# IdentityMD public control-plane probe

Observed 2026-10-06, approximately 05:00–05:02 UTC. **Facts below mean what the public service returned, not independent confirmation of the underlying activity.** Reads used no credentials and made no state changes. The deployed commit reported by [`/version`](https://api.imd.fun/version) was `5dba5e5e77aeeefe28ebba5126c8ace70de527c7`; `deployedAt` was null. [Saved responses and retrieval log](evidence/index.json) preserve the observations.

## 1. Read surfaces that matter

The project’s [Explorer](https://explorer.imd.fun/) links to [IMD API documentation](https://imd.fun/docs/), which identifies `https://api.imd.fun` as the control plane. The literal [identity.md domain](https://identity.md/) returned an unrelated passport-services page; it was not used as a technical source.

All concrete API links in this table returned HTTP 200 during this probe. They are GET reads, not invented route names.

| Area | Live read surfaces | What to inspect |
| --- | --- | --- |
| Runtime context | [`/version`](https://api.imd.fun/version), [`/health`](https://api.imd.fun/health), [`/services`](https://api.imd.fun/services), [`/swarm`](https://api.imd.fun/swarm) | Reported build, service presence, queues and aggregate activity. |
| Jobs | [`/jobs?limit=3`](https://api.imd.fun/jobs?limit=3), [one job](https://api.imd.fun/jobs/b0f332d1-6b3b-44a7-a5ed-8369ca149f3f), [its result](https://api.imd.fun/jobs/b0f332d1-6b3b-44a7-a5ed-8369ca149f3f/result) | State, node roles and verdicts, assigned seats, delivery commit, accepted source references. |
| Seats and workers | [`/workers`](https://api.imd.fun/workers?fields=tokenId,working,lastSeenAt), [`/seats/records`](https://api.imd.fun/seats/records), [seat 1013](https://api.imd.fun/seats/1013?work=2&reviews=2), [its standing](https://api.imd.fun/seats/1013/standing) | Device presence, seat history, enrollment, heartbeat freshness and dispatch eligibility. |
| Oracles | [attested request list](https://api.imd.fun/oracle/requests?limit=2&status=attested), [`/oracle/counts`](https://api.imd.fun/oracle/counts), [one attestation](https://api.imd.fun/oracle/requests/09432604-8c1a-4407-8d8d-6c66d7756679/attestation) | Question, status distribution, typed message, claimed signer and signature. |
| Publications | [`/publications`](https://api.imd.fun/publications?page=1&pageSize=2), [`/publications/counts`](https://api.imd.fun/publications/counts), [`/sites`](https://api.imd.fun/sites) | Published project entries, category counts, site status and content identifiers. |
| Human inspection | [Jobs](https://explorer.imd.fun/), [Agents](https://explorer.imd.fun/agents), [Oracle](https://explorer.imd.fun/oracle), [Published](https://explorer.imd.fun/published) | Browsable counterparts and links into individual records. |

**Documented, not successfully verified here:** request detail at `GET /oracle/requests/:id` and launch detail at `GET /launches/:id` are relevant to panels and deployment. Concrete requests returned 503. Other documented follow-ups include job submissions and records, seat owners, and workflow detail; those were not fetched. Documentation says job/oracle lists use creation-time cursors, whereas publications use page numbers; list `count` is not universally a network total. [API reference](https://imd.fun/docs/)

## 2. Three verifiable facts

1. **A completed job can expose a separately parked launch.** Job `b0f332d1-6b3b-44a7-a5ed-8369ca149f3f`, a ZTO bridge-adapter assignment, returned `state: completed`. Its result returned `complete: true`, three accepted source references and delivery commit `087d0519a25833a38820cda8878559868ef992e1`, while `launch.status` was `parked`. These are separate fields in the same result, not a comparison of unrelated counters. [Live result](https://api.imd.fun/jobs/b0f332d1-6b3b-44a7-a5ed-8369ca149f3f/result); [saved result](evidence/bridge-result.json).

2. **Seat identity, past work and current availability are separately observable.** Seat `1013` mapped to agent `52196`, with two attempts and two accepted submissions. Its history included the bridge job’s `audit_judge` role. Standing reported a connected device, `stale: false`, and `working: 0`: being online did not mean it was executing work at that instant. [Seat](https://api.imd.fun/seats/1013?work=2&reviews=2), [standing](https://api.imd.fun/seats/1013/standing); [saved seat](evidence/seat-1013.json), [saved standing](evidence/seat-standing.json).

3. **Oracle status and attestation contents can be inspected separately.** Counts returned 7,261 requests: 7,072 attested, 20 blocked, 166 disagreed, two mismatch and one refused. The sampled attestation for request `09432604-8c1a-4407-8d8d-6c66d7756679` returned domain version `2`, `panelSize: 5`, `quorum: 4`, `agreed: 4`, a signature and a signer field. This verifies the returned contents; no signature recovery or independent answer reproduction was performed. [Counts](https://api.imd.fun/oracle/counts), [attestation](https://api.imd.fun/oracle/requests/09432604-8c1a-4407-8d8d-6c66d7756679/attestation); [saved counts](evidence/oracle-counts.json), [saved attestation](evidence/oracle-attestation.json).

## 3. Three things the public API does not prove

1. **Correctness or safety of accepted work.** A verdict records the system’s decision under its checks. The sampled job reports a Foundry check profile, but that response alone does not establish exhaustive testing, a secure bridge, or correct research. Independent artifact inspection and appropriate reproduction remain necessary. [Job evidence](evidence/bridge-job.json).
2. **Independent people or independent reasoning behind seats.** Seat IDs, device keys and heartbeats expose logical participants. They do not establish distinct human operators, independent infrastructure, or freedom from correlated answers. This is an evidentiary limit, not an allegation about operators. [Seat evidence](evidence/seat-1013.json), [standing evidence](evidence/seat-standing.json).
3. **Truth or on-chain consumption of an oracle answer.** Returned signature bytes and agreement counts alone prove neither factual accuracy nor that a consumer contract accepted the answer. Cryptographic verification, signer trust, expiry handling and relevant chain evidence would need separate checks. [Attestation evidence](evidence/oracle-attestation.json).

## Uncertainty and unanswered questions

These are changing, non-atomic snapshots. Publications returned `count: 1141`, while the separately fetched counts response returned `all: 1140`. Timing or caching could explain that difference; this probe did not establish its cause. Category counts should not be added without establishing whether categories overlap. [Publication response](evidence/publications.json), [counts response](evidence/publication-counts.json).

The bridge job detail succeeded once and later returned 503; oracle request detail and launch detail also returned 503. Therefore the reason the launch was parked remains unanswered. No deployment transaction, source bundle, signature, or ownership claim was independently verified against a chain. Failed reads establish an observation-time access failure, not resource absence. See the [retrieval log](evidence/index.json).

## Concrete discovery beyond the marketing site

**The public control plane records the ZTO bridge-adapter job as completed, with a specific delivered source commit, while its requested launch remains parked.** The [marketing homepage](https://imd.fun/) did not supply that job-level distinction; the [job result](https://api.imd.fun/jobs/b0f332d1-6b3b-44a7-a5ed-8369ca149f3f/result) did. The supported inference is narrow but useful: completion of accepted work and launch deployment are separate milestones, so a completed-job label alone cannot establish a live deployment.
