mcp_census_v0_2_1 | record.population.frame_sources.a2aregistry.rows_read |
| UNCHECKABLE cards that point to no key at all | 9 | a2a_v0_1_1 | record.signatures.uncheckable_reasons |
| listings that served an agent card | 422 | a2a_v0_1_1_rows | rows with state CARD_SERVED |
| served cards that carry a signature | 33 | a2a_v0_1_1_rows | rows with sig_state other than NO_SIGNATURES |
| signed cards FAILED in the superseded v0.1 record | 3 | a2a_v0_1 | v0.1 rows with sig_state FAILED |
| signed cards UNCHECKABLE in the superseded v0.1 record | 12 | a2a_v0_1 | v0.1 rows with sig_state UNCHECKABLE |
| signed cards VERIFIED in the superseded v0.1 record | 18 | a2a_v0_1 | v0.1 rows with sig_state VERIFIED |
| endpoints in state AUTH_REQUIRED | 4,948 | mcp_census_v0_2_rows | rows with state AUTH_REQUIRED |
| endpoints in state MCP_ERROR | 65 | mcp_census_v0_2_rows | rows with state MCP_ERROR |
| endpoints in state NOT_MCP | 1,411 | mcp_census_v0_2_rows | rows with state NOT_MCP |
| endpoints in state RESPONDED | 13,087 | mcp_census_v0_2_rows | rows with state RESPONDED |
| endpoints in state SSE_ENDPOINT_ONLY | 144 | mcp_census_v0_2_rows | rows with state SSE_ENDPOINT_ONLY |
| endpoints in state TIMEOUT | 212 | mcp_census_v0_2_rows | rows with state TIMEOUT |
| endpoints in state UNREACHABLE | 1,259 | mcp_census_v0_2_rows | rows with state UNREACHABLE |
| 26 Sep responders that answered the 2026-07-28 protocol request | 392 | mcp_census_v0_2_1 | record.protocol_version.era_prober_0.2.modern |
| not contacted because robots.txt disallowed it or could not be read | 934 | mcp_census_v0_2_1 | record.not_attempted_by_reason (robots.txt rows) |
| not contacted because the listed URL is a template | 123 | mcp_census_v0_2_1 | record.not_attempted_by_reason |
| endpoints not contacted, each with a reason | 1,070 | mcp_census_v0_2_rows | rows with state NOT_ATTEMPTED |
| endpoints with an observed state | 21,126 | mcp_census_v0_2_rows | rows whose state is not NOT_ATTEMPTED |
| remote endpoints listed by the MCP registry or the Docker catalogue | 22,196 | mcp_census_v0_2_1 | rows in results.v0.2.public.jsonl.gz |
| 26 Sep responders | 7,282 | mcp_census_v0_2_1 | record.protocol_version.era_prober_0.2 (modern + legacy) |
| endpoints contacted on 26 Sep | 10,039 | mcp_census_v0_2_1 | record.rows_by_observation |
| endpoints whose observed state is carried from the 25 Sep runs (under 48 h old) | 11,087 | mcp_census_v0_2_1 | record.rows_by_observation |
| endpoints where two or more surfaces speak to AUTH | 933 | cp_v0_1_2_rows | AUTH CONSISTENT + INCONSISTENT |
| endpoints INCONSISTENT on AUTH | 5 | cp_v0_1_2_rows | AUTH INCONSISTENT |
| endpoints where two or more surfaces speak to PAYMENT | 116 | cp_v0_1_2_rows | PAYMENT CONSISTENT + INCONSISTENT |
| endpoints INCONSISTENT on PAYMENT | 4 | cp_v0_1_2_rows | PAYMENT INCONSISTENT |
| endpoints where two or more surfaces speak to PROTOCOL | 492 | cp_v0_1_2_rows | PROTOCOL CONSISTENT + INCONSISTENT |
| endpoints INCONSISTENT on PROTOCOL | 33 | cp_v0_1_2_rows | PROTOCOL INCONSISTENT |
| endpoints where two or more surfaces speak to TOOLS | 1,127 | cp_v0_1_2_rows | TOOLS CONSISTENT + INCONSISTENT |
| endpoints INCONSISTENT on TOOLS | 219 | cp_v0_1_2_rows | TOOLS INCONSISTENT |
