State of the Agent Internet: September 2026

Published 26 September 2026 by Council of AI (CSOAI Ltd, registered in England and Wales, no. 16939677). Figures as of 2026-09-26 10:34:15 UTC.

Measurement, not endorsement. This report gives aggregates only. It names no service, operator or issuer in a negative finding, and it scores, ranks or approves no company. An INCONSISTENT or FAILED result says that two public statements disagree, or that a check did not pass. It is not evidence of bad intent.

Summary

An agent that finds a service through a public catalogue can trust very little about it without checking. Discovery is abundant. Verification is the exception.

  • The official MCP registry held 36,134 entries listing 22,151 distinct remote endpoints. Of the 22,196 endpoints in the two MCP catalogues we read in full, we observed 21,126, and 13,087 answered as MCP servers.
  • 2,764 of 5,828 responding MCP endpoints contradict themselves across their own public documents on at least one point. Most of these are version strings. 256 disagree on something with more substance: tools, authentication, protocol or payment.
  • Of 422 A2A agent cards served, 33 carry a signature and 13 verify under the rules of the spec version the card declares.
  • Of 2,713 x402 payment hosts, 1,636 answered with HTTP 402 and 477 (17.58%) returned a fully conformant challenge.
  • For tokenised assets, a third-party state proof of supply was possible on 40 of 113 issuer-listed deployments we read. The others rely on an operator's API, or could not be checked.
  • Re-running signed model measurements on a second runtime, 46 of 140 cards reproduced item by item with the same counts, although 97.2% of individual item grades matched.
  • We measured ourselves first and found 8 places where external indexes list us differently from what we publish. We published three corrections to our own figures on the day of this report.

Discovery: what the catalogues contain

On 26 September a census frame read five public catalogues, each paginated to its signalled end where it had one.

Catalogues read on 26 September 2026
CatalogueRead stateEntriesDistinct endpoints
Official MCP registry (latest versions)EXHAUSTED36,13422,151
Hugging Face Spaces tagged mcp-serverEXHAUSTED10,85810,858
A2A registryEXHAUSTED445(cards, below)
Docker MCP catalogueEXHAUSTED32877
SmitheryPARTIAL264 of a declared 17,268none listed

Smithery's anonymous interface stops after five pages and lists no endpoint URLs, so the read is PARTIAL and we give no combined population total. The registry grew from 35,873 entries in our read of the previous day.

Which MCP endpoints answer

The population is every remote endpoint listed by the MCP registry or the Docker catalogue: 22,196. We sent only discovery requests, never a tool call, never a credential and never a payment, at most one request per second per host, and honoured robots.txt. 10,039 endpoints were contacted on 26 September; for 11,087 the state observed on 25 September (under 48 hours old) is carried. 1,070 were not contacted, each with a recorded reason (934 because of robots.txt, 123 because the listed URL was a template). The read state is therefore PARTIAL.

State of each remote MCP endpoint
StateEndpoints
Answered as an MCP server13,087
Asked for authentication4,948
Answered, but not as MCP1,411
Unreachable1,259
Timed out212
Legacy SSE endpoint only144
MCP error65
Not contacted (reason recorded)1,070

Of the 7,282 endpoints that answered on 26 September, 392 answered the newest protocol request (2026-07-28); the rest answered only the earlier handshake.

Hugging Face Spaces

On 25 September we covered all 10,822 Spaces tagged mcp-server. We read each Space's runtime stage from the Hub first and contacted a Space only if it was running, so none was woken. 8,164 were not running: 3,059 in a runtime error, 3,008 asleep, 1,251 paused and 759 with a build error, among other stages. Of the 2,658 contacted, 2,232 answered MCP and 401 offered only legacy SSE. About one tagged Space in five was serving MCP at that moment. A tag is self-declared.

Does the listing match the server?

The question is whether one MCP service tells a relying agent one current contract. We compared what each service says about itself across its public surfaces (its registry entry, /.well-known/mcp.json, its server card and any x402 manifest) with its live discovery answer. A dimension is judged only where two or more surfaces speak to it. The plan was 5,828 endpoints, and every one was attempted (record v0.1.2).

Contract parity by dimension, record v0.1.2
DimensionComparedInconsistentRate
VERSION5,8072,64445.5%
TOOLS1,12721919.4%
PROTOCOL492336.7%
PAYMENT11643.4%
AUTH93350.5%
  • Endpoints with at least one inconsistent dimension: 2,764 of 5,828 (47.4%). The superseded records gave 2,778 and then 2,768; see Corrections.
  • Inconsistent on VERSION only: 2,508. Inconsistent on another dimension: 256.
  • 247 endpoints had a surface that did not answer, so this run is labelled PARTIAL.

The version dimension

2,632 of the 2,644 version contradictions compare the registry's server.version with the live serverInfo.version. The registry schema calls these the same field ("Equivalent of Implementation.version in MCP specification"), so we compare them. The most common live values among the contradictions are 1.0.0 (514) and 0.1.0 (382). A version contradiction is weak evidence that anything is wrong. It is strong evidence that a version string is not a reliable way for an agent to pin a contract.

A pattern, cause not measured: 43 endpoints on 14 hosts report the live version 1.27.0, and 42 of them contradict a registry that gives 9 different versions for them. Across live values from 1.24.x to 1.29.x, 243 of 251 contradict the registry. One possible explanation is that a library fills in its own version when a server sets none. That is a hypothesis; we have not measured it.

Timing: live answers and documents were read up to about 5.5 hours apart, so a deploy in between can show as INCONSISTENT. An inconsistent row says that two public statements disagree. It does not say which one is true.

