Brand Design Ltd.
AI agents discover and order Brand Design services, including the 101Ts3t real-payment test.
- 1.0.1
- Version
- remote
- Transport
- 10
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 10 tools scanned
- metadata: scanned
No findings.
Tools (10)
catalog
Read the service catalogue: names, prices, currency and terms. No credentials needed. All amounts are integers in the minor unit; 100000 means 1000.00 EUR.
manifest
Read the commerce manifest: protocol, endpoints, authentication scheme, payment instrument and limits. No credentials needed.
register_agent
Register yourself and receive a client identifier and a secret. No approval and no prior arrangement. The secret is returned once and cannot be recovered. Put them in the Authorization header as "Bearer <clientId>:<secret>" for the other tools.
kya_challenge
Issue a fresh DNS TXT challenge for your currently authenticated agent identity. Needs commerce.order for OAuth. Supply an HTTPS contact URL on a domain you control, especially on the first OAuth connection. Omitting contact reuses the current contact. This replaces the previous challenge and clears its verification. Publish the returned txtValue at dnsName, then call kya_verify. Domain control does not establish buyer identity or grant spending authority. Do not publish secrets in DNS.
kya_verify
Check the DNS TXT challenge for your currently authenticated agent and record domain-control verification. Needs commerce.order for OAuth. First call kya_challenge and publish its exact DNS TXT record. The response gives verifiedAt and validUntil; verification is currently valid for 24 hours. This does not authorize a purchase or a payment.
kya_status
Read DNS domain-control verification for your currently authenticated agent. Needs commerce.read for OAuth. Returns verification status and, when present, DNS instructions and validity timestamps. This does not change the contact, challenge or verification.
create_order
Place an order for a service. Needs credentials. Returns the order id, the offer and an accessToken you must keep for the following calls. The offer is pinned to the hash of the service page; accept_offer needs offer.version and offer.terms.<language>.hash from it. Services without a catalogue price return an offer with no total and wait for a person to price it. Errors: MISSING_<field> when a required brief field is absent, UNEXPECTED_FIELD when the brief has a key the service does not declare.
accept_offer
Accept the offer on behalf of the buyer. Needs credentials. This locks the billing identity, the offer version and the hash of the terms as they stand at this moment. A later change to the website cannot pass for what was agreed. Errors: OFFER_CHANGED (409) if the offer or the terms changed since you read them; read order_status and use the new values. OFFER_EXPIRED (409) 30 days after the order. MANUAL_OFFER_REQUIRED (409) while a person has not priced the service yet.
start_payment
Start payment for a stage. Needs credentials. Without sharedPaymentToken you receive a hosted payment session, which you may complete yourself with a payment instrument issued to you, or hand to the person you act for. With a delegated shared payment token the payment settles directly. A self-registered agent must first have current DNS domain-control KYA for its HTTPS contact domain: call kya_challenge with a domain you control, publish its DNS TXT record and call kya_verify; kya_status reads the current verification. KYA does not grant buyer payment authority. On-chain payment is not accepted. Errors: OFFER_EXPIRED (409) for an advance after 30 days, FINAL_NOT_RELEASED (409) when the final payment is not open yet, PAYMENTS_DISABLED (503).
order_status
Read the current state of the order, its offer and its payments, including the invoice number once one has been issued. Needs credentials.