generated: '2026-09-19' method: searched source: openapi/afmr-ai-discovery-api-openapi.yml + live probes of afmr.ai (2026-09-19) + https://afmr.ai/.well-known/afmr.json + https://afmr.ai/server.json + https://afmr.ai/.well-known/agent-card.json + https://afmr.ai/standards/reputation-attestation/0.1/schema.json standards: - id: openapi-3.1 conforms: true evidence: https://afmr.ai/openapi.json declares openapi 3.1.0 with 21 paths / 22 operations, every operation carrying an operationId and summary; advertised as Link rel="service-desc" on the homepage. - id: rfc9457-problem-details conforms: true evidence: Observed live — GET /nope returns 404 application/problem+json {type, title, status, detail, instance}; GET /mcp returns 405 application/problem+json with Allow header; the spec declares components.schemas.Problem and a MethodNotAllowed problem+json response. - id: rfc9116-security-txt conforms: true evidence: https://afmr.ai/.well-known/security.txt (200) with Contact, Canonical, Expires 2027-07-30, Preferred-Languages — no Policy/Encryption fields. - id: rfc8615-well-known conforms: true evidence: security.txt, ai-plugin.json, agent-card.json, agent.json, afmr.json and mcp.json all served under /.well-known/. - id: rfc8288-web-linking conforms: true evidence: Homepage response carries Link relations canonical, alternate (llms.txt, llms-full.txt, resources.json), describedby (afmr.json), service-desc (openapi.json), service-meta (agent-card.json), license; every problem response carries Link rel="describedby". - id: mcp-2025-11-25 conforms: true evidence: POST https://afmr.ai/api/rpc initialize returns protocolVersion 2025-11-25 with tools + resources capabilities; tools/list returns 4 tools with JSON Schema inputSchemas and readOnly/idempotent annotations; listed in the official MCP Registry as ai.afmr/discovery 1.0.1. - id: mcp-server-json-2025-12-11 conforms: true evidence: https://afmr.ai/server.json validates against $schema https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json (two streamable-http remotes). - id: a2a-1.0 conforms: true evidence: /.well-known/agent-card.json is A2A 1.0-shaped (supportedInterfaces[0] JSONRPC 1.0, capabilities object, 4 skills); POST /a2a SendMessage answered 200 with a ROLE_AGENT message. See a2a/afmr-ai-a2a.yml (grade conformant). - id: openai-ai-plugin-manifest-v1 conforms: true evidence: /.well-known/ai-plugin.json schema_version v1, auth.type none, api.type openapi -> https://afmr.ai/openapi.json. - id: json-schema-2020-12 conforms: true evidence: The Reputation Attestation schema declares $schema https://json-schema.org/draft/2020-12/schema (json-schema/afmr-ai-reputation-attestation-0.1-schema.json); status.json records the Lift public-card schemas validate as draft 2020-12. - id: json-ld-schema-org conforms: true evidence: /.well-known/afmr.json is a schema.org DataCatalog (@context, @id, @type); status.json is a schema.org Dataset; evidence/index.json a DataCatalog; the AFMR 1.0 index publishes a JSON-LD context (wulfkaal.github.io/afmr/context.jsonld). - id: llms-txt conforms: true evidence: https://afmr.ai/llms.txt (200, H1 + blockquote + H2 link sections) and llms-full.txt; advertised in robots.txt, sitemap.xml and Link rel="alternate". - id: atom-1.0 conforms: true evidence: https://afmr.ai/feed.xml is an Atom feed (application/atom+xml) with two dated entries. - id: cors conforms: true evidence: access-control-allow-origin "*" with allow-methods GET, HEAD, OPTIONS and expose-headers ETag, Last-Modified, Link on every response. - id: oauth2 conforms: false evidence: No securitySchemes in the OpenAPI; /.well-known/oauth-authorization-server 404. All surfaces are unauthenticated public read-only by design. - id: rfc9728-protected-resource-metadata conforms: false evidence: /.well-known/oauth-protected-resource 404 on the MCP host (afmr.ai). Not applicable to an unauthenticated server, but recorded as absent. - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation headers observed; no deprecation policy published. - id: apis-json conforms: false evidence: /apis.json, /.well-known/apis.json and /apis.yml all 404 (problem+json). - id: rfc8414-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server 404. domain_standards: note: >- AFMR is itself a standards publisher for agent governance. The domain standards its contract DECLARES for that market are the agent-protocol ones above (A2A 1.0 agent card, MCP 2025-11-25 server + Registry manifest, ai-plugin v1) plus its own profile: the Reputation Attestation schema pins const type "AFMRReputationAttestation" and const profile "https://afmr.ai/standards/reputation-attestation/0.1" (schema.json properties.type / .profile). No SCIM/OData/FHIR/etc. applies to this market, and none is claimed. declared: - id: a2a-agent-card location: /.well-known/agent-card.json (supportedInterfaces[0].protocolVersion "1.0") - id: mcp-server-card location: /.well-known/mcp.json + /server.json ($schema server.schema.json 2025-12-11) - id: afmr-reputation-attestation-0.1 location: json-schema/afmr-ai-reputation-attestation-0.1-schema.json ($id, const type, const profile) compliance_certifications: [] compliance_note: No SOC 2 / ISO 27001 / trust-center claims are published anywhere on afmr.ai; no Compliance pointer is emitted.