| PASS | ANS lifecycle is ACTIVE (live) | registry reports ACTIVE |
| PASS | Canonical agent host | registry agentHost and ANS name match the requested host |
| PASS | Supports A2A or MCP | A2A, MCP |
| PASS | Endpoints are HTTPS with valid TLS | hostname and chain verified against the public WebPKI |
| PASS | Endpoints are on the registered host | every endpoint/metadata URL is on the registered agentHost |
| PASS | Endpoints pass outbound network policy | https/443, public DNS name, every resolved address globally routable |
| PASS | Registry detail and transparency log agree | search hit, agent detail and transparency-log badge are consistent |
| PASS | Identity certificate retrieved from ANS (optional) | retrieved from the official certificate-management API |
| PASS | Identity certificate validity and binding (optional) | validity window, host and ANS name binding verified; fingerprint matches the transparency-log attestation |
| PASS | Identity certificate chains to the ANS trust anchor (optional) | chain verifies to the provisioned ANS trust anchor |
| PASS | Protocol metadata fetched within limits | fetched with time/size/content-type limits |
| PASS | Metadata parses and matches the registration | parsed as data; interface matches the registration |
| PASS | Metadata signature / hash (optional) | card is signed by the key in the ANS-issued identity certificate |
| PASS | Agent Card hash is stable (drift watch) | matches the last verified hash |
| PASS | Not on the local blocklist | no local block |