.well-known generator

Starter files for the places agents and security researchers look on your domain: an Agent Card, security.txt and llms.txt.

By Emissar. Updated .

Your site

Used by all three files. Everything runs in your browser; nothing you type is sent or stored.

/.well-known/agent-card.json

A minimal A2A v1.0 Agent Card with one skill and the Agent Card generator's defaults: JSON-RPC, protocol 1.0, text in and out, no optional capabilities. Use the generator for more interfaces, skills or capabilities.

agent-card.json

    Serve it as application/json, with Cache-Control and an ETag. Then check it with the Agent Card validator.

    /.well-known/security.txt

    How security researchers reach you, in the RFC 9116 format.

    Contact method

    Anyone can read this file, so use an address you're happy to publish.

    Required. The default is just under a year away; RFC 9116 recommends less than a year.

    Language tags, separated by commas, for example en, fr.

    security.txt

      Serve it over https as text/plain; charset=utf-8. Canonical is set from your site address. Put a reminder in your calendar to update it before it expires.

      /llms.txt

      A Markdown map of your site for language models. It is a community proposal from llmstxt.org, not a standard, and AI tools differ in whether they read it.

      llms.txt

        Serve it at the root of your site, /llms.txt, as plain text. The title is your organization or site name.

        How it works

        • agent-card.json uses the same builder as the Agent Card generator, so a card with nothing flagged has no failures in the validator. Your organization and site address become the card's provider.
        • security.txt writes the two required fields, Contact and Expires, plus Preferred-Languages and Canonical. A web contact must be an https URL; an email address is written as a mailto: URI, as RFC 9116 requires. Expires is written in RFC 3339 form at midnight UTC.
        • llms.txt follows the llmstxt.org layout in order: an H1 title, a blockquote summary, optional detail, then H2 sections of links, with Optional last.

        Limitations

        • These are starting points. The Agent Card has one skill and no security schemes; security.txt has no Encryption, Policy or Acknowledgments fields and isn't signed; llms.txt lists only the links you add.
        • Nothing here checks that the URLs you enter exist or that your server sends the right headers. The Agent Card validator checks a published card, headers included.
        • llms.txt is a proposal. Publishing one doesn't guarantee any AI product reads it.

        Privacy

        This page runs in your browser; nothing is sent. What you type isn't stored, not even in your browser, so it's gone when you leave the page. As with any page on this site, Cloudflare processes your IP address to deliver and protect it. Details are in the trust center and the privacy policy.

        Related

        Sources