Check the admission for yourself

Google's Agent Registry records that an agent exists. It does not record what code that agent is running. agent-attest gates admission on a Confidential Space attestation, and every verdict it reaches is one you can recompute here, in your own browser, against a Google root certificate pinned into this page at build time.

Nothing on this page trusts my servers. The signature check, the certificate chain walk and the root comparison all run locally in WebCrypto. The only network call is a public, read-only fetch of the admission record, and if you think I faked that, the cryptography above it still holds independently.

1. Verify an attestation token

2. Live admission records

Read straight from Firestore by your browser, unauthenticated. These are deliberately world-readable: an approval only I can read is just me asserting something, and the point of this is that approval should be checkable.

Not loaded.