# IdentityMD public control-plane probe

Observed **2026-10-05, approximately 01:21–01:23 UTC**, using unauthenticated HTTPS GET requests. This report concerns the IdentityMD service at `imd.fun`: its [official API documentation](https://imd.fun/docs/) identifies `https://api.imd.fun` and [the Explorer](https://explorer.imd.fun/). The literal `identity.md` hostname returned an unrelated passport-service page and is not used as evidence about this network.

**Evidence labels:** “Observed” means a server response, not independently established real-world truth. “Documented” means an official route description, without a successful request necessarily having been made. “Inference” marks interpretation. Timestamped response excerpts are included in [evidence/](evidence/); they are locally captured evidence, not third-party attestations.

## 1. Read surfaces that matter

All API paths below use `https://api.imd.fun`. Concrete links are observed requests; route patterns in the final row are documented extensions, not invented endpoints.

| Surface | What it exposes and what was checked |
| --- | --- |
| Build and service context | [Version](https://api.imd.fun/version) returned HTTP 200, a commit, protocol version and feature flags. `/services` and `/swarm` also returned 200 during the initial probe: service presence and a fleet overview. |
| Jobs and outputs | [Job list](https://api.imd.fun/jobs?limit=3) returned IDs, objectives, states and timestamps. A [completed job’s result](https://api.imd.fun/jobs/39086abf-c9ed-4837-abfc-f7c5964cc741/result) exposes source hashes, download URLs, evaluation/profile and repository delivery. Its [records](https://api.imd.fun/jobs/39086abf-c9ed-4837-abfc-f7c5964cc741/records) expose a registry, record hash, status and transaction hash. All returned 200. |
| Seats and dispatch | [Seat records](https://api.imd.fun/seats/records) expose recorded attempt outcomes; [seat 1649’s standing](https://api.imd.fun/seats/1649/standing) exposes enrollment and heartbeat/presence. Both returned 200. `/workers?fields=tokenId,working,version` returned 200, but rows contained `deviceKey` and `working`, not the requested token/version fields; do not assume a projection proves those values. |
| Oracles | [Requests](https://api.imd.fun/oracle/requests?limit=3), [counts](https://api.imd.fun/oracle/counts) and a [specific request](https://api.imd.fun/oracle/requests/942a8e66-eedb-4bcd-9640-ef66d7a03a3c) returned 200. They expose lifecycle, question, block window and associated job. Its [attestation route](https://api.imd.fun/oracle/requests/942a8e66-eedb-4bcd-9640-ef66d7a03a3c/attestation) returned 404 with `not_attested`, not a signed answer. |
| Publications and serving identity | [Publications](https://api.imd.fun/publications?page=1&pageSize=3) initially returned 503, then 200 on retry. [Publication counts](https://api.imd.fun/publications/counts), [sites](https://api.imd.fun/sites), an [individual site](https://api.imd.fun/sites/ff444f56-603f-489b-a405-5ff4453d6352) and [current label mapping](https://api.imd.fun/sites/by-label/floppy-pepe-publication-blocked) returned 200. These distinguish catalog entries, stored site versions and the CID currently mapped to a name. |
| Documented drill-down routes | `GET /jobs/:id`, `/jobs/:id/submissions`, `/jobs/:id/panel`, `/jobs/:id/fuzz`, `/jobs/:id/assessments`; `/seats/:tokenId`, `/seats/owners`, `/contributors`; `/workflows/:id`, `/launches/:id/assurances`; `/work-records/:hash.json`, `/reviews/:hash.json`. These cover attempts, reviews, ownership, delivery context and supporting documents. Explorer also documents `/api/activity`, `/api/agents/:tokenId` and `/api/search`. See [official read-route documentation](https://imd.fun/docs/). These extensions were not individually tested here. |

**Reading limits:** Documentation specifies creation-time pagination for jobs/oracle requests and page-based pagination for publications. Job-list `count` is a page size, not a network total. The captured publications response contains three items but `count: 798`; the sites response reports `count: 100`, `total: 177`, `live: 160`. Counts from different surfaces therefore cannot be substituted for one another. [Docs](https://imd.fun/docs/), [publication snapshot](evidence/publications.json), [site snapshot](evidence/sites.json).

## 2. Three verifiable facts

1. **Observed — a delivered job records only structural evaluation.** Job `39086abf-c9ed-4837-abfc-f7c5964cc741` reports `state: completed`, `complete: true`, source `evaluation: structural`, `profile: none`, and delivery commit `e68ee4d2dfc1be005f329ad38d72a45e3cd7c0e6`. This is directly inspectable metadata about this job, not a claim that its software passed behavioral tests. [Live result](https://api.imd.fun/jobs/39086abf-c9ed-4837-abfc-f7c5964cc741/result), [snapshot](evidence/job-result.json).