| endpoints where two or more surfaces speak to VERSION | 5,807 | cp_v0_1_2_rows | VERSION CONSISTENT + INCONSISTENT |
| endpoints INCONSISTENT on VERSION | 2,644 | cp_v0_1_2_rows | VERSION INCONSISTENT |
| endpoints with at least one dimension where two public statements disagree | 2,764 | cp_v0_1_2_rows | rows with any dimension INCONSISTENT |
| same count in the superseded v0.1 record | 2,778 | cp_v0_1 | record.endpoints_with_any_inconsistent |
| same count in the superseded v0.1.1 record | 2,768 | cp_v0_1_1 | record.endpoints_with_any_inconsistent |
| VERSION contradictions whose live value is 0.1.0 | 382 | cp_v0_1_2_rows | INCONSISTENT VERSION rows by live.server_version |
| VERSION contradictions whose live value is 1.0.0 | 514 | cp_v0_1_2_rows | INCONSISTENT VERSION rows by live.server_version |
| endpoints inconsistent on tools, auth, protocol or payment | 256 | cp_v0_1_2_rows | rows with an INCONSISTENT dimension other than VERSION |
| VERSION contradictions between the registry server.version and the live serverInfo.version | 2,632 | cp_v0_1_2 | record.version_namespaces.registry_version_vs_live_serverinfo.differ |
| endpoints in the contract-parity plan, all attempted | 5,828 | cp_v0_1_2_rows | rows in rows.v0.1.2.jsonl.gz |
| endpoints with a surface that did not answer (why the run is PARTIAL) | 247 | cp_v0_1_2 | record.run.read_gaps.endpoints_with_an_unread_surface |
| of those, VERSION INCONSISTENT | 243 | cp_v0_1_2_rows | VERSION state |
| endpoints whose live version is between 1.24.x and 1.29.x | 251 | cp_v0_1_2_rows | live.server_version prefix 1.24.-1.29. |
| distinct hosts among them | 14 | cp_v0_1_2_rows | distinct host |
| of those, VERSION INCONSISTENT | 42 | cp_v0_1_2_rows | VERSION state |
| distinct registry versions they contradict | 9 | cp_v0_1_2_rows | registry claims on those rows |
| endpoints whose live serverInfo.version is 1.27.0 | 43 | cp_v0_1_2_rows | rows with live.server_version == 1.27.0 |
| endpoints inconsistent on VERSION only | 2,508 | cp_v0_1_2_rows | rows whose INCONSISTENT set is exactly {VERSION} |
| distinct remote endpoints the Docker catalogue lists | 77 | mcp_census_v0_2_1 | record.population.frame_sources.docker-mcp-registry.distinct_endpoints |
| Docker MCP catalogue entries | 328 | mcp_census_v0_2_1 | record.population.frame_sources.docker-mcp-registry.rows_read |
| agent ids that declare an MCP, A2A or web endpoint | 13,210 | erc8004_agents_rows | state DECLARES_ENDPOINT |
| agent ids whose file was not fetched (outside the plan, or refused) | 231,014 | erc8004_agents_rows | state NOT_FETCHED |
| registration files that declare no MCP, A2A or web endpoint | 187,513 | erc8004_agents_rows | state NO_ENDPOINT |
| agent ids with no registration URI at all | 52,469 | erc8004_agents_rows | state NO_URI |
| registration URIs that could not be read | 13,788 | erc8004_agents_rows | state URI_UNREACHABLE |
| distinct declared A2A endpoints contacted | 4,389 | erc8004 | record.declared_endpoint_probes.a2a.n_attempted |
| declared A2A endpoints with no card at the well-known path | 3,407 | erc8004 | probe-a2a rows NOT_FOUND |
| declared A2A endpoints that served a card | 886 | erc8004 | probe-a2a rows CARD_SERVED |
| served cards with a signature | 5 | erc8004 | probe-a2a sig_state |
