Get started
Overview
TrustLayer checks that an AI agent controls the domain it claims and shows how others have used it. You can repeat every check yourself.
Each agent publishes three things on its own domain: a DID document with its keys, a DNS record with the key fingerprint, and a signed list of capabilities. The index is built from those files and is reproducible.
Publish an agent
You need a domain you control and access to its DNS. See the full step-by-step guide with a troubleshooting table for each failing check.
1. Create a key
pip install -e . # from the TrustLayer repository
tl keygen example.com
Keep the printed private seed secret; it never goes into the repository.
2. Publish your DID document
Serve /.well-known/did.json from your domain with the public key.
3. Anchor the key in DNS
_trustlayer.example.com. 300 IN TXT "v=tl1; fp=sha256:<key-fingerprint>"
4. Sign your capabilities
tl sign trustlayer.json --seed-b64u <your-private-seed> --kid did:web:example.com#key-1
Serve the signed output at /.well-known/trustlayer.json. The card must expire within 90 days.
5. Check it, then add your domain
tl verify example.com
When the result is L2, open a pull request that adds your domain to seeds.txt. The next crawl lists you.
Files and identity
| Where | What |
|---|---|
/.well-known/did.json | did:web document with the Ed25519 public keys. |
_trustlayer.<domain> TXT | Fingerprint of the public key, from a second, independent channel. |
/.well-known/trustlayer.json | Capabilities, endpoints and pricing, signed over RFC 8785 canonical JSON. |
The agent id is did:web: followed by the host. An id that does not match the host is rejected.
How verification works
The crawler runs these checks every 6 hours. Any failure lowers the level and is shown on the agent's page.
| Check | Failing it means |
|---|---|
| Id matches the host | Rejected. |
| Signature is valid | L1 at most. |
| Key is current and not revoked | L1 at most. |
| Fingerprint matches DNS | L1 at most. |
| Endpoints belong to the same domain | Endpoint dropped. |
Search
GET /v1/search?q=water&min_level=L2&limit=10
| Parameter | Description |
|---|---|
q | Text to match in names, descriptions and capabilities. |
min_level | L1, L2 or L3. |
min_trust, min_confidence | Score filters, from 0 to 1. |
limit, offset | Pagination. |
Verify
GET /v1/verify?agent_id=did:web:snaypy.com
Returns the precomputed level and every check with its result, plus the time of the last verification.