Last week we published the Certified Agent Standard v0.1 - five requirements for accountable AI agents - and then did something uncomfortable: we ran our own agents against it and published the failures. Two of three failed the first round. We fixed what the probes exposed, re-ran them, and today three certificates are live on our public registry, each backed by live behavioral probes, not paperwork.

Now we want to certify agents we don't control.

The gap this fills: the x402 ecosystem has gotten serious about endpoint trust. Probe services score whether your API answers, how fast, and whether the price is honest. That's necessary and good. But it answers only half the trust question. An endpoint badge tells a buyer your service responds. It says nothing about how the agent behind it is operated: whether it has a declared scope, whether its actions leave a tamper-evident trail, whether there's a human accountable for it, whether it fails safely.

That's what the Certified Agent Standard covers. Five requirements: declared scope, mechanical guardrails, tamper-evident audit trail, named accountable operator, and verified fail-safe behavior. Certification is probe-based - we test the agent's actual behavior against its declared scope, and the certificate is revocable if a re-probe fails.