.well-known generator
Starter files for the places agents and security researchers look on your domain: an Agent Card, security.txt and llms.txt.
By Emissar. Updated .
agent-card.json
Serve it as application/json, with Cache-Control and an ETag. Then check it with the Agent Card validator.
security.txt
Serve it over https as text/plain; charset=utf-8. Canonical is set from your site address. Put a reminder in your calendar to update it before it expires.
llms.txt
Serve it at the root of your site, /llms.txt, as plain text. The title is your organization or site name.
Secondary links an agent can skip when it's short on context.
How it works
- agent-card.json uses the same builder as the Agent Card generator, so a card with nothing flagged has no failures in the validator. Your organization and site address become the card's provider.
- security.txt writes the two required fields, Contact and Expires, plus Preferred-Languages and Canonical. A web contact must be an https URL; an email address is written as a
mailto:URI, as RFC 9116 requires. Expires is written in RFC 3339 form at midnight UTC. - llms.txt follows the llmstxt.org layout in order: an H1 title, a blockquote summary, optional detail, then H2 sections of links, with Optional last.
Limitations
- These are starting points. The Agent Card has one skill and no security schemes; security.txt has no Encryption, Policy or Acknowledgments fields and isn't signed; llms.txt lists only the links you add.
- Nothing here checks that the URLs you enter exist or that your server sends the right headers. The Agent Card validator checks a published card, headers included.
- llms.txt is a proposal. Publishing one doesn't guarantee any AI product reads it.
Privacy
This page runs in your browser; nothing is sent. What you type isn't stored, not even in your browser, so it's gone when you leave the page. As with any page on this site, Cloudflare processes your IP address to deliver and protect it. Details are in the trust center and the privacy policy.
Related
- Agent Cards explained: fields, discovery, and caching
- Publish your first Agent Card
- Build an A2A server on Cloudflare Workers
- Agent Card generator: a full v1.0 card with several interfaces and skills
- Agent Card validator: check a published card
Sources
- A2A Protocol Specification, version 1.0.0, section 8.2: Discovery
- a2a.proto, the normative A2A data model
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure
- RFC 8615: Well-Known Uniform Resource Identifiers
- RFC 3339: Date and Time on the Internet
- RFC 5646: Tags for Identifying Languages
- The /llms.txt file (llmstxt.org proposal)