API reference
The Trooth application programming interface (API) is public, read-only and versioned. The endpoints on this page need no key and no account.
Quickstart
The public endpoints take no key: the Trust Profile read below, the operations in the API reference, and the Model Context Protocol (MCP) server. Trooth does not offer a credentialed API for outside integration. The authenticated endpoints run the company and buyer workspaces, are scoped to a signed-in session, and are not documented here.
A workspace API key has one documented use: sending evidence events into your own company workspace, described under Connect, API and webhook in the workspace. A key is scoped to that workspace, shown once when it is created, and revocable at any time. No other endpoint is documented for a key, so a key is not a supported way to read or change anything else. Webhooks fire on the events listed in the developer docs, and a delivery is attempted rather than guaranteed.
Example request
# Reads a company's published Trust Profile by its slug. No key, no account.curl https://api.trooth.co/public/trust/your-coconst res = await fetch("https://api.trooth.co/public/trust/your-co");const profile = await res.json();console.log(profile.profile.displayName, profile.profile.domain);Authentication and rate limits
The endpoints on this page take no authentication. Where a limit applies it is counted for each IP address rather than for each tenant. This site's own limits run two fixed windows at the same time, one by the minute and one by the hour (lib/rate-limit.ts). The Trooth API applies no rate limit to the /public/trust read above. The MCP server allows 120 tool calls a minute for each IP address, counted separately on each server instance, so the limit is approximate; listing and the handshake are not counted, and over it the answer is 429 with Retry-After: 60. Trooth is free and has no plans, so no caller carries a larger allowance than another. Webhooks are HMAC-signed.
MCP server for AI agents
Trooth's public trust layer is queryable by AI agents over the Model Context Protocol. The server is read-only and needs no key: it exposes published Trust Profiles, live outside-in surface reads, token checks, and Trooth's curated knowledge base, with the same provenance labels as everywhere else. Point any MCP client that connects to remote servers at the endpoint below (streamable HTTP, single JSON response per POST, protocol 2026-07-28, server trooth-mcp 1.1.0). The older revisions 2025-06-18, 2025-03-26 or 2024-11-05 are still answered, so a client written against one of those keeps working and does not have to change to connect. The block below is a project .mcp.json entry in the form Claude Code and VS Code document; Claude.ai and Claude Desktop take the same URL under Customize, Connectors, Add custom connector, and ChatGPT has Trooth Network as a listed app. Each client's plan and region limits and its removal step are on the agents page.
{ "mcpServers": { "trooth": { "type": "http", "url": "https://api.trooth.co/public/mcp" } }}Tools: trooth_public_trust_profile (for a company that publishes, its record in prose: coverage, the last witnessed date, continuity, a methodology summary, how many facts are published and a link to the profile; the facts themselves are on the profile and in /api/network/profile), trooth_outside_in_read (live TLS, security headers, security.txt for any public domain), trooth_verify (re-check a Trust Ledger Token's two signatures and report it valid, expired, revoked, or invalid when a signature fails), and trooth_ask (Trooth product and methodology questions). Each takes one required string argument (company, domain, token, question) and returns structuredContent with status, provenance, subject and summary alongside the text. The server also serves 4 markdown resources (trooth://methodology, trooth://provenance-labels, trooth://verify-a-vendor, trooth://what-a-call-sends) and 3 prompts (vendor_trust_check, verify_trust_token, before_you_trust). Tool calls are rate limited per IP, as above; tenant data is never exposed. The field-level contract and the agent pattern are on Agents and MCP.
Every interface, in one table
This is the controlling list of what Trooth offers programmatically. Anything not in it is internal: it serves the website, changes without notice and is not supported for integration.
| Interface | Host | Access | Effect | Support | Documented at |
|---|---|---|---|---|---|
| Canonical profile, GET /api/network/profile | trooth.co | Public, no credential | Read | Supported, contract 2 | /openapi.json |
| The other eight public reads in /openapi.json | trooth.co | Public, no credential | Read | Supported | /developers |
| GET /public/trust/:slug and the directory feed | api.trooth.co | Public, no credential | Read | Supported; older than the canonical profile, which is preferred | Trust Profile API |
| MCP server, four tools | api.trooth.co/public/mcp | Public, no credential | Read | Supported | Agents and MCP |
| Profile subscriptions (agent-subscribe) | api.trooth.co | Public; the destination must answer a challenge | Creates a subscription and sends deliveries | Supported | Agents and MCP |
| Command-line interface (CLI), trooth check and lint | api.trooth.co (check only) | Public, no credential | Read | Supported | CLI |
| Workspace evidence events | api.trooth.co | Workspace API key | Writes to your own workspace | Supported, one use | Connect, API and webhook, in the workspace |
| Webhooks and alert destinations | Outbound from Trooth | Configured in a signed-in workspace | Deliveries to your endpoint | Supported | Webhooks |
| WebMCP draft tools | In the signed-in editor, in your browser | Your own session | Changes a draft; never publishes | Experimental | Build with AI |
| Session routes behind the website and workspaces | trooth.co | Signed-in session | Varies | Internal, not supported | Not documented |
Pagination and completeness
The directory search pages with an opaque cursor: pass next_cursor back as cursor until it is null. A cursor names a position in an ordering, not a frozen copy of the directory. The walk is not atomic: a company published, edited or removed while you walk can appear on a page you have not reached yet, or move past one you have. There are no tombstones: a removed company is simply absent.
To hold a complete copy, walk to the end, then walk again, and compare the two sets of slug values. A slug in both walks is current. A slug in only the second is new. A slug in only the first was removed or unpublished; confirm it with GET /api/network/profile?q=<slug>, which answers found: false for a company no longer published. Repeat until two walks agree. A cursor that cannot be read is refused with 400, never answered with an empty page.
The API is free.
Every endpoint on this page is free to call, with no key and no account. Trooth is free to join, free to be listed and free to be witnessed. There is nothing to buy, and no position on any Trooth page is for sale.
Use of the Trooth API is subject to the Terms of Service.