| of those, verified | 4 | erc8004 | probe-a2a sig_state VERIFIED |
| agent ids registered on the ERC-8004 identity registry on three chains | 505,635 | erc8004_agents_rows | rows in agents.jsonl.gz |
| agent ids on base | 95,776 | erc8004_agents_rows | rows by chain |
| agent ids on bsc | 358,401 | erc8004_agents_rows | rows by chain |
| agent ids on ethereum | 51,458 | erc8004_agents_rows | rows by chain |
| declared MCP endpoints that answered but not as MCP | 1,092 | erc8004 | probe-mcp rows NOT_MCP |
| declared MCP endpoints that answered as MCP | 580 | erc8004 | probe-mcp rows RESPONDED |
| declared MCP endpoints unreachable | 393 | erc8004 | probe-mcp rows UNREACHABLE |
| declared MCP endpoints contacted | 2,113 | erc8004 | record.declared_endpoint_probes.mcp.n_attempted |
| distinct declared MCP endpoints planned for a probe | 2,144 | erc8004 | record.declared_endpoint_probes.mcp.n_planned |
| agents in the top-20% plan whose registration files were fetched | 101,127 | erc8004 | record.plan.n_plan |
| Hugging Face Spaces tagged mcp-server (26 Sep frame) | 10,858 | mcp_census_v0_2_1 | record.population.frame_sources.hf-spaces.rows_read |
| Spaces reported as build error | 759 | hf_spaces_rows | rows with state BUILD_ERROR |
| Spaces reported as paused | 1,251 | hf_spaces_rows | rows with state PAUSED |
| Spaces that answered MCP initialize | 2,232 | hf_spaces_rows | rows with state RESPONDED |
| Spaces reported as runtime error | 3,059 | hf_spaces_rows | rows with state RUNTIME_ERROR |
| Spaces reported as sleeping | 3,008 | hf_spaces_rows | rows with state SLEEPING |
| Spaces that offered only legacy SSE | 401 | hf_spaces_rows | rows with state SSE_ENDPOINT_ONLY |
| Spaces contacted (Hub stage RUNNING) | 2,658 | hf_spaces_rows | total minus not contacted |
| Spaces not contacted because the Hub reported them not running | 8,164 | hf_spaces_rows | rows whose state is a Hub runtime stage |
| Spaces covered (25 Sep) | 10,822 | hf_spaces_rows | rows in data/spaces.jsonl.gz |
| capsule batches in the index | 8 | index | batches |
| measurement capsules under the index root | 13,184 | index | union of capsule ids over all batches |
| reproduced the score only | 2 | mill_batch1 | REPRODUCED_AGGREGATE_ONLY |
| signed cards re-run on a second runtime (one model) | 14 | mill_batch1 | capsules |
| item grades that differed | 14 | mill_batch1 | items - grade_equal_items |
| items compared | 887 | mill_batch1 | sum differential.n_items |
| reproduced item by item | 5 | mill_batch1 | REPRODUCED_ITEMWISE |
| did not reproduce | 7 | mill_batch1 | NOT_REPRODUCED |
| raw outputs that differed | 60 | mill_batch1 | raw_output_differing_item_ids |
| cards that reproduced the score only | 9 | mill_batch2 | REPRODUCED_AGGREGATE_ONLY |
| axes in batch 2 | 14 | mill_batch2_parity_summary | distinct axis |
| signed cards re-run on a second runtime | 140 | mill_batch2 | capsules |
| item grades equal on both runtimes | 8,624 | mill_batch2 | sum differential.grade_equal_items |
| item grades equal, per cent | 97.2 | mill_batch2 | grade_equal / items |
| items compared | 8,870 | mill_batch2 | sum differential.n_items |
| cards with the same grade on every item | 49 | mill_batch2 | REPRODUCED_ITEMWISE |
| models in batch 2 | 10 | mill_batch2_parity_summary | distinct model |