Signed agent cards

The A2A card census covered all 443 registry listings (25 September). 422 served a card, and 33 of those (7.8%) carry a signature. Each card is judged by the rules of the spec version it declares (record v0.1.1):

Signed agent cards by verification result
ResultRecord v0.1.1Superseded v0.1
Verified1318
Failed83
Uncheckable (no usable key)1212

Why the numbers moved: A2A spec section 8.4.3 (step 3) says to remove properties that hold default values before verifying. Our first prober did not. Of the 25 signed cards that declare 1.x, 8 verify under the spec's procedure, 7 fail and 10 are uncheckable. 6 of the failures verify over the card as served, with defaults left in: the signing tools skipped the step the spec requires. 3 cards that declare 0.x verify under 0.x rules, which define no canonicalisation, but would get another result under 1.x rules. 9 of the uncheckable cards point to no key at all.

Our reading is that signing tools and the spec's verification procedure currently disagree. That is a finding about a canonicalisation gap, not about bad actors. A verified card proves only that the key it points to signed its bytes. It does not prove who the agent is.

On-chain agent registrations

The ERC-8004 identity registry lets anyone register an agent on-chain. We read every agent id on three chains with read-only calls: 505,635 ids (51,458 on Ethereum, 95,776 on Base, 358,401 on BNB Smart Chain). An id is not an operator; one operator can hold many.

  • 52,469 ids have no registration file at all.
  • We fetched registration files for the top fifth by a published feedback signal (101,127 ids). 231,014 ids were outside that plan or refused, 13,788 files could not be read, and 187,513 files declare no MCP, A2A or web endpoint.
  • 13,210 ids declare an endpoint. Of 2,144 distinct declared MCP endpoints, we contacted 2,113: 580 answered as MCP, 1,092 answered but not as MCP and 393 were unreachable.
  • Of 4,389 declared A2A endpoints, 886 served a card and 3,407 had none at the well-known path. 5 served cards carry a signature, and 4 verify.

This census is PARTIAL: registration files were fetched only for the plan, and within a fetch budget.

Payment doors (x402)

Each day we read both public x402 Bazaar indexes to the end (17,548 and 6,909 resources) and send one GET to each distinct host. Nothing is paid. On 26 September there were 2,713 hosts:

  • 1,636 answered HTTP 402; 1,527 sent a PAYMENT-REQUIRED header; 555 declared x402Version: 2 in the body.
  • 477 (17.58%) were fully conformant: a 402, the header, version 2 in the body and a Bazaar extension block.
  • 1,013 pass on the header alone but not in the body. 19 were unreachable.
  • The day before there were 2,735 hosts and 470 conformant: 26 hosts were added, 48 dropped, 3 became conformant and 4 lost conformance.

Context from others (their findings, not ours)

We did not measure settlement volume or who pays whom. Two published on-chain analyses did. Visa and Artemis ("Agentic Payments from the Ground Up", July 2026) report that x402's raw totals of about 135.7 million US dollars settled across 178.3 million transactions fall to about 15.0 million dollars across 109.6 million once activity resembling wash trading, testing or internal transfers is filtered: roughly 89% of the dollars and 39% of the transactions. TRM Labs (9 September 2026) examined 52.7 million dollars settled across 198.9 million x402 transactions on Base, Solana and Polygon, found 25.62 million dollars likely to be commerce, and attributed 0.6% to 7.5% of that to AI agents. The two use different methods and windows, and their figures should not be combined. Visa and Artemis · TRM Labs. Our own measurement says nothing about whether any door would deliver after payment.

Tokenised assets across ledgers

The question: where an issuer publishes a list of where its asset lives, can a third party read each ledger, and with what strength of evidence? From 280 tokenised-asset candidates in public value sources we took the top fifth (56) to read first. Value decides only what we read first; it is not a measurement and not a ranking. 21 selected assets have an issuer-list reader wired; 41 do not and are UNMEASURED. We read 113 issuer-listed deployments on 26 September.

Evidence ladder: deployments read, by strength of evidence
Evidence levelDeploymentsWhat it meansLedgers
STATE_PROOF_VERIFIED40Supply read with a Merkle state proof, checked against a block header whose hash we recomputed. The header is not checked against validator signatures.abcore, arbitrum, base, bsc, celo, ethereum, ink, linea, mantle, morph, noble, optimism, polygon, robinhood, sonic, unichain
STATE_PROOF_RECORDED9A proof was returned and kept, but the block header could not be recomputed, so it is not bound to the block.avalanche, cronos, kaia, kava, tempo, xrplevm
OPERATOR_API52The number comes from a node or API operator. No proof.aptos, bsc, ethereum, hedera, hyperevm, mantle, monad, near, plasma, plume, polygon, solana, stellar, sui, ton, tron, unichain, xlayer, xrpl, zksync
UNCHECKABLE12The read failed, or the list could not be compared.aptos, arbitrum, avalanche, base, sei, worldchain
  • The level depends on the pair of reader and ledger, not only on the ledger: the same chain can appear at two levels for different assets.
  • Issuer lists: 14 assets publish a readable deployment list. 3 are bank deposit-token services on private, permissioned ledgers, with nothing a third party can read. 1 has no public deployment list, and 3 list pages could not be read.
  • Issuer claims against ledgers: 4 assets consistent, 2 inconsistent, 15 uncheckable. The inconsistencies fall into two classes: 3 deployments that an issuer lists as deprecated still show issued supply ("deprecated" is the issuer's word; we do not assess its meaning), and 1 contract, on a ledger the issuer does not list and at an address it lists elsewhere, answers with the product's symbol. Whether that contract is the issuer's is not established.
  • These reads measure issued supply only. They say nothing about reserves, backing, net asset value, ownership or redeemability, and there is no cross-asset total. Nothing here is investment advice.

