Hosted KYA certificate
A signed public record for one operator and one reviewed agent, MCP server, endpoint, package, repository, or agent card.
KYA for Agents and MCP
Xupra KYA gives agents and MCP servers a hosted certificate, public verification API, live MCP trust handshake, wallet binding, registry listing, and optional blockchain proof.
The official MCP Registry makes MCP servers discoverable. KYA adds the commercial trust layer: who operates the system, what endpoint is certified, which key and wallet are bound, and whether another agent should trust it before calling or paying it.
Xupra does not force one payment rail. Stripe, x402, crypto, invoice, direct contracts, and future Xupra payment services can all sit behind the same KYA verification model.
Hosted certificate
https://xupracorp.com/kya-registry/sample-certificate
What we offer
KYA sits above discovery. It makes counterparties easier to inspect before a tool call, data exchange, wallet-signing request, or payment-related workflow.
A signed public record for one operator and one reviewed agent, MCP server, endpoint, package, repository, or agent card.
Xupra records who operates the asset, what endpoint or manifest belongs to it, which public key is certified, and which wallet can be associated with it.
A live verification path lets a verifier prepare a nonce challenge and confirm that the remote system still controls the certified operational key.
The public chain receives hashes and timestamps, not private customer evidence. It is the tamper-evidence layer for certificates and later ledger roots.
Approved assets can be published to the Xupra KYA Registry with certificate, API, endpoint, and metadata links for counterparties.
When a seller wants it, Xupra can record hashed commercial references as internal KYA evidence without storing private payment data.
Agent vs MCP
The distinction matters because agent-to-agent transactions need both sides: the endpoint being called and the actor deciding to trust it.
The server or endpoint exposes tools, resources, prompts, and context. It is what another application or agent connects to.
The actor deciding what to do. It may call an MCP server, delegate work, request data, trigger payment, or verify another agent before using it.
The trust layer between them. KYA binds the operator, MCP endpoint, agent identity, public key, wallet reference, policy, and certificate status.
How the system works
KYA combines hosted certificate lookup, policy evaluation, optional live challenge-response, and evidence records. The certificate tells another agent what was reviewed. The MCP handshake proves the live peer still controls the certified key.
01
Xupra starts from a public MCP registry entry, remote endpoint, agent card, package, repository, or company website.
02
Xupra can connect from our side to the company's MCP endpoint to record reachability, response headers, latency, and available public tool metadata where allowed.
03
After agreement and payment, Xupra runs the review, records evidence privately, signs the hosted certificate, and publishes the public verification record.
04
A buyer agent fetches the certificate, checks policy, validates status and signature, then uses MCP challenge-response for stronger live proof.
Trust infrastructure
Customer evidence, surveys, private review notes, and payment references stay off-chain. The chain is used for public proof that a certificate or ledger root existed at a point in time.
Signs the canonical certificate payload with a controlled Xupra issuer key.
Stores signed certificate artifacts and publication manifests outside the public UI.
Serves active status, certificate JSON, issuer metadata, badge, and MCP handshake tools.
Records hashes for public tamper evidence once the certificate is anchored.
Verification endpoints
The sample certificate shows the public fields. Live certificates expose the same shape through a hosted page and machine-readable API.
https://xupracorp.com/kya-registry/sample-certificate
https://xupracorp.com/.well-known/kya-registry.json
https://xupracorp.com/api/kya-registry/v1/mcp
kya_prepare_handshake / kya_verify_handshake / kya_evaluate_policy