2. **Observed — recorded participation and current presence are separate.** Seat 1649 has agent ID 50975 and 3,742 recorded attempts: 3,597 accepted, 26 rejected, 33 failed and 86 pending. Its separate standing response reports `connected: true`, `acceptingWork: true`, `stale: false` at `2026-10-05T01:21:53.552Z`. These are historical counters plus a momentary presence report, not a count of distinct people. [Records](https://api.imd.fun/seats/records), [standing](https://api.imd.fun/seats/1649/standing), [saved counters](evidence/seats.json), [saved standing](evidence/seat-standing.json).

3. **Observed — an oracle question can exist without an attestation.** Request `942a8e66-eedb-4bcd-9640-ef66d7a03a3c` was `assessing`, concerned chain 4663 and blocks 80353023–80370860, and linked job `69f342b6-2010-48d4-bfde-e986eca75530`. The attestation read returned `404 not_attested` with detail `the request is assessing`. That establishes the response at capture time, not permanent absence. [Request](https://api.imd.fun/oracle/requests/942a8e66-eedb-4bcd-9640-ef66d7a03a3c), [saved attestation response](evidence/oracle-attestation.json).

## 3. Three things the public API does not prove

1. **Output correctness or security.** Completion, a source hash and a publication record do not establish that software works, is safe, or that a research claim is true. The concrete completed job above explicitly reports structural evaluation with no execution profile. **Inference:** behavioral assurance requires additional evidence appropriate to the output. **Unanswered:** what independent behavioral review, if any, covers that exact delivered commit? [Result evidence](evidence/job-result.json).

2. **Independent human operators or independent reasoning.** A seat ID, device presence, registration and acceptance counters do not establish one distinct person per seat, unrelated ownership/control, or freedom from shared models and correlated errors. **Limit:** no human-identity or reasoning-independence verification was performed. **Unanswered:** what independently auditable evidence establishes operator and panel independence? [Standing evidence](evidence/seat-standing.json), [seat records](https://api.imd.fun/seats/records).

3. **Oracle truth or on-chain finality merely from returned metadata.** A request’s existence is not a signed answer; the checked request demonstrates that distinction. Even returned signatures and transaction hashes would require cryptographic and chain checks before claiming signer validity, inclusion or finality, and a valid signature alone would not prove the answer true. The sampled job record says `status: sent` and supplies a transaction hash; this report did not check its receipt. **Unanswered:** does that transaction have a successful, sufficiently confirmed receipt, and does a given oracle answer reproduce against its pinned evidence? [Attestation response](evidence/oracle-attestation.json), [job records](https://api.imd.fun/jobs/39086abf-c9ed-4837-abfc-f7c5964cc741/records).

## Uncertainty and method limits

These requests are separate snapshots, not an atomic database view. Status totals changed between probes. A transient publication 503 recovered; neither response establishes sustained availability. `/version` returned commit `0f11e1323268f7bb135ac3ba2f9cbd91f109776b` with `deployedAt: null`, so it supplies no deployment timestamp. No authenticated calls, writes, chain RPC verification, signature verification or output execution were performed. Homepage inspection covered fetched HTML, not an exhaustive interactive browser session. Local checks validate this deliverable’s consistency, not the service’s honesty or the research independently. [Version snapshot](evidence/version.json), [homepage retrieval metadata](evidence/marketing.json).

## Concrete discovery beyond the marketing site alone

**Observed:** the site named `floppy-pepe-publication-blocked` has a superseded version that still reports `status: named`. Old site `ff444f56-603f-489b-a405-5ff4453d6352` points to replacement `6bd98343-8df9-4f88-864e-76e7fd7d52f7`, with `supersededAt: 2026-10-04T20:10:34.913Z`. Its old CID is `bafybeihjxnetle4y734uuehslnwgefci54bqvwus4cmghtdildlpyrriqu`; the label lookup instead returns `bafybeihsmv266oxzfswzowerkcieswqnmn7hoa3ghrg3ablerk5cljfxty`. **Inference:** `named` alone is insufficient to identify the current published version; follow supersession and resolve the label. This specific version-to-CID relationship comes from operational records, not the fetched marketing homepage, and is discoverable by any human or agent using the same public reads. [Old site](https://api.imd.fun/sites/ff444f56-603f-489b-a405-5ff4453d6352), [current label](https://api.imd.fun/sites/by-label/floppy-pepe-publication-blocked), [saved old site](evidence/site-old.json), [saved mapping](evidence/site-current.json).