The same model on two runtimes

A published score is only useful if it belongs to the model rather than to the machine it ran on. We re-ran signed measurement cards on a second runtime with the same model digest, the same instrument and the same item bank: the first runs were on an RTX 3090, the re-runs on Kaggle 2×T4 (ollama 0.33.0, temperature 0, seed 0).

Cross-runtime reproduction of signed measurement cards
MeasureBatch 1Batch 2
Scope1 model, 14 axes10 models × 14 axes
Cards re-run14140
Same grade on every item549
Same score only (item grades differed)29
Not reproduced782
Items compared8878,870
Item grades that differed14246

In batch 2, 8,624 of 8,870 item grades matched (97.2%) and 7,404 raw outputs were byte-identical. Yet only 49 cards had the same grade on every item, and 46 of those also had the same counts. Two runs can reach the same score with different item grades, so we now admit a reproduction only at the item level: same instrument, model and bank, same counts, and the same grade on every item. The 37 cards that meet that rule with at least 30 graded items are released for quoting; the rest are not.

The second runtime is not deterministic either: a repeat on the same T4s was not byte-identical for 20 model-axis pairs. The 3090's GPU driver and its ollama version at run time were not recorded, and two runtimes cannot separate hardware effects from the software stack. A third runtime would be needed.

Ourselves first

Before measuring anyone else, we measured how external indexes list us: 138 cells, one for each of our offerings in each index that could list it.

  • 37 consistent, 8 inconsistent, 55 not listed (recorded only after a complete read of an open directory), 37 uncheckable and 1 not declared.
  • The 8 inconsistencies are ours to fix: 6 x402 listings whose URL query string differs from our manifest, 1 directory tool list that differs from what our MCP server serves, and 1 registry package version that lags the package index.
  • 40 registry endpoints are listed under our own names, and 39 of them point at a host that does not resolve. They are counted as unreachable in the census above, like anyone else's.
  • We also record 118 public signals about ourselves each day (downloads, citations, index listings): 103 were measured. 50 are our own activity, 15 come from outside and 43 cannot be separated, so download counts are context, not users.

What we did not measure

  • Whether any service, agent, card or payment door is safe, correct, maintained, or does what it says.
  • Anything behind authentication. We sent no credential, called no tool and paid for nothing.
  • Smithery beyond the entries its anonymous interface serves; any combined population total.
  • Reachability from any other network location, or at any other time.
  • Which of two disagreeing public statements is true.
  • Identity: a verified signature proves who holds a key, not who an agent is.
  • Payment settlement, delivery after payment, price or volume.
  • Reserves, backing, net asset value, holders or redeemability of any asset; the 41 selected assets with no reader wired; permissioned ledgers.
  • A third runtime for the reproduction study, the 3090's driver, or its ollama version at run time.
  • Traffic or ranking in any index that lists us.

Corrections

We published three corrections to our own published figures on 26 September 2026. Each superseded record stays published byte for byte beside its correction.

  1. Contract parity v0.1 to v0.1.1. Four misreads in the producer were fixed. Endpoints with any inconsistency went from 2,778 to 2,768.
  2. A2A card census v0.1 to v0.1.1. The spec's default-value removal (section 8.4.3) was not applied in v0.1. Verified cards went from 18 to 13, failed from 3 to 8.
  3. Contract parity v0.1.1 to v0.1.2. Three method defects were fixed: an asymmetric authentication rule, a tool list read as a contradiction when only part of it is public before authentication, and a surface that did not answer being counted as silence. Endpoints with any inconsistency went from 2,768 to 2,764, and the run is now labelled PARTIAL.

A fourth change corrected a label only: the MCP endpoint census v0.2 had said EXHAUSTED while 1,070 endpoints were not contacted. Record v0.2.1 says PARTIAL. No count changed.

Two notices were cancelled. We had prepared private notes to two service operators about findings in our data, one about an agent-card signature and one about an authentication declaration. The corrections above showed both findings were wrong, so neither was sent. No notice from that queue has been sent.

Our full corrections ledger is at /corrections.

How to verify

The numbers on this page

Every figure above is in numbers.json, with the record it was recomputed from and that record's sha256. The file is signed in numbers.signed.json and timestamped in numbers.json.ots.

  1. Fetch the key: did:web:csoai.org#board-attestation-1 in csoai.org/.well-known/did.json (Ed25519, x = k2fPWb6ctyu8l5at8FYgHsHFit_qoT-DssW3VNbCAXA).
  2. Canonicalise payload from the signed file as JSON with keys sorted, no whitespace, UTF-8. Its sha256 must equal signature.payload_sha256.
  3. payload.artifact.sha256 must equal the sha256 of numbers.json as downloaded.
  4. Verify signature.sig_ed25519 (hex) over the canonical payload bytes with the key.
  5. Timestamp: ots upgrade numbers.json.ots && ots verify numbers.json.ots. At publication the proof is a pending calendar commitment, not yet a Bitcoin attestation; upgrade it later to check.

The records behind them

Most source records are public on Hugging Face with the same sha256 (the appendix links each one), so every count can be recomputed from the published rows. The same signature check applies to each *.signed.json beside them. The cross-runtime, self-parity and public-signal records are not yet published; their sha256 is given so a later publication can be checked against it.