| cards that did not reproduce | 82 | mill_batch2 | NOT_REPRODUCED |
| raw outputs byte-equal on both runtimes | 7,404 | mill_batch2_parity_summary | sum raw_eq |
| model-axis pairs where a same-runtime repeat was not byte-identical | 20 | mill_batch2_parity_summary | repeat_raw_eq not n/n |
| cards meeting the item-level rule (same counts and same grade on every item) | 46 | mill_batch2 | REPRODUCED_ITEMWISE with declared.counts == observed.counts; equals the dry run |
| of those, cards with at least 30 graded items, released for quoting | 37 | mill_batch2_admission | dry-run rows meeting the rule with n >= 30 |
| registry endpoints under our own names | 40 | mcp_census_v0_2_rows | rows with own_estate true |
| of those, unreachable | 39 | mcp_census_v0_2_rows | own_estate rows with state UNREACHABLE |
| signals from outside | 15 | public_signals | summary.by_self_or_external |
| of those, measured | 103 | public_signals | summary.by_state |
| signals where ours and others' cannot be separated | 43 | public_signals | summary.by_self_or_external |
| signals that are our own activity | 50 | public_signals | summary.by_self_or_external |
| public signals about ourselves recorded daily | 118 | public_signals | summary.n_signals |
| distinct remote endpoints those registry entries list | 22,151 | mcp_census_v0_2_1 | record.population.frame_sources.mcp-registry.distinct_endpoints |
| official MCP registry entries read (latest versions), read to its end | 36,134 | mcp_census_v0_2_1 | record.population.frame_sources.mcp-registry.rows_read |
| registry entries in the 25 Sep read | 35,873 | mcp_census_v0_2_1 | record.population.vs_2026-09-25_frame |
| Smithery's own declared total | 17,268 | mcp_census_v0_2_1 | record.population.frame_sources.smithery.reason ('declared totalCount=17268') |
| distinct Smithery entries the anonymous API served (PARTIAL) | 264 | mcp_census_v0_2_1 | record.population.frame_sources.smithery.reason ('500 rows served, 264 distinct') |
| cells CONSISTENT | 37 | self_parity | state CONSISTENT |
| cells INCONSISTENT | 8 | self_parity | state INCONSISTENT |
| cells NOT_DECLARED | 1 | self_parity | state NOT_DECLARED |
| cells NOT_LISTED | 55 | self_parity | state NOT_LISTED |
| cells UNCHECKABLE | 37 | self_parity | state UNCHECKABLE |
| cells: our offerings x the indexes that could list them | 138 | self_parity | capsules |
| directory tool list that differs from what our MCP server serves | 1 | self_parity | INCONSISTENT tools cells |
| registry package version that lags the package index | 1 | self_parity | INCONSISTENT version cells |
| our x402 listings whose listed URL query string differs from our manifest | 6 | self_parity | INCONSISTENT x402 cells |
| hosts that answered HTTP 402 | 1,636 | x402_snapshot_2026_09_26 | rows with status 402 |
| resources in one index (read complete) | 17,548 | x402_summary_2026_09_26 | indexes.cdp.resources |
| hosts fully conformant (402 + header + v2 body + Bazaar block) | 477 | x402_snapshot_2026_09_26 | rows with conformant true |
| conformant share of hosts, per cent | 17.58 | x402_summary_2026_09_26 | headline.conformant_pct |
| hosts that sent a PAYMENT-REQUIRED header | 1,527 | x402_summary_2026_09_26 | headline.carried_payment_required_header |
