CrawlCheck

Registry · Capabilities · reducto.ai

Capability registry

What reducto.ai declares an agent can do

Measured 2026-10-04 18:18 UTC from the declarations the site publishes (record 8dio0dsfj6). Each capability is shown as declared, under the policy class that decides whether anything may call it, beside what a call observed.

38declared
1public read-only
0called and verified
0declared ≠ observed
a2a, agent_skill, api, mcp, openapiprotocols
Public read-only: 1Authenticated read-only: 2Irreversible write: 3External communication: 1Unknown: 27Metadata: 4
Public read-only 1 · Authenticated read-only 2 · Irreversible write 3 · External communication 1 · Unknown 27 · Metadata 4

Declared versus observed

CapabilityPolicy classDeclaredObserved
https://accounts.reducto.ai
api · https://accounts.reducto.ai
Metadata
never called automatically
an API the catalog lists; its operations are in its own description
auth: unknown
not attempted
on another origin (accounts.reducto.ai): only the scanned origin is called
https://platform.reducto.ai
api · https://platform.reducto.ai
Metadata
never called automatically
an API the catalog lists; its operations are in its own description
auth: unknown
not attempted
on another origin (platform.reducto.ai): only the scanned origin is called
https://mcp.reducto.ai/mcp
api · https://mcp.reducto.ai/mcp
Metadata
never called automatically
an API the catalog lists; its operations are in its own description
auth: unknown
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
parse_parse_post
openapi · POST · https://platform.reducto.ai/parse
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
async_parse_parse_async_post
openapi · POST · https://platform.reducto.ai/parse_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
extract_extract_post
openapi · POST · https://platform.reducto.ai/extract
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
extract_async_extract_async_post
openapi · POST · https://platform.reducto.ai/extract_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
split_split_post
openapi · POST · https://platform.reducto.ai/split
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
split_async_split_async_post
openapi · POST · https://platform.reducto.ai/split_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
edit_edit_post
openapi · POST · https://platform.reducto.ai/edit
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
edit_async_edit_async_post
openapi · POST · https://platform.reducto.ai/edit_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
pipeline_pipeline_post
openapi · POST · https://platform.reducto.ai/pipeline
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
pipeline_async_pipeline_async_post
openapi · POST · https://platform.reducto.ai/pipeline_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
classify_classify_post
openapi · POST · https://platform.reducto.ai/classify
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
classify_async_classify_async_post
openapi · POST · https://platform.reducto.ai/classify_async
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
retrieve_parse_job__job_id__get
openapi · GET · https://platform.reducto.ai/job/{job_id}
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
delete_parse_job_job__job_id__delete
openapi · DELETE · https://platform.reducto.ai/job/{job_id}
Irreversible write
never called automatically
HTTP DELETE
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
cancel_job_cancel__job_id__post
openapi · POST · https://platform.reducto.ai/cancel/{job_id}
Irreversible write
never called automatically
a write whose name contains “cancel”
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
get_jobs_jobs_get
openapi · GET · https://platform.reducto.ai/jobs
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 0
not attempted
requires http_bearer: never called without the operator's own credentials
upload_upload_post
openapi · POST · https://platform.reducto.ai/upload
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 0
not attempted
requires http_bearer: never called without the operator's own credentials
delete_uploaded_file_upload__file_id__delete
openapi · DELETE · https://platform.reducto.ai/upload/{file_id}
Irreversible write
never called automatically
HTTP DELETE
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
webhook_portal_configure_webhook_post
openapi · POST · https://platform.reducto.ai/configure_webhook
External communication
never called automatically
its name contains “webhook”
auth: http_bearer · required inputs: 0
not attempted
requires http_bearer: never called without the operator's own credentials
get_version_version_get
openapi · GET · https://platform.reducto.ai/version
Public read-onlyHTTP GET with no declared security
auth: none · required inputs: 0
not attempted
on another origin (platform.reducto.ai): only the scanned origin is called
get_documentation
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
upload_file
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
parse_document
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
extract_data
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
split_document
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
classify_document
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
edit_document
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
get_job
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
list_jobs
mcp · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: none
not attempted
on another origin (mcp.reducto.ai): only the scanned origin is called
parse
a2a · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: http_bearer
not attempted
requires http_bearer: never called without the operator's own credentials
extract
a2a · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: http_bearer
not attempted
requires http_bearer: never called without the operator's own credentials
split
a2a · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: http_bearer
not attempted
requires http_bearer: never called without the operator's own credentials
classify
a2a · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: http_bearer
not attempted
requires http_bearer: never called without the operator's own credentials
edit
a2a · https://mcp.reducto.ai/mcp
Unknown
never called automatically
its effect is not stated in the declaration
auth: http_bearer
not attempted
requires http_bearer: never called without the operator's own credentials
reducto
agent_skill · https://reducto.ai/SKILL.md
Metadata
never called automatically
an instruction file an agent reads; not an operation
auth: none
not attempted
metadata: describes a surface, is not itself an action

Where the declaration and the call disagree

None: every capability that was called answered as declared.

Signed certificate

This page’s rows, signed by the observer’s Ed25519 key: every capability’s id, endpoint, safety class, policy class and observed state, the declaration hashes and the record’s sealed manifest. The certificate is derived from the record alone, so the same record always yields the same id.

certificate_id ccap1:f96e7b7c4b4ca8cdce7dc9090183df120e22d2f5e911469e78d8c940f3b1df26
alg Ed25519 · kid hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
sig _350ZWXPFDsQE3lHeK62YSwyiBV20gCoQqDnR0UdfVx6hRQpUzIguEO484D1r-bChzcESA1sAOf5F97wX68BBQ

The certificate as JSON · verify it now · the key directory · machine-readability certificate

To verify it yourself: SHA-256 the certificate object as canonical JSON (keys sorted, no whitespace); the hex digest must equal certificate_sha256 and the id; then check the Ed25519 signature over "crawlcheck-capability-certificate-v1\n" followed by that hex digest, with the key in the directory whose RFC 7638 thumbprint is the kid.

Policy classes

Policy classCalled automatically?Rule
Public read-only
public_read_only
yes, to verifyMay be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin.
Authenticated read-only
authenticated_read_only
neverNever called by CrawlCheck. An agent needs the user's own credentials and consent.
Reversible write
reversible_write
neverNever invoked automatically. Needs the owner's written authorisation and a test account.
Irreversible write
irreversible_write
neverNever invoked automatically. Deletes or changes something that cannot be undone.
Financial
financial
neverNever invoked automatically. Moves money or creates a charge.
External communication
external_communication
neverNever invoked automatically. Sends a message, email or notification to someone.
Identity and accounts
identity
neverNever invoked automatically. Creates, signs in to or changes an account or credential.
Unknown
unknown
neverNever invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case.
Metadata
metadata
neverNothing to invoke: a listing, a server card or a skill file, not an operation.