The measurement index

One index binds the day's measurement capsules together. Index sha256 ee3d921750d40456eb58ed24d2a9ba141d6fc1d16510ddd338166c4f5620b72a; index root 85533b833d36f8a4165da34206ee6e39f7434c646c8a2c381d251391ceec366d, an RFC 6962 Merkle tree hash over the sorted capsule ids of all 8 batches (13,184 capsules); root over the batch roots aba3b220f3fc7cc6b056e1620b8cc5f40d282b1841af39856e2152c8349cf5ef. The index signature verifies under the same key; its timestamp is a pending calendar commitment. The index and its capsule batches are not yet published.

Ask for a re-check, or object

If a figure here is wrong, or a row about your service is out of date, email nicholas@csoai.org or use /dispute to object to, dispute or request a correction of anything we publish. Corrections are dated in the ledger.

Appendix: every number and its source

Paths are relative to the measuring host's data volume. "Public copy" links go to a file with the same sha256.

Every number on this page with its source record
NumberValueSourceRecompute
0.x cards that verify5a2a_v0_1_1_rowscanonicalisation_rule x sig_state
signed cards judged under 0.x rules (no canonicalisation step defined)8a2a_v0_1_1_rowsrows by canonicalisation_rule
0.x cards that would get another verdict under 1.x rules3a2a_v0_1_1record.signatures.declared_0x_where_1x_rules_give_another_verdict
1.x cards FAILED7a2a_v0_1_1_rowscanonicalisation_rule x sig_state
1.x cards UNCHECKABLE10a2a_v0_1_1_rowscanonicalisation_rule x sig_state
1.x cards VERIFIED8a2a_v0_1_1_rowscanonicalisation_rule x sig_state
signed cards judged under A2A 1.x rules (spec 8.4.3)25a2a_v0_1_1_rowsrows by canonicalisation_rule
signed cards FAILED under the rules of the spec version they declare (v0.1.1)8a2a_v0_1_1_rowsrows with sig_state FAILED
signed cards UNCHECKABLE under the rules of the spec version they declare (v0.1.1)12a2a_v0_1_1_rowsrows with sig_state UNCHECKABLE
signed cards VERIFIED under the rules of the spec version they declare (v0.1.1)13a2a_v0_1_1_rowsrows with sig_state VERIFIED
A2A registry listings read by the card census (25 Sep)443a2a_v0_1_1_rowsrows in cards.v0.1.1.jsonl.gz
FAILED cards that verify only over the card as served, defaults included6a2a_v0_1_1record.signatures.failed_that_verify_under_a_non_spec_serialisation
A2A registry listings (26 Sep frame)445mcp_census_v0_2_1record.population.frame_sources.a2aregistry.rows_read
UNCHECKABLE cards that point to no key at all9a2a_v0_1_1record.signatures.uncheckable_reasons
listings that served an agent card422a2a_v0_1_1_rowsrows with state CARD_SERVED
served cards that carry a signature33a2a_v0_1_1_rowsrows with sig_state other than NO_SIGNATURES
signed cards FAILED in the superseded v0.1 record3a2a_v0_1v0.1 rows with sig_state FAILED
signed cards UNCHECKABLE in the superseded v0.1 record12a2a_v0_1v0.1 rows with sig_state UNCHECKABLE
signed cards VERIFIED in the superseded v0.1 record18a2a_v0_1v0.1 rows with sig_state VERIFIED
endpoints in state AUTH_REQUIRED4,948mcp_census_v0_2_rowsrows with state AUTH_REQUIRED
endpoints in state MCP_ERROR65mcp_census_v0_2_rowsrows with state MCP_ERROR
endpoints in state NOT_MCP1,411mcp_census_v0_2_rowsrows with state NOT_MCP
endpoints in state RESPONDED13,087mcp_census_v0_2_rowsrows with state RESPONDED
endpoints in state SSE_ENDPOINT_ONLY144mcp_census_v0_2_rowsrows with state SSE_ENDPOINT_ONLY
endpoints in state TIMEOUT212mcp_census_v0_2_rowsrows with state TIMEOUT
endpoints in state UNREACHABLE1,259mcp_census_v0_2_rowsrows with state UNREACHABLE
26 Sep responders that answered the 2026-07-28 protocol request392mcp_census_v0_2_1record.protocol_version.era_prober_0.2.modern
not contacted because robots.txt disallowed it or could not be read934mcp_census_v0_2_1record.not_attempted_by_reason (robots.txt rows)
not contacted because the listed URL is a template123mcp_census_v0_2_1record.not_attempted_by_reason
endpoints not contacted, each with a reason1,070mcp_census_v0_2_rowsrows with state NOT_ATTEMPTED
endpoints with an observed state21,126mcp_census_v0_2_rowsrows whose state is not NOT_ATTEMPTED
remote endpoints listed by the MCP registry or the Docker catalogue22,196mcp_census_v0_2_1rows in results.v0.2.public.jsonl.gz
26 Sep responders7,282mcp_census_v0_2_1record.protocol_version.era_prober_0.2 (modern + legacy)
endpoints contacted on 26 Sep10,039mcp_census_v0_2_1record.rows_by_observation
endpoints whose observed state is carried from the 25 Sep runs (under 48 h old)11,087mcp_census_v0_2_1record.rows_by_observation
endpoints where two or more surfaces speak to AUTH933cp_v0_1_2_rowsAUTH CONSISTENT + INCONSISTENT