| hosts that pass on the header but not in the body | 1,013 | x402_summary_2026_09_26 | header_v2_bazaar_not_body |
| distinct hosts across both public x402 Bazaar indexes | 2,713 | x402_snapshot_2026_09_26 | rows in the snapshot |
| hosts added | 26 | x402_diff_2026_09_26 | hosts_added |
| hosts dropped | 48 | x402_diff_2026_09_26 | hosts_dropped |
| lost conformance | 4 | x402_diff_2026_09_26 | lost_conformance |
| newly conformant | 3 | x402_diff_2026_09_26 | newly_conformant |
| resources in the other index (read complete) | 6,909 | x402_summary_2026_09_26 | indexes.payai.resources |
| conformant the day before | 470 | x402_diff_2026_09_26 | conformant_previous |
| hosts the day before | 2,735 | x402_diff_2026_09_26 | previous_hosts |
| hosts unreachable | 19 | x402_snapshot_2026_09_26 | rows with no status |
| hosts that declared x402Version 2 in the body | 555 | x402_summary_2026_09_26 | headline.x402_version_2 |
| deployments read at evidence level OPERATOR_API | 52 | xl_daily | deployments with evidence_kind OPERATOR_API |
| distinct ledgers at evidence level OPERATOR_API | 20 | xl_daily | distinct ledger |
| deployments read at evidence level STATE_PROOF_RECORDED | 9 | xl_daily | deployments with evidence_kind STATE_PROOF_RECORDED |
| distinct ledgers at evidence level STATE_PROOF_RECORDED | 6 | xl_daily | distinct ledger |
| deployments read at evidence level STATE_PROOF_VERIFIED | 40 | xl_daily | deployments with evidence_kind STATE_PROOF_VERIFIED |
| distinct ledgers at evidence level STATE_PROOF_VERIFIED | 16 | xl_daily | distinct ledger |
| deployments read at evidence level UNCHECKABLE | 12 | xl_daily | deployments with evidence_kind UNCHECKABLE |
| distinct ledgers at evidence level UNCHECKABLE | 6 | xl_daily | distinct ledger |
| selected assets with an issuer list reader wired | 21 | xl_daily | len(assets) |
| issuer-listed deployments read | 113 | xl_daily | len(deployments) |
| deployments an issuer lists as deprecated that still show issued supply | 3 | xl_daily | parity.findings_inconsistent kind |
| contracts on a ledger the issuer does not list, at a listed address, answering with the product symbol | 1 | xl_daily | parity.findings_inconsistent kind |
| tokenised-asset candidates with a positive value in the public value sources | 280 | xl_daily | selection.frame_n |
| top fifth selected to read first | 56 | xl_daily | selection.k |
| assets on private, permissioned ledgers: nothing a third party can read | 3 | xl_daily | PERMISSIONED_NOT_READABLE |
| assets whose issuer publishes a readable deployment list | 14 | xl_daily | assets.issuer_list_state READ |
| assets with no public deployment list | 1 | xl_daily | ISSUER_LIST_UNAVAILABLE |
| assets whose list page could not be read | 3 | xl_daily | UNCHECKABLE |
| assets whose issuer claims vs ledgers are CONSISTENT | 4 | xl_daily | parity.asset_states |
| assets whose issuer claims vs ledgers are INCONSISTENT | 2 | xl_daily | parity.asset_states |
| assets whose issuer claims vs ledgers are UNCHECKABLE | 15 | xl_daily | parity.asset_states |
| selected assets not read (no issuer-list reader wired): UNMEASURED | 41 | xl_daily | len(unmeasured_selected) |
| Source | Record | sha256 | Board signature |
|---|---|---|---|
