Registry · Capabilities · surrealdb.com
Capability registry
What surrealdb.com declares an agent can do
Measured 2026-10-05 04:18 UTC from the declarations the site publishes (record 2ubk6f7pw9). Each capability is shown as declared, under the policy class that decides whether anything may call it, beside what a call observed.
Declared versus observed
| Capability | Policy class | Declared | Observed |
|---|---|---|---|
| getCloudPricing openapi · GET · https://surrealdb.com/api/cloud/pricing.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | behavior verified HTTP 200 · application/json |
| getHomepageMarkdown openapi · GET · https://surrealdb.com/index.md | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | behavior verified HTTP 200 · text/markdown |
| getPageMarkdown openapi · GET · https://surrealdb.com/{page}.md | Public read-only | HTTP GET with no declared security auth: none · required inputs: 1 | not attempted needs 1 required input: nothing is invented to fill them |
| getLlmsIndex openapi · GET · https://surrealdb.com/llms.txt | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getLlmsFull openapi · GET · https://surrealdb.com/llms-full.txt | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getSitemapIndex openapi · GET · https://surrealdb.com/sitemap.xml | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getOpenApiDescription openapi · GET · https://surrealdb.com/openapi.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getMcpServerCard openapi · GET · https://surrealdb.com/.well-known/mcp/server-card.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getAgentCard openapi · GET · https://surrealdb.com/.well-known/agent-card.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getAiCatalog openapi · GET · https://surrealdb.com/.well-known/ai-catalog.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getAgentSkillsIndex openapi · GET · https://surrealdb.com/.well-known/agent-skills/index.json | Public read-only | HTTP GET with no declared security auth: none · required inputs: 0 | not attempted outside the per-scan call budget (2 GETs, 1 MCP tool) |
| getAuthGuide openapi · GET · https://surrealdb.com/auth.md | Identity and accounts never called automatically | its name contains “auth” auth: none · required inputs: 0 | not attempted classed identity_or_account: only read-only public actions are ever called |
| getSectionPageMarkdown openapi · GET · https://surrealdb.com/{section}/{page}.md | Public read-only | HTTP GET with no declared security auth: none · required inputs: 2 | not attempted needs 2 required inputs: nothing is invented to fill them |
| getSubsectionPageMarkdown openapi · GET · https://surrealdb.com/{section}/{subsection}/{page}.md | Public read-only | HTTP GET with no declared security auth: none · required inputs: 3 | not attempted needs 3 required inputs: nothing is invented to fill them |
| getDeepPageMarkdown openapi · GET · https://surrealdb.com/{section}/{subsection}/{subsubsection}/{page}.md | Public read-only | HTTP GET with no declared security auth: none · required inputs: 4 | not attempted needs 4 required inputs: nothing is invented to fill them |
| server mcp | Metadata never called automatically | a server declaration; its tools are listed only by the server itself (tools/list), which is not called auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| cloud-instance-management a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| surrealql-query a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| schema-and-catalogue a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| instance-monitoring a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| organisation-access a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| billing-and-usage a2a | Financial never called automatically | its name contains “billing” auth: unknown | not attempted classed financial: only read-only public actions are ever called |
| agent-memory a2a | Unknown never called automatically | its effect is not stated in the declaration auth: unknown | not attempted classed unknown: only read-only public actions are ever called |
| surrealdb-agent-memory-docs agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-agent-memory-docs/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealdb-cli agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-cli/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealdb-docs agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-docs/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealdb-js agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-js/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealdb-python agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-python/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealdb-vector agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealdb-vector/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealkit agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealkit/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealql-functions agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealql-functions/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealql-performance agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealql-performance/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
| surrealql agent_skill · https://surrealdb.com/.well-known/agent-skills/surrealql/SKILL.md | Metadata never called automatically | an instruction file an agent reads; not an operation auth: none | not attempted metadata: describes a surface, is not itself an action |
Where the declaration and the call disagree
None: every capability that was called answered as declared.
Signed certificate
This page’s rows, signed by the observer’s Ed25519 key: every capability’s id, endpoint, safety class, policy class and observed state, the declaration hashes and the record’s sealed manifest. The certificate is derived from the record alone, so the same record always yields the same id.
alg Ed25519 · kid hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
sig 3sFhtJAXU_80V_57nw-AZ7T4jXtqOeNdGFsyb1NAG65TBIB4FvHsXbilvTsfhqrM4T9nno_qJlxdBfsBxHapBA
The certificate as JSON · verify it now · the key directory · machine-readability certificate
To verify it yourself: SHA-256 the certificate object as canonical JSON (keys sorted, no whitespace); the hex digest must equal certificate_sha256 and the id; then check the Ed25519 signature over "crawlcheck-capability-certificate-v1\n" followed by that hex digest, with the key in the directory whose RFC 7638 thumbprint is the kid.
Policy classes
| Policy class | Called automatically? | Rule |
|---|---|---|
| Public read-only public_read_only | yes, to verify | May be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin. |
| Authenticated read-only authenticated_read_only | never | Never called by CrawlCheck. An agent needs the user's own credentials and consent. |
| Reversible write reversible_write | never | Never invoked automatically. Needs the owner's written authorisation and a test account. |
| Irreversible write irreversible_write | never | Never invoked automatically. Deletes or changes something that cannot be undone. |
| Financial financial | never | Never invoked automatically. Moves money or creates a charge. |
| External communication external_communication | never | Never invoked automatically. Sends a message, email or notification to someone. |
| Identity and accounts identity | never | Never invoked automatically. Creates, signs in to or changes an account or credential. |
| Unknown unknown | never | Never invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case. |
| Metadata metadata | never | Nothing to invoke: a listing, a server card or a skill file, not an operation. |