endpoints INCONSISTENT on AUTH5cp_v0_1_2_rowsAUTH INCONSISTENT
endpoints where two or more surfaces speak to PAYMENT116cp_v0_1_2_rowsPAYMENT CONSISTENT + INCONSISTENT
endpoints INCONSISTENT on PAYMENT4cp_v0_1_2_rowsPAYMENT INCONSISTENT
endpoints where two or more surfaces speak to PROTOCOL492cp_v0_1_2_rowsPROTOCOL CONSISTENT + INCONSISTENT
endpoints INCONSISTENT on PROTOCOL33cp_v0_1_2_rowsPROTOCOL INCONSISTENT
endpoints where two or more surfaces speak to TOOLS1,127cp_v0_1_2_rowsTOOLS CONSISTENT + INCONSISTENT
endpoints INCONSISTENT on TOOLS219cp_v0_1_2_rowsTOOLS INCONSISTENT
endpoints where two or more surfaces speak to VERSION5,807cp_v0_1_2_rowsVERSION CONSISTENT + INCONSISTENT
endpoints INCONSISTENT on VERSION2,644cp_v0_1_2_rowsVERSION INCONSISTENT
endpoints with at least one dimension where two public statements disagree2,764cp_v0_1_2_rowsrows with any dimension INCONSISTENT
same count in the superseded v0.1 record2,778cp_v0_1record.endpoints_with_any_inconsistent
same count in the superseded v0.1.1 record2,768cp_v0_1_1record.endpoints_with_any_inconsistent
VERSION contradictions whose live value is 0.1.0382cp_v0_1_2_rowsINCONSISTENT VERSION rows by live.server_version
VERSION contradictions whose live value is 1.0.0514cp_v0_1_2_rowsINCONSISTENT VERSION rows by live.server_version
endpoints inconsistent on tools, auth, protocol or payment256cp_v0_1_2_rowsrows with an INCONSISTENT dimension other than VERSION
VERSION contradictions between the registry server.version and the live serverInfo.version2,632cp_v0_1_2record.version_namespaces.registry_version_vs_live_serverinfo.differ
endpoints in the contract-parity plan, all attempted5,828cp_v0_1_2_rowsrows in rows.v0.1.2.jsonl.gz
endpoints with a surface that did not answer (why the run is PARTIAL)247cp_v0_1_2record.run.read_gaps.endpoints_with_an_unread_surface
of those, VERSION INCONSISTENT243cp_v0_1_2_rowsVERSION state
endpoints whose live version is between 1.24.x and 1.29.x251cp_v0_1_2_rowslive.server_version prefix 1.24.-1.29.
distinct hosts among them14cp_v0_1_2_rowsdistinct host
of those, VERSION INCONSISTENT42cp_v0_1_2_rowsVERSION state
distinct registry versions they contradict9cp_v0_1_2_rowsregistry claims on those rows
endpoints whose live serverInfo.version is 1.27.043cp_v0_1_2_rowsrows with live.server_version == 1.27.0
endpoints inconsistent on VERSION only2,508cp_v0_1_2_rowsrows whose INCONSISTENT set is exactly {VERSION}
distinct remote endpoints the Docker catalogue lists77mcp_census_v0_2_1record.population.frame_sources.docker-mcp-registry.distinct_endpoints
Docker MCP catalogue entries328mcp_census_v0_2_1record.population.frame_sources.docker-mcp-registry.rows_read
agent ids that declare an MCP, A2A or web endpoint13,210erc8004_agents_rowsstate DECLARES_ENDPOINT
agent ids whose file was not fetched (outside the plan, or refused)231,014erc8004_agents_rowsstate NOT_FETCHED
registration files that declare no MCP, A2A or web endpoint187,513erc8004_agents_rowsstate NO_ENDPOINT
agent ids with no registration URI at all52,469erc8004_agents_rowsstate NO_URI
registration URIs that could not be read13,788erc8004_agents_rowsstate URI_UNREACHABLE
distinct declared A2A endpoints contacted4,389erc8004record.declared_endpoint_probes.a2a.n_attempted
declared A2A endpoints with no card at the well-known path3,407erc8004probe-a2a rows NOT_FOUND
declared A2A endpoints that served a card886erc8004probe-a2a rows CARD_SERVED
served cards with a signature5erc8004probe-a2a sig_state
of those, verified4erc8004probe-a2a sig_state VERIFIED
agent ids registered on the ERC-8004 identity registry on three chains505,635erc8004_agents_rowsrows in agents.jsonl.gz
agent ids on base95,776erc8004_agents_rowsrows by chain
agent ids on bsc358,401erc8004_agents_rowsrows by chain
agent ids on ethereum51,458erc8004_agents_rowsrows by chain
declared MCP endpoints that answered but not as MCP1,092erc8004probe-mcp rows NOT_MCP
declared MCP endpoints that answered as MCP580erc8004probe-mcp rows RESPONDED
declared MCP endpoints unreachable393erc8004probe-mcp rows UNREACHABLE
declared MCP endpoints contacted2,113erc8004record.declared_endpoint_probes.mcp.n_attempted
distinct declared MCP endpoints planned for a probe2,144erc8004record.declared_endpoint_probes.mcp.n_planned
agents in the top-20% plan whose registration files were fetched101,127erc8004record.plan.n_plan
Hugging Face Spaces tagged mcp-server (26 Sep frame)10,858mcp_census_v0_2_1record.population.frame_sources.hf-spaces.rows_read
Spaces reported as build error759hf_spaces_rowsrows with state BUILD_ERROR
