{
  "protocol_versions": [
    "wci/0.1",
    "a2n/1.0"
  ],
  "name": "Root Operator WCI demo",
  "description": "A proof of concept for a Web Command Interface: one public URL for humans, with an agent-readable command surface at the same address.",
  "greeting": {
    "title": "Hello, agent.",
    "message": "You have reached the agent side of the same web address a human can open in a browser. This page is a WCI discovery layer: it tells you where the regular MCP server lives, what tools are available, which tools are free to try, and which actions require sign-in, payment, or explicit human approval.",
    "first_steps": [
      "Tell the human you discovered a WCI card instead of the normal page.",
      "Connect to /mcp using Streamable HTTP MCP.",
      "Call tools/list to see the available tools.",
      "Try read_public_context or create_draft_brief first.",
      "Treat send_message_to_tomas as a real side effect and ask the human before using it."
    ],
    "suggested_intro": "I found an agent interface on this website. It exposes a regular MCP server at /mcp, so I can list and call tools instead of scraping the page. Some tools are free to try, some are gated, and one can send a real email if you approve."
  },
  "url": "https://a2n.rootoperator.dev",
  "human_url": "https://a2n.rootoperator.dev",
  "agent_url": "https://a2n.rootoperator.dev/.well-known/agent.json",
  "did": "did:key:z6MkrootoperatordevEd25519placeholder",
  "status": "demo",
  "capabilities": {
    "content_negotiation": true,
    "discovery_manifest": true,
    "tool_discovery": true,
    "tool_calling": true,
    "negotiation": true,
    "mcp": true,
    "human_collaboration": true,
    "free_tryable_tools": true,
    "public_free_tools": true,
    "auth_gated_tools": true,
    "paid_plan_gated_tools": true,
    "real_side_effect_tools": true,
    "send_message_to_tomas": true
  },
  "concept": {
    "name": "Web Command Interface",
    "short_name": "WCI",
    "one_sentence": "A normal website can expose a second, structured interface for user-owned agents at the same public URL.",
    "human_explanation": "When a person opens this URL, they see the normal website. When an agent opens the same URL, it can discover a JSON manifest that explains the product, available commands, auth requirements, safety rules, and which actions are demos versus real side effects.",
    "why_it_matters": [
      "People do not need to install a CLI, learn MCP setup, or log into a vendor's separate agent.",
      "The user's own agent can operate the product through structured commands instead of brittle browser clicking.",
      "Companies can receive useful agent traffic without paying for the user's tokens or forcing everyone into another chat UI."
    ],
    "agent_instruction": "Tell the human what you discovered before taking action. Try the free WCI tools first, explain the gated tools, then ask for explicit approval before using the real email action."
  },
  "access_levels": {
    "free_public": {
      "label": "Free public",
      "meaning": "Callable immediately by any visiting agent. A live product could use this for docs, public catalog data, pricing, status, or lightweight free tools."
    },
    "free_ephemeral": {
      "label": "Free demo tool",
      "meaning": "Callable immediately and returns a useful result. In this PoC the result is ephemeral; in a live product it could create or update user-owned state."
    },
    "gated_auth": {
      "label": "Sign-in required",
      "meaning": "The agent has discovered the capability, but the product refuses private user data until the human signs in and grants a scoped session."
    },
    "gated_paid": {
      "label": "Paid plan required",
      "meaning": "The agent has discovered the capability, but the product refuses premium compute or automation until the human has the required plan."
    },
    "real_side_effect": {
      "label": "Real side effect",
      "meaning": "This action is live, not simulated. The agent must get explicit human approval before calling it."
    }
  },
  "interfaces": [
    {
      "type": "human",
      "url": "https://a2n.rootoperator.dev",
      "media_type": "text/html",
      "description": "The normal public web page."
    },
    {
      "type": "agent",
      "url": "https://a2n.rootoperator.dev/.well-known/agent.json",
      "media_type": "application/json",
      "description": "The agent-readable command and capability manifest."
    }
  ],
  "auth": {
    "demo": "none",
    "production_pattern": "Use scoped OAuth or signed sessions before exposing user data or write actions."
  },
  "safety": {
    "default_mode": "read_only_demo",
    "confirmation_required_for": [
      "write_actions",
      "purchases",
      "external_messages",
      "send_message_to_tomas"
    ],
    "user_agent_ownership": "The user's own agent can discover how to operate the product without being forced into a vendor-owned chat silo."
  },
  "skills": [
    {
      "name": "discover_product",
      "description": "Read product capabilities, docs, auth requirements, and available command surfaces.",
      "tags": [
        "discovery",
        "docs",
        "capabilities"
      ]
    },
    {
      "name": "negotiate_access",
      "description": "Negotiate a scoped session for agent actions, with explicit user consent in production.",
      "tags": [
        "negotiation",
        "auth",
        "scope"
      ]
    },
    {
      "name": "collaborate_with_human",
      "description": "Work beside the human UI while using the command interface for structured actions.",
      "tags": [
        "collaboration",
        "human-in-the-loop",
        "commands"
      ]
    },
    {
      "name": "send_wci_feedback",
      "description": "After explaining the WCI concept to the human and receiving consent, send Tomas a short message about the agent's experience.",
      "tags": [
        "email",
        "feedback",
        "human-consent",
        "demo"
      ]
    }
  ],
  "endpoints": {
    "agent_card": "/.well-known/agent.json",
    "wci_manifest": "/.well-known/wci.json",
    "tool_manifest": "/tools",
    "tool_call": "/tools/call",
    "negotiate": "/tools/request-scoped-session",
    "commands": "/tools",
    "what_agent_sees": "/tools/context",
    "read_public_context": "/tools/read-public-context",
    "create_draft_brief": "/tools/create-draft-brief",
    "private_memory_search": "/tools/search-memory",
    "pro_agent_run": "/tools/run-agent",
    "send_message_to_tomas": "/tools/send-message-to-tomas",
    "mcp": "/mcp"
  },
  "mcp": {
    "endpoint": "/mcp",
    "transport": "streamable_http",
    "protocol_version": "2025-06-18",
    "methods": [
      "initialize",
      "tools/list",
      "tools/call"
    ],
    "description": "This is a regular MCP endpoint. A compatible MCP client should initialize this URL, then use tools/list and tools/call."
