generated: '2026-09-06' method: searched source: >- https://acadio.com/.well-known/ucp , https://acadio.com/.well-known/openid-configuration , probed tools/list at https://acadio.com/api/ucp/mcp , https://acadio.instantdocsbase.com/help/jwt-auth-documentation , https://acadio.instantdocsbase.com/help/webhooks-documentation , https://acadio.com/pages/lms-solutions and https://acadio.com/blogs/lms-articles description: >- Standards and specifications Acadio's own surfaces assert or demonstrably implement. Every entry cites the exact location the claim was read from; nothing is inferred from product category. conformance: - id: mcp name: Model Context Protocol conforms: true evidence: >- https://acadio.com/api/ucp/mcp answered a JSON-RPC 2.0 tools/list request with HTTP 200 and 13 tools carrying inputSchema objects, probed 2026-09-06. - id: ucp name: Universal Commerce Protocol (dev.ucp.shopping) conforms: true versions: ['2026-08-25', '2026-04-08', '2026-01-23'] evidence: >- https://acadio.com/.well-known/ucp declares ucp.version 2026-08-25, supported_versions for 2026-04-08 and 2026-01-23, the dev.ucp.shopping service with transport "mcp", and the dev.ucp.shopping.{cart,checkout,fulfillment,discount,order,catalog.search,catalog.lookup} capabilities with their ucp.dev schema URIs. - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: >- Every one of the 13 tool inputSchema objects returned by tools/list declares "$schema":"https://json-schema.org/draft/2020-12/schema". - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://acadio.com/.well-known/openid-configuration returns HTTP 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri, response_types_supported, scopes_supported and id_token_signing_alg_values_supported (RS256). - id: oauth2 name: OAuth 2.0 (authorization code + PKCE) conforms: true evidence: >- The same document advertises grant_types_supported authorization_code, refresh_token and urn:ietf:params:oauth:grant-type:jwt-bearer with code_challenge_methods_supported S256. Acadio LMS separately documents Google OAuth 2.0 authorization-code login at https://acadio.instantdocsbase.com/help/google-oauth-2-dot-0-documentation . - id: rfc7519-jwt name: 'RFC 7519: JSON Web Token' conforms: true evidence: >- https://acadio.instantdocsbase.com/help/jwt-auth-documentation specifies a signed JWS payload with documented claims and optional max-age and issuer claims, consumed at https://{domain}/auth/callback/jwt-auth. - id: rfc2104-hmac name: 'HMAC-SHA256 message authentication (RFC 2104 / FIPS 180-4)' conforms: true evidence: >- https://acadio.instantdocsbase.com/help/webhooks-documentation states Acadio signs the JSON webhook payload with HMAC SHA-256 and delivers the signature in the X-Acadio-Hmac-Sha256 header. - id: iso4217 name: 'ISO 4217 currency codes (minor units)' conforms: true evidence: >- Every UCP money value returned by the MCP tools is an integer in ISO 4217 minor units paired with a currency code, documented in each tool description. - id: iso3166-1-alpha-2 name: ISO 3166-1 alpha-2 country codes conforms: true evidence: >- The create_checkout inputSchema requires billing address country "in 2-letter ISO 3166-1 alpha-2 format". - id: rfc9457 name: 'RFC 9457: Problem Details for HTTP APIs' conforms: false evidence: >- No application/problem+json response, no error catalog and no error reference page is published on any Acadio surface. - id: openapi name: OpenAPI conforms: false evidence: >- /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all return the Kong "no Route matched with those values" 404 on api.acadio.com and an SPA shell on the portal hosts. No OpenAPI is published anywhere. - id: asyncapi name: AsyncAPI conforms: false evidence: >- A 19-topic webhook catalog is documented in prose at https://acadio.instantdocsbase.com/help/webhooks-documentation but no AsyncAPI document is published. domain_standards: - id: scorm name: SCORM 1.2 and SCORM 2004 (ADL Sharable Content Object Reference Model) regime: education conforms: true evidence: >- Acadio states courses in SCORM format can be imported and published, lists SCORM as a first-class activity media type on https://acadio.com/pages/lms-solutions and https://acadio.com/pages/lms-certification-training , documents SCORM as an activity type that is explicitly excluded from external completion events at https://acadio.instantdocsbase.com/help/completion-event-for-activities , and publishes an authoring guide "Best Practices for Creating SCORM 1.2 and 2004 Courses for Acadio LMS" (2025-10-29) at https://acadio.com/blogs/lms-articles . note: >- SCORM is the interoperability standard that matters in this market: a customer whose course library is already SCORM-packaged migrates without a bespoke conversion. Acadio names both profile versions, which is the specific claim rather than the generic one. - id: ucp-agentic-commerce name: Universal Commerce Protocol regime: commerce conforms: true evidence: >- https://acadio.com/.well-known/ucp — the contract declares the standard for its own market, including the payment_handlers block naming merchant_name "Acadio" and merchant_origin "acadio.com". not_found: - id: lti name: 1EdTech Learning Tools Interoperability note: No LTI claim appears on any Acadio surface; not probed for, not asserted. - id: xapi name: xAPI / Experience API (ADL) note: >- No xAPI or Tin Can claim is published. Acadio's own event surface is a proprietary webhook bus rather than an LRS. - id: oneroster name: 1EdTech OneRoster note: Not claimed. Acadio explicitly positions away from K-12, where OneRoster concentrates. compliance_certifications: published: false note: >- No SOC 2, ISO 27001, HIPAA, FedRAMP or PCI attestation, and no trust center, is published on any Acadio surface. Searched 2026-09-06; nothing found. No Compliance pointer is emitted.