Spaces reported as paused1,251hf_spaces_rowsrows with state PAUSED
Spaces that answered MCP initialize2,232hf_spaces_rowsrows with state RESPONDED
Spaces reported as runtime error3,059hf_spaces_rowsrows with state RUNTIME_ERROR
Spaces reported as sleeping3,008hf_spaces_rowsrows with state SLEEPING
Spaces that offered only legacy SSE401hf_spaces_rowsrows with state SSE_ENDPOINT_ONLY
Spaces contacted (Hub stage RUNNING)2,658hf_spaces_rowstotal minus not contacted
Spaces not contacted because the Hub reported them not running8,164hf_spaces_rowsrows whose state is a Hub runtime stage
Spaces covered (25 Sep)10,822hf_spaces_rowsrows in data/spaces.jsonl.gz
capsule batches in the index8indexbatches
measurement capsules under the index root13,184indexunion of capsule ids over all batches
reproduced the score only2mill_batch1REPRODUCED_AGGREGATE_ONLY
signed cards re-run on a second runtime (one model)14mill_batch1capsules
item grades that differed14mill_batch1items - grade_equal_items
items compared887mill_batch1sum differential.n_items
reproduced item by item5mill_batch1REPRODUCED_ITEMWISE
did not reproduce7mill_batch1NOT_REPRODUCED
raw outputs that differed60mill_batch1raw_output_differing_item_ids
cards that reproduced the score only9mill_batch2REPRODUCED_AGGREGATE_ONLY
axes in batch 214mill_batch2_parity_summarydistinct axis
signed cards re-run on a second runtime140mill_batch2capsules
item grades equal on both runtimes8,624mill_batch2sum differential.grade_equal_items
item grades equal, per cent97.2mill_batch2grade_equal / items
items compared8,870mill_batch2sum differential.n_items
cards with the same grade on every item49mill_batch2REPRODUCED_ITEMWISE
models in batch 210mill_batch2_parity_summarydistinct model
cards that did not reproduce82mill_batch2NOT_REPRODUCED
raw outputs byte-equal on both runtimes7,404mill_batch2_parity_summarysum raw_eq
model-axis pairs where a same-runtime repeat was not byte-identical20mill_batch2_parity_summaryrepeat_raw_eq not n/n
cards meeting the item-level rule (same counts and same grade on every item)46mill_batch2REPRODUCED_ITEMWISE with declared.counts == observed.counts; equals the dry run
of those, cards with at least 30 graded items, released for quoting37mill_batch2_admissiondry-run rows meeting the rule with n >= 30
registry endpoints under our own names40mcp_census_v0_2_rowsrows with own_estate true
of those, unreachable39mcp_census_v0_2_rowsown_estate rows with state UNREACHABLE
signals from outside15public_signalssummary.by_self_or_external
of those, measured103public_signalssummary.by_state
signals where ours and others' cannot be separated43public_signalssummary.by_self_or_external
signals that are our own activity50public_signalssummary.by_self_or_external
public signals about ourselves recorded daily118public_signalssummary.n_signals
distinct remote endpoints those registry entries list22,151mcp_census_v0_2_1record.population.frame_sources.mcp-registry.distinct_endpoints
official MCP registry entries read (latest versions), read to its end36,134mcp_census_v0_2_1record.population.frame_sources.mcp-registry.rows_read
registry entries in the 25 Sep read35,873mcp_census_v0_2_1record.population.vs_2026-09-25_frame
Smithery's own declared total17,268mcp_census_v0_2_1record.population.frame_sources.smithery.reason ('declared totalCount=17268')
distinct Smithery entries the anonymous API served (PARTIAL)264mcp_census_v0_2_1record.population.frame_sources.smithery.reason ('500 rows served, 264 distinct')
cells CONSISTENT37self_paritystate CONSISTENT
cells INCONSISTENT8self_paritystate INCONSISTENT
cells NOT_DECLARED1self_paritystate NOT_DECLARED
cells NOT_LISTED55self_paritystate NOT_LISTED
cells UNCHECKABLE37self_paritystate UNCHECKABLE
cells: our offerings x the indexes that could list them138self_paritycapsules
directory tool list that differs from what our MCP server serves1self_parityINCONSISTENT tools cells
registry package version that lags the package index1self_parityINCONSISTENT version cells
our x402 listings whose listed URL query string differs from our manifest6self_parityINCONSISTENT x402 cells
hosts that answered HTTP 4021,636x402_snapshot_2026_09_26rows with status 402
resources in one index (read complete)17,548x402_summary_2026_09_26indexes.cdp.resources
hosts fully conformant (402 + header + v2 body + Bazaar block)477x402_snapshot_2026_09_26rows with conformant true
conformant share of hosts, per cent17.58x402_summary_2026_09_26headline.conformant_pct
hosts that sent a PAYMENT-REQUIRED header1,527x402_summary_2026_09_26headline.carried_payment_required_header
