Early AccessEvery agent is free to connect — no card, no checkout. Paid agents are coming.

Verified publisher

It tells you who published an agent — not that the agent is safe.

A “Verified publisher” has proven they control the domain or GitHub organization shown next to their name. That confirms their identity. It is not a safety review of the agent itself — for that, read the security facts on each agent’s page.

How identity is proven

A publisher earns the badge one of two ways. Both are things only the real owner can do, so the badge can’t be claimed for a domain or organization someone doesn’t control.

Domain control

The publisher added a unique verification record to their domain’s DNS, which only someone who controls that domain can do. So the domain shown next to the badge really is theirs.

GitHub organization ownership

The publisher signed in with GitHub, and we confirmed they are an owner or admin of the organization they claim. So the organization shown next to the badge really is theirs.

What the badge does not mean

  • It does not mean the agent is safe, audited, or certified by FindAgent.
  • It does not replace the per-listing security facts — always check what an agent can do, where your keys go, and whether it was scanned and human-reviewed on its own page.
  • It says nothing about quality, reliability, or whether the agent is right for you.

In short: the badge answers “who published this?” — not “is this safe?”. Read the security guarantees to see what every agent is held to, verified publisher or not.

Frequently asked questions

Does a Verified publisher badge mean the agent is safe?

No. The badge verifies the publisher’s IDENTITY — that they control the domain or GitHub organization shown. It does not certify that the agent is safe, well-behaved, or bug-free. For what the platform actually enforces on every agent, see the per-listing security facts on the agent’s page and our Security page.

How does a publisher get verified?

They prove they control a domain (by adding a unique DNS TXT record we check) or that they own/admin a GitHub organization (checked live with their own GitHub sign-in). Both are things only the real owner can do, so the badge can’t be self-claimed for a domain or org someone doesn’t control.

What should I still check before connecting a verified publisher’s agent?

The same things you check for any agent: the per-listing security facts on its page — what it can do, where your keys go, and whether it was scanned and human-reviewed. Verified identity tells you who published it, not whether it’s right for you.