| a2a_v0_1 | A2A signed agent-card census, record v0.1 (superseded, kept) census-universes-publish-2026-09-25/a2a/record.json public copy | b290b53d05912d8b3a5913c7e73e693f40cc71be8e0432c4626643c6d662176c | VERIFIES (2026-09-25T08:22:33.567Z) |
| a2a_v0_1_1 | A2A signed agent-card census, record v0.1.1 (correction) cp-fix-20260926/a2a-corr/out/record.v0.1.1.json public copy | 4a2b46bb42aa727363ca04d8a2cc21ed76b50a4c6937a62f80d6fcfda191af91 | VERIFIES (2026-09-26T04:06:22.149Z) |
| a2a_v0_1_1_rows | A2A card census v0.1.1 rows, one per registry listing cp-fix-20260926/a2a-corr/out/data/cards.v0.1.1.jsonl.gz public copy | 93f9865008531a9cb5c44bc8c8d32a1bf1dc775c4e3ec9880128f13c6ab2791c | no signature of its own; sha256 given |
| cp_v0_1 | MCP contract parity, record v0.1 (superseded, kept) contract-parity-2026-09-25/record/record.json public copy | 45e3fd63fc98ad251a4f9fe5fdb705ed7fbc28321d5c205d10114a21730cc323 | VERIFIES (2026-09-25T12:25:41.808Z) |
| cp_v0_1_1 | MCP contract parity, record v0.1.1 (superseded, kept) cp-fix-20260926/record/record.v0.1.1.json public copy | 9cd02be424bf608d41f40522e48188f5a9ef4d13c8de6e28023b20a941fd4ef8 | VERIFIES (2026-09-26T02:21:40.535Z) |
| cp_v0_1_2 | MCP contract parity, record v0.1.2 (correction) cp-fix-20260926/v012/rec/record.v0.1.2.json public copy | 5a9bedff1b6facbd9e19a1db1282b37fb6cedd9bf6c7dd14aeeeff387eae77ed | VERIFIES (2026-09-26T07:32:39.698Z) |
| cp_v0_1_2_rows | MCP contract parity v0.1.2 rows, one per endpoint cp-fix-20260926/v012/rec/rows.v0.1.2.jsonl.gz public copy | 8fb15bcbb83db1ae6a61945c2f870a16d27adcc751c059439e63d8e910730492 | no signature of its own; sha256 given |
| erc8004 | ERC-8004 agent census, record 26 Sep 2026 stage/erc8004-agent-census/record.json public copy | 60bd9728f22159351feb71ccd6e0c01faab582f0ccf661415e36f339e52d2538 | VERIFIES (2026-09-26T05:31:49.737Z) |
| erc8004_agents_rows | ERC-8004 agent rows, one per registered agent id stage/erc8004-agent-census/agents.jsonl.gz public copy | eafd6b18313df16a139114347f136afc527d7c349f01e7c348a436657e9b6995 | no signature of its own; sha256 given |
| hf_spaces | Hugging Face Spaces tagged mcp-server, record of 25 Sep 2026 census-universes-publish-2026-09-25/hf/record.json public copy | 53022d26ca321b291ca5578b3b318ef645ecf1e4343b13320ebc91642abb906e | VERIFIES (2026-09-25T08:22:30.245Z) |
| hf_spaces_rows | Hugging Face Spaces rows, one per Space census-universes-publish-2026-09-25/hf/data/spaces.jsonl.gz public copy | 7b9bb0d630444a41f5757499f14e096e0fb37431c69aed6ebbc2aa0ba415088c | no signature of its own; sha256 given |
| index | Measurement-capsule index v0.2 (26 Sep 2026): one signed root over every capsule batch measurement-index-v0.2-2026-09-26.json | ee3d921750d40456eb58ed24d2a9ba141d6fc1d16510ddd338166c4f5620b72a | VERIFIES (2026-09-26T10:34:15.836Z) |
| mcp_census_v0_2_1 | Remote MCP endpoint census, record v0.2.1 (corrected label; counts identical to v0.2) census-v0.2-2026-09-26/pub/record.v0.2.1.json public copy | 3155502aa629a3e0e8dd0240862933e475cc2afaf3417d03c0efa314d139c4bd | VERIFIES (2026-09-26T07:33:47.357Z) |
| mcp_census_v0_2_rows | Remote MCP endpoint census v0.2 rows, one per endpoint census-v0.2-2026-09-26/pub/results.v0.2.public.jsonl.gz public copy | a9b644a17e116c1c6f12c4ecacbb013bab62b3d04f5e84f4715578406984fc70 | no signature of its own; sha256 given |