hosts that pass on the header but not in the body1,013x402_summary_2026_09_26header_v2_bazaar_not_body
distinct hosts across both public x402 Bazaar indexes2,713x402_snapshot_2026_09_26rows in the snapshot
hosts added26x402_diff_2026_09_26hosts_added
hosts dropped48x402_diff_2026_09_26hosts_dropped
lost conformance4x402_diff_2026_09_26lost_conformance
newly conformant3x402_diff_2026_09_26newly_conformant
resources in the other index (read complete)6,909x402_summary_2026_09_26indexes.payai.resources
conformant the day before470x402_diff_2026_09_26conformant_previous
hosts the day before2,735x402_diff_2026_09_26previous_hosts
hosts unreachable19x402_snapshot_2026_09_26rows with no status
hosts that declared x402Version 2 in the body555x402_summary_2026_09_26headline.x402_version_2
deployments read at evidence level OPERATOR_API52xl_dailydeployments with evidence_kind OPERATOR_API
distinct ledgers at evidence level OPERATOR_API20xl_dailydistinct ledger
deployments read at evidence level STATE_PROOF_RECORDED9xl_dailydeployments with evidence_kind STATE_PROOF_RECORDED
distinct ledgers at evidence level STATE_PROOF_RECORDED6xl_dailydistinct ledger
deployments read at evidence level STATE_PROOF_VERIFIED40xl_dailydeployments with evidence_kind STATE_PROOF_VERIFIED
distinct ledgers at evidence level STATE_PROOF_VERIFIED16xl_dailydistinct ledger
deployments read at evidence level UNCHECKABLE12xl_dailydeployments with evidence_kind UNCHECKABLE
distinct ledgers at evidence level UNCHECKABLE6xl_dailydistinct ledger
selected assets with an issuer list reader wired21xl_dailylen(assets)
issuer-listed deployments read113xl_dailylen(deployments)
deployments an issuer lists as deprecated that still show issued supply3xl_dailyparity.findings_inconsistent kind
contracts on a ledger the issuer does not list, at a listed address, answering with the product symbol1xl_dailyparity.findings_inconsistent kind
tokenised-asset candidates with a positive value in the public value sources280xl_dailyselection.frame_n
top fifth selected to read first56xl_dailyselection.k
assets on private, permissioned ledgers: nothing a third party can read3xl_dailyPERMISSIONED_NOT_READABLE
assets whose issuer publishes a readable deployment list14xl_dailyassets.issuer_list_state READ
assets with no public deployment list1xl_dailyISSUER_LIST_UNAVAILABLE
assets whose list page could not be read3xl_dailyUNCHECKABLE
assets whose issuer claims vs ledgers are CONSISTENT4xl_dailyparity.asset_states
assets whose issuer claims vs ledgers are INCONSISTENT2xl_dailyparity.asset_states
assets whose issuer claims vs ledgers are UNCHECKABLE15xl_dailyparity.asset_states
selected assets not read (no issuer-list reader wired): UNMEASURED41xl_dailylen(unmeasured_selected)
Source records with sha256
SourceRecordsha256Board signature
a2a_v0_1A2A signed agent-card census, record v0.1 (superseded, kept)
census-universes-publish-2026-09-25/a2a/record.json
public copy
b290b53d05912d8b3a5913c7e73e693f40cc71be8e0432c4626643c6d662176cVERIFIES (2026-09-25T08:22:33.567Z)
a2a_v0_1_1A2A signed agent-card census, record v0.1.1 (correction)
cp-fix-20260926/a2a-corr/out/record.v0.1.1.json
public copy
4a2b46bb42aa727363ca04d8a2cc21ed76b50a4c6937a62f80d6fcfda191af91VERIFIES (2026-09-26T04:06:22.149Z)
a2a_v0_1_1_rowsA2A card census v0.1.1 rows, one per registry listing
cp-fix-20260926/a2a-corr/out/data/cards.v0.1.1.jsonl.gz
public copy
93f9865008531a9cb5c44bc8c8d32a1bf1dc775c4e3ec9880128f13c6ab2791cno signature of its own; sha256 given
cp_v0_1MCP contract parity, record v0.1 (superseded, kept)
contract-parity-2026-09-25/record/record.json
public copy
45e3fd63fc98ad251a4f9fe5fdb705ed7fbc28321d5c205d10114a21730cc323VERIFIES (2026-09-25T12:25:41.808Z)
cp_v0_1_1MCP contract parity, record v0.1.1 (superseded, kept)
cp-fix-20260926/record/record.v0.1.1.json
public copy
9cd02be424bf608d41f40522e48188f5a9ef4d13c8de6e28023b20a941fd4ef8VERIFIES (2026-09-26T02:21:40.535Z)
cp_v0_1_2MCP contract parity, record v0.1.2 (correction)
cp-fix-20260926/v012/rec/record.v0.1.2.json
public copy
5a9bedff1b6facbd9e19a1db1282b37fb6cedd9bf6c7dd14aeeeff387eae77edVERIFIES (2026-09-26T07:32:39.698Z)
cp_v0_1_2_rowsMCP contract parity v0.1.2 rows, one per endpoint
cp-fix-20260926/v012/rec/rows.v0.1.2.jsonl.gz
public copy
8fb15bcbb83db1ae6a61945c2f870a16d27adcc751c059439e63d8e910730492no signature of its own; sha256 given
erc8004ERC-8004 agent census, record 26 Sep 2026
stage/erc8004-agent-census/record.json
public copy
60bd9728f22159351feb71ccd6e0c01faab582f0ccf661415e36f339e52d2538VERIFIES (2026-09-26T05:31:49.737Z)
