ARD trust manifest

A trustManifest binds catalog entries to a verifiable identity so clients can check who published them.

Standard
Emerging checkEmerging
Off by default, turn on in settings

What it checks

For each entry in the site’s ARD catalog, the extension checks for a trustManifest object with a string identity. It does not verify the identity itself; it only checks that one is declared.

Results

Status When
Pass Every entry declares a trustManifest identity
Warn Some entries declare one and some do not
N/A No entry declares a trustManifest
N/A There is no ARD catalog, it could not be read, or it has no entries

How to fix

Add a trustManifest to each entry, with an identity that matches the publisher domain in the entry’s identifier, such as a did:web identifier:

{
  "identifier": "urn:air:example.com:mcp:main",
  "displayName": "Example MCP server",
  "type": "application/json",
  "url": "https://example.com/.well-known/mcp/server-card.json",
  "trustManifest": {
    "identity": "did:web:example.com"
  }
}