Docs · Anchor Manifest v0.1 · draft

Anchor Manifest specification

There are good formats for describing a server, an API and an agent already. What's missing is one place per publisher that says which of those exist, how to reach each one, what it costs, which variant is safe to hand an agent, and whether anyone still maintains it. The manifest is that place. It's small on purpose and it links out instead of duplicating.

Design goals

  1. Use existing protocols first. The manifest points at an MCP registry server.json, an OpenAPI document, an A2A agent card, an llms.txt and x402 discovery data. It doesn't restate any of them.
  2. Add only what agents keep needing and nobody publishes. Read-only variants, per-call payment terms, status and changelog links, and a way to verify who published the file.
  3. Be readable by a model with no prior knowledge, and small enough to fetch on every crawl.
  4. Be optional. Tools without a manifest are still listed and scored. A manifest makes their facts more accurate and refreshes them faster.

Location and discovery

Serve the document at https://<publisher-domain>/.well-known/anchor.json with Content-Type: application/json and CORS enabled. Optionally advertise it with Link: </.well-known/anchor.json>; rel="anchor-manifest" on responses from the tool's own endpoints, and list it in llms.txt.

Document

{
  "anchor": "0.1",
  "publisher": {
    "name": "Example Search",
    "url": "https://example.com",
    "contact": "agents@example.com",
    "docs": "https://example.com/docs",
    "llmsTxt": "https://example.com/llms.txt"
  },
  "tools": [
    {
      "id": "com.example/search",
      "kind": "mcp",
      "name": "Example Search MCP",
      "description": "Web search and page fetch for agents.",
      "endpoint": "https://mcp.example.com/mcp",
      "transport": "streamable-http",
      "auth": ["none", "oauth2", "api-key"],
      "readOnlyVariant": "https://mcp.example.com/mcp/readonly",
      "scopedVariants": { "search-only": "https://mcp.example.com/mcp/search" },
      "payments": [
        { "protocol": "x402", "version": 2, "networks": ["eip155:8453", "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"], "asset": "USDC", "priceUsd": 0.005, "unit": "call", "discovery": "https://api.cdp.coinbase.com/platform/v2/x402/discovery/search?payTo=0x..." }
      ],
      "pricing": "https://example.com/pricing",
      "freeTier": { "cardRequired": false, "limit": "1000 calls/month" },
      "schemas": {
        "mcpServerJson": "https://registry.modelcontextprotocol.io/v0.1/servers/com.example%2Fsearch",
        "openapi": "https://api.example.com/openapi.json",
        "a2aAgentCard": null
      },
      "status": "https://status.example.com",
      "changelog": "https://example.com/changelog",
      "deprecations": [
        { "what": "/sse endpoint", "sunset": "2026-12-31", "replacement": "https://mcp.example.com/mcp" }
      ],
      "telemetry": { "collected": true, "optOut": "EXAMPLE_TELEMETRY=0", "policy": "https://example.com/privacy" },
      "security": "https://example.com/.well-known/security.txt",
      "source": "https://github.com/example/search-mcp",
      "license": "MIT"
    }
  ],
  "verify": {
    "dnsTxt": "_anchor.example.com",
    "http": "https://example.com/.well-known/anchor.json"
  },
  "updated": "2026-09-25"
}

Fields

Top level

FieldRequiredTypeNotes
anchoryesstringSpecification version, "0.1"
publisheryesobjectname, url required. contact, docs, llmsTxt recommended
toolsyesarrayOne entry per tool. May be empty for a publisher that only wants to be verified
verifynoobjectHow the claim is verified, see below
updatedyesdateISO date the document last changed

Tool entry

FieldRequiredTypeNotes
idyesstringReverse-DNS identifier, the same form the MCP registry uses (com.example/search). Use the registry name if the tool is registered.
kindyesmcp · http · openapi · a2a · sdkWhat kind of thing the endpoint is
name, descriptionyesstringShort. A model reads them
endpointyes for hostedURLThe primary hosted endpoint. Local-only tools use packages instead
packagesnoarray of {registry, name}npm, pypi, oci, nuget
transportyes for mcpstreamable-http · stdio · sseDeclare sse only while it still works. List it under deprecations when retiring
authyesarrayAny of none, oauth2, api-key, pat, httpsig, x402. Order by preference.
readOnlyVariantnoURLAn endpoint or mode that exposes no write tools. Strongly recommended, and scored.
scopedVariantsnomapNamed narrower endpoints
payments[]noarrayprotocol (x402, mpp, l402, card), version, networks (CAIP-2), asset, priceUsd, unit (call, token, page, minute), optional discovery URL
pricingnoURLHuman pricing page readable without a login
freeTiernoobjectcardRequired boolean and a limit string
schemasnoobjectmcpServerJson, openapi, a2aAgentCard, jsonSchema URLs
status, changelogrecommendedURLScored under transparency
deprecations[]noarraywhat, sunset (date), replacement
telemetryrecommendedobjectcollected boolean, optOut instruction, policy URL
securitynoURLUsually the publisher's security.txt
source, licensenoURL, SPDX id

Verification

A manifest is trusted for a listing when one of these holds.

  • DNS. A TXT record at _anchor.<publisher-domain> contains anchor-verify=<token>, where the token is issued when claiming the listing.
  • HTTP. The manifest is served from /.well-known/anchor.json on the same registrable domain as the tool's endpoint, and the endpoint responds. Same origin is the proof.
  • Registry. The id is a verified namespace in the official MCP registry and the registry's server.json lists the same endpoint.

A manifest that fails verification is ignored, not penalised. The crawler falls back to what it can observe.

How Anchor Terminal uses it

On every crawl the manifest is fetched, verified and diffed. Changed endpoints, prices, deprecations and variants update the listing's facts the same day. Declared deprecations with sunset dates count as graceful, never as negative events. A declared readOnlyVariant gets probed. If it exposes write tools, the declaration is marked false on the tool's page. Declared payments get probed with the same unpaid-request and canary-settlement method as any other x402 endpoint.

Relationship to other formats

FormatWhat it describesHow the manifest relates
MCP registry server.jsonPackages and remotes of one server, with a verified namespaceLinked via schemas.mcpServerJson. The manifest reuses its id
OpenAPIOperations of an HTTP APILinked via schemas.openapi. RFC 9727 /.well-known/api-catalog stays the standard way to list OpenAPI documents
A2A agent cardSkills and interfaces of an agentLinked via schemas.a2aAgentCard. The card stays at /.well-known/agent-card.json
llms.txtSite index for LLMsLinked from publisher.llmsTxt. The manifest should be listed in it
x402 Bazaar / /.well-known/x402Payable resources and pricesLinked via payments[].discovery. Prices in the live 402 win
MCP server cards (/.well-known/mcp/server-cards.json, proposed)Capabilities of MCP servers on a hostIf adopted, the manifest will link to it. Until then the manifest carries the minimum needed

Status

Draft v0.1. Fields get added, not removed, before v1. Anchor Terminal publishes its own manifest at /.well-known/anchor.json.

Nobody outside this site publishes one yet, so the field list is our guess at what agents need rather than something worn in by use. The payments shape is the part I'd expect to change first, because MPP and L402 don't map cleanly onto priceUsd per unit. Feedback to agents@anchorterminal.com.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.