erc8004_agents_rowsERC-8004 agent rows, one per registered agent id
stage/erc8004-agent-census/agents.jsonl.gz
public copy
eafd6b18313df16a139114347f136afc527d7c349f01e7c348a436657e9b6995no signature of its own; sha256 given
hf_spacesHugging Face Spaces tagged mcp-server, record of 25 Sep 2026
census-universes-publish-2026-09-25/hf/record.json
public copy
53022d26ca321b291ca5578b3b318ef645ecf1e4343b13320ebc91642abb906eVERIFIES (2026-09-25T08:22:30.245Z)
hf_spaces_rowsHugging Face Spaces rows, one per Space
census-universes-publish-2026-09-25/hf/data/spaces.jsonl.gz
public copy
7b9bb0d630444a41f5757499f14e096e0fb37431c69aed6ebbc2aa0ba415088cno signature of its own; sha256 given
indexMeasurement-capsule index v0.2 (26 Sep 2026): one signed root over every capsule batch
measurement-index-v0.2-2026-09-26.json
ee3d921750d40456eb58ed24d2a9ba141d6fc1d16510ddd338166c4f5620b72aVERIFIES (2026-09-26T10:34:15.836Z)
mcp_census_v0_2_1Remote MCP endpoint census, record v0.2.1 (corrected label; counts identical to v0.2)
census-v0.2-2026-09-26/pub/record.v0.2.1.json
public copy
3155502aa629a3e0e8dd0240862933e475cc2afaf3417d03c0efa314d139c4bdVERIFIES (2026-09-26T07:33:47.357Z)
mcp_census_v0_2_rowsRemote MCP endpoint census v0.2 rows, one per endpoint
census-v0.2-2026-09-26/pub/results.v0.2.public.jsonl.gz
public copy
a9b644a17e116c1c6f12c4ecacbb013bab62b3d04f5e84f4715578406984fc70no signature of its own; sha256 given
mcp_census_v0_2_supersededRemote MCP endpoint census, record v0.2 (superseded, kept)
census-v0.2-2026-09-26/pub/record.v0.2.json
public copy
a18447e5bb27decbc7d20c1542994811f47dee94b4650faed7b231af5c5d72bdVERIFIES (2026-09-26T07:04:34.530Z)
mill_batch1Cross-runtime reproduction, batch 1 (one model, 14 cards)
measurement-capsules-v0.2-2026-09-26-mill_cross_runtime/record.json
32ece857c94062f41a03aad9e269532cdbe5dc0a576ed20110edc4ecacb0468dVERIFIES (2026-09-26T06:20:12.622Z)
mill_batch2Cross-runtime reproduction, batch 2 (10 models x 14 axes)
measurement-capsules-v0.2-2026-09-26-mill_cross_runtime-batch2/record.json
422fa6377b274bab095e8e875f67d087a275417c14c90a4c4e4cedb56ca9a5ffVERIFIES (2026-09-26T10:33:45.092Z)
mill_batch2_admissionCross-runtime batch 2, item-level rule dry run
mill-kaggle-batch2-2026-09-26/admission-dryrun.txt.gz
20a0210e39d54dcbaa4067c0f7a8c5241a915df78ed7edbae6d53c03820f2ccfno signature of its own; sha256 given
mill_batch2_parity_summaryCross-runtime batch 2, per-card item comparison
mill-kaggle-batch2-2026-09-26/parity-summary.json
a3bd67a4fd119a4c5f0ec2190c2dde0aff1064bcdeb25c0d4961e541055d4e59no signature of its own; sha256 given
public_signalsPublic signals about ourselves, 26 Sep 2026
public-signals/2026-09-26/record.json
7c23af1cea95c58d99a2eff2928c5637f38057d238d1b44e49fb8832460f81b0VERIFIES (2026-09-26T08:31:57.056Z)
self_paritySelf-parity: how external indexes list our own offerings, 26 Sep 2026
self-parity/2026-09-26/record.json
a2f205ca43d096ec0e9f621d8e0dcda2bd2d8040b39ff277ef7ae50fa9de4dfeVERIFIES (2026-09-26T05:46:23.225Z)
tool_driftTool-list drift between two observations (capsule batch)
measurement-capsules-v0.2-2026-09-26-tool_drift/record.json
a7a13dab161631d0557726fd64c0dee82bd0b95cb54e2749d96aaddc93fef473VERIFIES (2026-09-26T06:53:20.454Z)
x402_diff_2026_09_26x402 day-on-day diff 25 to 26 Sep 2026
flywheel/x402/diff-2026-09-26.json
ff101ce3705cf1ee1ae3284f572cec4d7e9cc92889b6c68a9a0aa2aa7a35cbd9no signature of its own; sha256 given
x402_release_2026_09_25x402 Bazaar conformance, daily release 25 Sep 2026
flywheel/x402/release-2026-09-25.json
0d84f400f17a0d771e557d51a5a2edd0674d05c617e23f73d4d5c87db1bae1f4VERIFIES (2026-09-25T11:32:26.082Z)
x402_release_2026_09_26x402 Bazaar conformance, daily release 26 Sep 2026
flywheel/x402/release-2026-09-26.json
public copy
4e7635ae398be274371ee48a81f7cb1def46c13ef01742e830bbea93b8c13a0bVERIFIES (2026-09-26T01:11:11.344Z)
x402_snapshot_2026_09_26x402 Bazaar conformance snapshot, one row per host
flywheel/x402/snapshots/conformance-2026-09-26.jsonl
public copy
5faccd86a679f1407da1926e11fba5e98f9e1367f494f56b48f3978369f92853no signature of its own; sha256 given
x402_summary_2026_09_26x402 Bazaar conformance summary 26 Sep 2026
flywheel/x402/summary-2026-09-26.json
public copy
4705777f34e72bf935b19398dca486ad252212531ede84d963086087f6d2e3cdno signature of its own; sha256 given
xl_dailyCross-ledger daily read of tokenised assets, 26 Sep 2026
xl-daily/2026-09-26/xl-daily-2026-09-26.json
public copy
b02851fcbc8ea5ad6460c6c847e8af9eaec74d36a09121989590dc180a5d700dVERIFIES (2026-09-26T06:44:44.913Z)