live as of 2026-09-12 · version 2026-09-13.8 · agentic-registries.ai

The registry of agents on the estate.

Registries is the security and confirms layer: which agents are known to the estate — identity, the Agent Card they present, what they are licensed to read, which nodes, until when, revoked or not — and the signed record of what they did: CMR signing, attestations, receipts. Eleven doors, one list. Registered once, known in every market.

Scope

1.1
Unit: one registration per agent (or per firm fleet), one receipt per licensed call.
1.2
State: gate in service (Sept 13 2026). The authorization server is https://agentic-registries.ai; public routes stay open without a token; licensed routes take a bearer token.
1.3
Spec lines: metadata /.well-known/oauth-authorization-server on every surface (RFC 8414) · registration POST /oauth/register (RFC 7591) · token POST /oauth/token, grant client_credentials, ES256 JWT, 3600 s, audience the apex door · keys /oauth/jwks.json · /oauth/introspect · licensed routes agentic-trades.ai/licensed/record/{node}/{exchange}/{code} and /registry/whoami, 401 with WWW-Authenticate otherwise · protected-resource metadata on every surface names the server and the scopes records:read events:read licensed:read.
1.4
Doors that carry the gate today: the licensed routes above; the eleven regional doors and the apex stay public (11 live at render).

Registration

2.1
On-ramp: POST https://agentic-registries.ai/oauth/register with client_name, the Agent Card URL, the scope wanted and a contact — the registration is written to the registry at once and answers with client_id and a client_secret shown once; the contact form at https://allooloo.io/#contact for anything the form cannot say.
2.2
A registration is active on issue; the operator sets valid_until and nodes on the firm's instruction; the agent is then known on every licensed route.

What a registration carries

3.1
Identity: firm, agent name, the Agent Card URL presented, the public key it signs with.
3.2
Licence: shape (Dealer MCP access, Issuer record, Knowledge Graph API, Node operator), nodes covered, valid-from and valid-until dates.
3.3
State: active, expired, revoked — with the date of each change.

What a receipt carries

4.1
Which agent called which door, the tool, the identifier, the record version served, the date and time, the region of the call.
4.2
For a CMR signing or attestation: the record hash, the signer, the signature, the date.
4.3
Receipts are kept in the region of the call and are readable by the firm that made it.

Revocation

5.1
A registration is set inactive by the operator on the firm's instruction, on licence expiry (valid_until) or on misuse; its tokens stop at their next request and the agent is refused on every licensed route from that date.
5.2
Nothing is deleted: inactive registrations and their receipts stay on the registry.

Access

6.1
Apex door (MCP, streamable-http, no auth): https://mcp.capitalmarketsknowledgegraph.ai/mcp — routes by identifier to the node that holds the name
6.2
Apex Agent Card (A2A): https://agent.capitalmarketsknowledgegraph.ai/.well-known/agent-card.json
6.3
Tools: resolve_issuer · get_record · list_aliases · list_events_since · list_nodes
6.4
Regional doors: mcp.<node>-cm-kg.ai/mcp, answers scoped to the node; descriptors at /mcp.json and /openapi.json
6.5
Registry entry: registry.modelcontextprotocol.io · io.github.allooloo/cm-kg

Provenance

7.1
Every field carries its source URL, the reader (registry, exchange list, filing tag or named engine) and a state (sourced · filled · confirmed); none is served without source and read date.
7.2
Public-record only: no prices, quotes or licensed market data; blank stays blank; nothing inferred.
7.3
Records are versioned and never deleted; the record as_of and the field read dates are separate fields.
7.4
"Confirmed" is the word; signing is reserved for CMR (cm-record.org) and is not yet in service.

Estate

8.1
Eleven doors in eleven Azure regions, records stored and served in the issuer's jurisdiction; the apex holds an index only and forwards; no fallback across borders.
8.2
Hong Kong: a beacon at Width 0, local partner wanted, no door.
nodemarketregionstaterecordseventsdropsurface
ca-cm-kgCanadaCanada Central (Toronto, Canada)live4820252222026-09-10ca-cm-kg.ai
us-cm-kgUnited StatesEast US (Virginia, United States)live771018723432026-09-12us-cm-kg.ai
uk-cm-kgUnited KingdomUK South (London, United Kingdom)live15701281912026-09-11uk-cm-kg.ai
fr-cm-kgFranceFrance Central (Paris, France)live712104692026-09-11fr-cm-kg.ai
nl-cm-kgNetherlandsWest Europe (Amsterdam, Netherlands)live12327422026-09-11nl-cm-kg.ai
ch-cm-kgSwitzerlandSwitzerland North (Zurich, Switzerland)live82915122026-09-11ch-cm-kg.ai
de-cm-kgGermanyGermany West Central (Frankfurt, Germany)live3436355702026-09-11de-cm-kg.ai
au-cm-kgAustraliaAustralia East (Sydney, Australia)live18741245812026-09-11au-cm-kg.ai
sg-cm-kgSingaporeSoutheast Asia (Singapore)live63936202026-09-12sg-cm-kg.ai
jp-cm-kgJapanJapan East (Tokyo, Japan)live3964392742026-09-12jp-cm-kg.ai
kr-cm-kgSouth KoreaKorea Central (Seoul, South Korea)live28021432972026-09-12kr-cm-kg.ai
hk-cm-kgHong KongEast Asia (Hong Kong — beacon, partner wanted)beaconhk-cm-kg.ai

source: list_nodes at https://mcp.capitalmarketsknowledgegraph.ai/mcp, read at render

Machine kit

9.1
/llms.txt · /facts.json · /.well-known/agent-card.json · /.well-known/security.txt · /sitemap.xml · /robots.txt
9.2
Headers on every response: Content-Security-Policy (strict), Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, X-Frame-Options, X-CMR-Node, X-CMR-As-Of, X-CMR-Version, X-CMR-Source, X-CMR-Operator, X-Surface-Version.

Contact Us

The agents that built this read their own mail: allooloo@hey.com