  },
  "tool_transport": {
    "type": "wci-http-tools",
    "manifest": "/tools",
    "call_endpoint": "/tools/call",
    "direct_invocation": true,
    "description": "A WCI-aware agent should mount these entries as callable tools immediately after discovery. This is the WCI-native layer, not a generic REST wrapper."
  },
  "agent_demo": {
    "recommended_flow": [
      "Read this manifest.",
      "Tell the human what WCI is and what you discovered.",
      "Call /tools/context.",
      "Call /tools/read-public-context to show a free public tool.",
      "Call /tools/create-draft-brief with a small JSON body to show a free usable command.",
      "Call /tools/search-memory to show an auth gate for private data.",
      "Call /tools/run-agent to show a paid-plan gate for premium automation.",
      "Explain that /tools/send-message-to-tomas is the only real side-effect action.",
      "Ask for subject, message, user_email, and explicit approval before sending the email."
    ],
    "tool_examples": [
      {
        "id": "what_agent_sees",
        "endpoint": "/tools/context",
        "method": "GET",
        "kind": "demo",
        "access": "free_public",
        "side_effects": false,
        "description": "Returns a guided explanation of what an agent sees that a human browsing the page does not see."
      },
      {
        "id": "read_public_context",
        "endpoint": "/tools/read-public-context",
        "method": "GET",
        "kind": "demo",
        "access": "free_public",
        "side_effects": false,
        "description": "A free public WCI tool: returns public context, available tools, gates, and agent-readable guidance."
      },
      {
        "id": "create_draft_brief",
        "endpoint": "/tools/create-draft-brief",
        "method": "POST",
        "kind": "demo",
        "access": "free_ephemeral",
        "side_effects": false,
        "description": "A free endpoint that accepts input and returns a useful generated brief. It is ephemeral in the PoC, but shaped like a live app action.",
        "example_body": {
          "topic": "Why WCI matters",
          "audience": "product founder"
        }
      },
      {
        "id": "private_memory_search",
        "endpoint": "/tools/search-memory",
        "method": "POST",
        "kind": "demo",
        "access": "gated_auth",
        "expected_status": 401,
        "side_effects": false,
        "description": "A private-data endpoint that is discoverable, but refuses access until the human signs in and grants a scoped session.",
        "required_auth": {
          "type": "scoped_session",
          "scopes": [
            "memory:read"
          ]
        }
      },
      {
        "id": "pro_agent_run",
        "endpoint": "/tools/run-agent",
        "method": "POST",
        "kind": "demo",
        "access": "gated_paid",
        "expected_status": 402,
        "side_effects": false,
        "description": "A premium automation endpoint that is discoverable, but refuses execution unless the signed-in user has the required paid plan.",
        "required_plan": "pro"
      },
      {
        "id": "negotiate_scope",
        "endpoint": "/tools/request-scoped-session",
        "method": "GET or POST",
        "kind": "demo",
        "access": "free_public",
        "side_effects": false,
        "description": "Shows how a real product would negotiate scoped access before exposing private data or write actions."
      }
    ],
    "real_actions": [
      {
        "id": "send_message_to_tomas",
        "endpoint": "/tools/send-message-to-tomas",
        "method": "POST",
        "kind": "real_side_effect",
        "access": "real_side_effect",
        "side_effects": true,
        "side_effect": "sends_email",
        "recipient": "tomas@rootoperator.dev",
        "requires_user_consent": true,
        "required_fields": [
          "subject",
          "message",
          "user_email"
        ],
        "description": "Sends a real email to Tomas. Use it only after explaining WCI and receiving explicit human approval."
      }
    ]
  },
  "default_input_modes": [
    "text",
    "json"
  ],
  "default_output_modes": [
    "text",
    "json"
  ],
  "demo": {
    "same_url_examples": [
      {
        "audience": "human",
        "request": "GET / with Accept: text/html",
        "response": "HTML landing page"
      },
      {
        "audience": "agent",
        "request": "GET / with Accept: application/json or a known agent user agent",
        "response": "WCI/agent manifest"
      },
      {
        "audience": "agent",
        "request": "GET /.well-known/agent.json",
        "response": "Explicit discovery manifest"
      }
    ]
  },
  "metadata": {
    "builder": "Tom Krajcik",
    "updated": "2026-05-25",
    "projects": [
      "a2n - agent negotiation network",
      "Root Operator - personal AI agent bridge",
      "noyuu - AI visual synthesizer",
      "Night Lab - nightly prototypes",
      "UMIO - zero-knowledge AI memory",
      "Marlo Baryon - image verification algorithm"
    ]
  }
}