generated: '2026-08-30' method: derived source: openapi/agentic-ai-foundation-mcp-registry-openapi.yaml, json-schema/agentic-ai-foundation-mcp-protocol-schema.json, a2a/agentic-ai-foundation-agent-card.json, live probes 2026-08-30 provider: Agentic AI Foundation providerId: agentic-ai-foundation description: >- Standards conformance for the Agentic AI Foundation. AAIF is unusual in this catalog: it is a standards body, so most of the entries below are standards it AUTHORS rather than merely consumes. Each entry cites the exact artifact location that evidences it. standards: - id: openapi-3.1 name: OpenAPI 3.1.0 conforms: true evidence: >- openapi/agentic-ai-foundation-mcp-registry-openapi.yaml declares openapi: 3.1.0 and parses; served live from https://registry.modelcontextprotocol.io/openapi.yaml with content-type application/openapi+yaml (HTTP 200). - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: true evidence: >- Every one of the 32 operations declares application/problem+json on its `default` response via the ErrorModel schema (type/title/status/detail/instance/errors). Confirmed on the wire: GET https://registry.modelcontextprotocol.io/.well-known/security.txt returned 404 with content-type application/problem+json and a populated body. - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: >- The registry contract sets jsonSchemaDialect https://json-schema.org/draft/2020-12/schema, and the MCP protocol schema saved at json-schema/agentic-ai-foundation-mcp-protocol-schema.json declares the same $schema. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- MCP is a JSON-RPC 2.0 protocol. Confirmed live: POST https://modelcontextprotocol.io/mcp with a jsonrpc 2.0 tools/list envelope returned a jsonrpc 2.0 result (HTTP 200, text/event-stream). - id: rfc9116 name: RFC 9116 security.txt conforms: false partial: true evidence: >- https://modelcontextprotocol.io/.well-known/security.txt returns 200 with a Contact: field but no Expires: field, which RFC 9116 section 2.5.5 makes REQUIRED. Every other AAIF host 404s. - id: oauth2 name: OAuth 2.0 conforms: false partial: true evidence: >- The registry CONSUMES a GitHub OAuth access token at POST /v0.1/auth/github-at (GET /v0/health returns a github_client_id), but it publishes no authorization server: /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on every host including the versioned /v0 and /v0.1 prefixes. Its own scheme is a bearer JWT, not OAuth. - id: oidc name: OpenID Connect conforms: false partial: true evidence: >- POST /v0.1/auth/oidc and /v0.1/auth/github-oidc accept OIDC ID tokens, so the registry is an OIDC relying party. It is not a provider — no /.well-known/openid-configuration is served anywhere. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation header observed on any probed response; no deprecation policy published. - id: pagination name: Cursor pagination conforms: true evidence: >- GET /v0.1/servers takes cursor + limit (default 30, max 100) and returns Metadata{count, nextCursor}. updated_since + include_deleted additionally provide an incremental-sync contract. - id: idempotency name: Client-supplied idempotency keys conforms: false evidence: >- No Idempotency-Key header anywhere in the contract and no idempotency documentation. See conventions/agentic-ai-foundation-conventions.yml. domain_standards: note: >- AAIF's market IS agent interoperability, and its domain standards are the ones it stewards. These are declared by the contracts in this repo, not asserted from a marketing page. standards: - id: mcp name: Model Context Protocol relationship: authors revision: '2026-07-28' conforms: true evidence: >- json-schema/agentic-ai-foundation-mcp-protocol-schema.json is the project's own normative JSON Schema for the 2026-07-28 revision, fetched verbatim from raw.githubusercontent.com/modelcontextprotocol/modelcontextprotocol/main/schema/2026-07-28/schema.json. A live conforming server is answering at https://modelcontextprotocol.io/mcp. - id: a2a name: Agent2Agent (A2A) relationship: hosts conforms: true grade: conformant evidence: >- a2a/agentic-ai-foundation-agent-card.json — served at the canonical /.well-known/agent-card.json on modelcontextprotocol.io, protocolVersion 0.3, capabilities is an object, skills is an array. Graded in a2a/agentic-ai-foundation-a2a.yml. - id: agents-md name: AGENTS.md relationship: hosts conforms: true evidence: >- AGENTS.md is an AAIF-hosted project (https://aaif.io/projects/agents-md, https://agents.md/), and an AAIF project repository ships one: https://raw.githubusercontent.com/aaif-goose/goose/main/AGENTS.md returned HTTP 200 and a real "AGENTS Instructions" document (5,278 bytes) when probed 2026-08-30. - id: agent-skills name: Agent Skills relationship: publishes conforms: true evidence: >- Two skill.md documents served under /.well-known/agent-skills/ on modelcontextprotocol.io, both with valid frontmatter (name, description, arguments), saved in skills/. - id: acp name: Agent Client Protocol relationship: consumes conforms: true evidence: >- goose exposes `goose acp` — run as an ACP agent server over stdio (https://goose-docs.ai/docs/guides/goose-cli-commands). compliance: certifications_published: false trust_center: false detail: >- No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim appears on any AAIF host, and no trust center exists. This is expected: AAIF is a Linux Foundation standards body, not a data processor, and its projects are self-hosted software rather than a managed service. maintainers: - FN: Kin Lane email: info@apievangelist.com