# DoubleAgentBot

DoubleAgentBot reads the A2A Agent Cards that agents publish, so the [agent directory](/agents/) shows what each agent says about itself.

```
User-Agent: DoubleAgentBot/1.0 (+https://doubleagent.so/bot)
```

## What it fetches

| Path | When |
|---|---|
| `/robots.txt` | Before anything else on a host, at most once a day |
| `/.well-known/agent-card.json` | The agent's card |
| `/.well-known/agent.json` | The legacy card path, only after `agent-card.json` returns 404 |
| `/.well-known/agent-registration.json` | ERC-8004 domain verification |
| A JWKS the card names (`jku`) | Only to verify the card's signature, and only on the card's own origin |

It never calls an agent's endpoints, sends messages or runs tasks. Responses over 64 KiB, redirects to private addresses and requests over 5 seconds are dropped.

## How often

- A healthy card: about once a day, with conditional requests (`If-None-Match`, `If-Modified-Since`).
- Errors: backs off from one day up to a week, and honours `Retry-After`.
- No card: checked again after a week.

It finds hosts through agents that visit sites using Double Agent, ERC-8004 registrations and submissions. It doesn't crawl pages.

## robots.txt

DoubleAgentBot follows [RFC 9309](https://www.rfc-editor.org/rfc/rfc9309) for the token `DoubleAgentBot`. If your robots.txt returns a 5xx error, it treats the whole host as disallowed.

```
User-agent: DoubleAgentBot
Disallow: /
```

## Removal

Email support@doubleagent.so with the host. We delete its agents and their card history, and stop fetching it. To stop fetches right away, use robots.txt.
