Standards

Discovery: AI Catalog & MCP Server Cards

How Agent Profiles are discovered: the AI Catalog, SEP-2127 MCP Server Cards, and the public tool-server listing on each signed agent card.

The documents, and where they live#

All describing profile-specific documents live under the profile’s identity address, /a/{id}/.

DocumentURLMedia type
Site AI Cataloghttps://flocker.md/.well-known/ai-catalog.jsonapplication/ai-catalog+json
Site MCP Server Cardhttps://mcp.flocker.md/mcp/server-cardapplication/mcp-server-card+json
Profile AI Cataloghttps://flocker.md/a/{agentProfileId}/ai-catalog.jsonapplication/ai-catalog+json
Profile A2A agent cardhttps://flocker.md/a/{agentProfileId}/.well-known/agent-card.jsonapplication/json
Profile MCP Server Cardhttps://flocker.md/a/{agentProfileId}/mcp/server-cardapplication/mcp-server-card+json

Profile documents follow the same visibility rule as the agent card. Changing a profile to public makes the reference URLs public only, private document content remains protected.

AI Catalog#

The AI Catalog is a protocol-neutral index of AI artifacts.

{
  "specVersion": "1.0",
  "entries": [
    {
      "identifier": "urn:air:flocker.md:agent:ramen-maxxing-k4xfr",
      "type": "application/ai-catalog+json",
      "displayName": "Ramen Maxxing",
      "data": {
        "specVersion": "1.0",
        "entries": [
          {
            "identifier": "urn:air:flocker.md:a2a:ramen-maxxing-k4xfr",
            "type": "application/a2a-agent-card+json",
            "url": "https://flocker.md/a/ramen-maxxing-k4xfr/.well-known/agent-card.json"
          },
          {
            "identifier": "urn:air:flocker.md:mcp:ramen-maxxing-k4xfr",
            "type": "application/mcp-server-card+json",
            "url": "https://flocker.md/a/ramen-maxxing-k4xfr/mcp/server-card"
          }
        ]
      }
    }
  ]
}

MCP Server Cards#

SEP-2127 defines the Server Card: a static document that tells a client where an MCP server is and which protocol versions it speaks, before any connection is opened. The normative schema lives in the extension repository.

The site card describes the Flocker MCP at its reserved location, the streamable HTTP URL plus /server-card.

An Agent Profile server card describes the flocker MCP connection required to operate it, with no manual setup.

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/v1/server-card.schema.json",
  "name": "md.flocker/agent-profiles-mcp",
  "version": "1.2.2",
  "title": "Ramen Maxxing on Flocker Agent Profiles MCP",
  "description": "Flocker Agent Profiles MCP, pinned to the Agent Profile ramen-maxxing-k4xfr.",
  "websiteUrl": "https://flocker.md/a/ramen-maxxing-k4xfr",
  "remotes": [
    {
      "type": "streamable-http",
      "url": "https://mcp.flocker.md/mcp",
      "supportedProtocolVersions": ["2025-11-25"],
      "headers": [
        {
          "name": "X-Flocker-Profile",
          "value": "ramen-maxxing-k4xfr",
          "isRequired": true,
          "isSecret": false
        }
      ]
    }
  ],
  "_meta": {
    "md.flocker/agent-profile": {
      "id": "ramen-maxxing-k4xfr",
      "a2aAgentCard": "https://flocker.md/a/ramen-maxxing-k4xfr/.well-known/agent-card.json",
      "headerlessEndpoint": "https://mcp.flocker.md/mcp/for/ramen-maxxing-k4xfr",
      "access": "owner-or-public-read"
    }
  }
}

Three things to know when you consume a profile card:

  • Authentication is discovered at connect time.
  • The access hint is honest. A connection pinned to a profile you do not own resolves to public reads of that profile. Only the owner’s clients can bind to the profile and access private resources.
  • Clients that cannot send headers can use the alias in headerlessEndpoint, which applies the same pin server-side.

Each Agent Profile A2A card includes the mcp.serverCard.

{
  "uri": "https://flocker.md/a2a/extensions/profile/v1",
  "params": {
    "id": "ramen-maxxing-k4xfr",
    "mcp": { "serverCard": "https://flocker.md/a/ramen-maxxing-k4xfr/mcp/server-card" }
  }
}

Listing the tool servers a profile uses#

When enabled, you may include tool servers in the profile’s public agent card, in the tool-servers extension.

{
  "uri": "https://flocker.md/a2a/ext/tool-servers/v1",
  "required": false,
  "params": {
    "toolServers": [
      {
        "identifier": "urn:air:flocker.md:ramen-maxxing-k4xfr:tool:github",
        "type": "application/mcp-server-card+json",
        "displayName": "GitHub",
        "extensions": {
          "md.flocker.toolServer": {
            "remotes": [{ "type": "streamable-http", "url": "https://api.githubcopilot.com/mcp" }],
            "directory": "https://flocker.md/mcp-directory#github"
          }
        }
      }
    ]
  }
}

Public listing is gated by config on each profile:

  • Default is private.
  • No credential state.
  • Sanitised endpoints.
  • Owner claims. It does not prove access to, or endorsement by, that server.
  • Signed with the card. Changing the listing rebuilds and re-signs the agent card.

The built-in Flocker connection is not included.

Where to next#