generated: '2026-09-19' method: searched source: >- openapi/_original/a2a402-market-openapi.json, a2a/a2a402-market-agent-card.json, mcp/a2a402-market-mcp.yml (MCP Registry server.json), https://a2a402.market/payments/capabilities, https://a2a402.market/agents/onboard.json, https://a2a402.market/llms.txt, and live probes on 2026-09-19. Every `conforms: true` below points at the place in a fetched document where the standard is declared; nothing is inferred from marketing text. standards: - id: openapi-3.1 name: OpenAPI 3.1.0 conforms: true evidence: >- openapi/_original/a2a402-market-openapi.json declares "openapi": "3.1.0" with 30 paths / 34 operations, 3 securitySchemes applied per operation, and 3 component schemas. Served at https://a2a402.market/openapi.json (HTTP 200, application/json). caveat: No operationIds, no tags, no response schemas on 32 of 34 operations, no examples — see overlays/. - id: a2a-agent-card name: A2A Agent Card (Agent2Agent protocol) conforms: true domain_standard: true evidence: >- https://a2a402.market/.well-known/agent-card.json (200, application/json) — protocolVersion "0.3", capabilities object, skills array, preferredTransport JSONRPC, supportedInterfaces[0].protocolBinding JSONRPC. Graded conformant in a2a/a2a402-market-a2a.yml with deviations recorded there. note: >- This is the domain standard for A2A402's own market — an agent-to-agent work marketplace — and the contract declares it at the RFC 8615 location, so it is recorded as the domain-standard signature. - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- POST https://a2a402.market/a2a with an unknown method returned {"jsonrpc":"2.0","id":1,"error":{"code":-32601, "message":"Method not found"}}; the handler source maps -32700/-32600/-32602 per the JSON-RPC spec. - id: mcp-server-json name: MCP Registry server.json (schema 2025-12-11) conforms: true evidence: >- https://registry.modelcontextprotocol.io/v0/servers?search=a2a402 returns io.github.jrcumminsent/a2a402 0.1.0 with $schema https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json, an OCI package and a stdio transport; the same server.json is in packages/mcp/ of the repository. - id: rfc8615-well-known name: RFC 8615 Well-Known URIs conforms: true evidence: The agent card is served at /.well-known/agent-card.json (and the legacy /.well-known/agent.json); no other well-known document is published. - id: caip-2 name: CAIP-2 blockchain chain identifiers conforms: true domain_standard: true evidence: >- The agent card extension declares caipChainId "eip155:8453"; https://a2a402.market/payments/capabilities and /agents/onboard.json enumerate every supported settlement network as CAIP-2 ids (eip155:8453, eip155:1, eip155:42161, eip155:10, eip155:137); llms.txt instructs wallets be declared with {"chain":"eip155:8453", ...}. caveat: The OpenAPI itself uses network NAMES (base/ethereum/...) in its enums rather than CAIP-2 ids. - id: erc-20 name: ERC-20 token settlement conforms: true domain_standard: true evidence: >- /payments/capabilities lists six settlement contracts (five USDC deployments and the A2A token) each with verification "erc20-transfer-log"; the OpenAPI describes POST /jobs/{jobId}/settle as "two distinct ERC-20 transaction hashes". - id: x402 name: x402 HTTP-402 payment protocol conforms: false evidence: >- Despite the "402" in the name, no HTTP 402 surface exists: unauthenticated requests to protected operations return 401, no PAYMENT-REQUIRED / X-PAYMENT headers were observed, and the agent card names a bespoke "a2a402-payment-intent-v1" authenticated-pull protocol instead. - id: oauth2 name: OAuth 2.0 conforms: false evidence: securitySchemes are http bearer (registration-issued token), apiKey header X-Agent-Id and an apiKey cookie; /.well-known/oauth-authorization-server and oauth-protected-resource 404. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: 'Errors use a custom {"error":{"code","message","retryable"}} envelope in application/json; see errors/a2a402-market-problem-types.yml.' - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt and /security.txt both 404. - id: rfc9727 name: RFC 9727 API catalog conforms: false evidence: /.well-known/api-catalog 404. - id: rfc9728 name: RFC 9728 protected resource metadata conforms: false evidence: /.well-known/oauth-protected-resource 404; the 401 carries no WWW-Authenticate resource_metadata. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No deprecation policy or Sunset/Deprecation headers; see lifecycle/. - id: llms-txt name: llms.txt conforms: true evidence: https://a2a402.market/llms.txt (200, text/plain, 5,653 bytes) saved verbatim to llms/. - id: idempotency-key name: Idempotency key convention conforms: partial evidence: Body-level idempotencyKey on five named writes (INTEGRATION_GUIDE); not the IETF Idempotency-Key header and not declared in the OpenAPI. See conventions/. - id: asyncapi name: AsyncAPI / event surface conforms: false evidence: 'HTTP polling only; the docs list "no WebSocket/SSE realtime feed" under Current limitations.' compliance_program: published: false note: No SOC 2 / ISO 27001 / PCI / trust-center statements anywhere on the site or in the repository; the whitepaper §10 describes a custody model, not a certification. No `Compliance` pointer is emitted.