Hands-on
Labs
Two self-paced tracks, run on Instruqt, and a handful of commands you can run right now against the live demonstration systems.
Each lab is a sealed sandbox of its own: a signed DNS hierarchy, seller, buyer, approval authority, agent registry and verifier, all under the reserved .test domain. Nothing in a lab touches a public system, and payments are simulated.
~15 minutes · no install
Guided tour
For security leaders and policy audiences
The five questions, answered inside your own sandbox: follow prepared commands, read the evidence, and watch a seller refuse an attack. Nothing to install.
Opens at GovWare~60 minutes · terminal
Builder
For engineers and agent builders
Sign your own zone, publish and register your agent, get a person's approval for a purchase, then attack your own seller and read the verifier's scorecard.
Opens at GovWareTry it now from your terminal
These run against the live agents behind the demonstration. They are read-only: nothing here spends money or changes state.
Discover the seller's agent catalogue in DNS
dig +dnssec _index._agents.agenthaven.dev TYPE64A signed record naming "catalog.agenthaven.dev", reachable over h2 on port 443. This is DNS-AID: an agent catalogue, published like any other DNS record and signed the same way.
Read the same catalogue as JSON
curl -s https://agenthaven.dev/.well-known/ard.jsonThe Agentic Resource Discovery (ARD) view of the same agents, with richer metadata than DNS alone carries.
Fetch the seller's agent card
curl -s https://travel.agenthaven.dev/.well-known/agent-card.jsonWho runs the agent, where to reach it, and what it can do, in the A2A agent card format.
Check the seller's DANE record
dig _443._tcp.travel.agenthaven.dev TLSAThe certificate the domain owner authorised in DNS for this endpoint, so an impostor at the same address can't pass the check.
Read the seller's signed ledger
curl -s https://travel.agenthaven.dev/ledgerA hash-chained, signed log of the seller's own actions. Anyone can read it; nobody can quietly edit it.