| mcp_census_v0_2_superseded | Remote MCP endpoint census, record v0.2 (superseded, kept) census-v0.2-2026-09-26/pub/record.v0.2.json public copy | a18447e5bb27decbc7d20c1542994811f47dee94b4650faed7b231af5c5d72bd | VERIFIES (2026-09-26T07:04:34.530Z) |
| mill_batch1 | Cross-runtime reproduction, batch 1 (one model, 14 cards) measurement-capsules-v0.2-2026-09-26-mill_cross_runtime/record.json | 32ece857c94062f41a03aad9e269532cdbe5dc0a576ed20110edc4ecacb0468d | VERIFIES (2026-09-26T06:20:12.622Z) |
| mill_batch2 | Cross-runtime reproduction, batch 2 (10 models x 14 axes) measurement-capsules-v0.2-2026-09-26-mill_cross_runtime-batch2/record.json | 422fa6377b274bab095e8e875f67d087a275417c14c90a4c4e4cedb56ca9a5ff | VERIFIES (2026-09-26T10:33:45.092Z) |
| mill_batch2_admission | Cross-runtime batch 2, item-level rule dry run mill-kaggle-batch2-2026-09-26/admission-dryrun.txt.gz | 20a0210e39d54dcbaa4067c0f7a8c5241a915df78ed7edbae6d53c03820f2ccf | no signature of its own; sha256 given |
| mill_batch2_parity_summary | Cross-runtime batch 2, per-card item comparison mill-kaggle-batch2-2026-09-26/parity-summary.json | a3bd67a4fd119a4c5f0ec2190c2dde0aff1064bcdeb25c0d4961e541055d4e59 | no signature of its own; sha256 given |
| public_signals | Public signals about ourselves, 26 Sep 2026 public-signals/2026-09-26/record.json | 7c23af1cea95c58d99a2eff2928c5637f38057d238d1b44e49fb8832460f81b0 | VERIFIES (2026-09-26T08:31:57.056Z) |
| self_parity | Self-parity: how external indexes list our own offerings, 26 Sep 2026 self-parity/2026-09-26/record.json | a2f205ca43d096ec0e9f621d8e0dcda2bd2d8040b39ff277ef7ae50fa9de4dfe | VERIFIES (2026-09-26T05:46:23.225Z) |
| tool_drift | Tool-list drift between two observations (capsule batch) measurement-capsules-v0.2-2026-09-26-tool_drift/record.json | a7a13dab161631d0557726fd64c0dee82bd0b95cb54e2749d96aaddc93fef473 | VERIFIES (2026-09-26T06:53:20.454Z) |
| x402_diff_2026_09_26 | x402 day-on-day diff 25 to 26 Sep 2026 flywheel/x402/diff-2026-09-26.json | ff101ce3705cf1ee1ae3284f572cec4d7e9cc92889b6c68a9a0aa2aa7a35cbd9 | no signature of its own; sha256 given |
| x402_release_2026_09_25 | x402 Bazaar conformance, daily release 25 Sep 2026 flywheel/x402/release-2026-09-25.json | 0d84f400f17a0d771e557d51a5a2edd0674d05c617e23f73d4d5c87db1bae1f4 | VERIFIES (2026-09-25T11:32:26.082Z) |
| x402_release_2026_09_26 | x402 Bazaar conformance, daily release 26 Sep 2026 flywheel/x402/release-2026-09-26.json public copy | 4e7635ae398be274371ee48a81f7cb1def46c13ef01742e830bbea93b8c13a0b | VERIFIES (2026-09-26T01:11:11.344Z) |
| x402_snapshot_2026_09_26 | x402 Bazaar conformance snapshot, one row per host flywheel/x402/snapshots/conformance-2026-09-26.jsonl public copy | 5faccd86a679f1407da1926e11fba5e98f9e1367f494f56b48f3978369f92853 | no signature of its own; sha256 given |
| x402_summary_2026_09_26 | x402 Bazaar conformance summary 26 Sep 2026 flywheel/x402/summary-2026-09-26.json public copy | 4705777f34e72bf935b19398dca486ad252212531ede84d963086087f6d2e3cd | no signature of its own; sha256 given |
| xl_daily | Cross-ledger daily read of tokenised assets, 26 Sep 2026 xl-daily/2026-09-26/xl-daily-2026-09-26.json public copy | b02851fcbc8ea5ad6460c6c847e8af9eaec74d36a09121989590dc180a5d700d | VERIFIES (2026-09-26T06:44:44.913Z) |