generated: '2026-09-19' method: searched source: https://agentopt.app/.well-known/agent-card.json docs: - https://agentopt.app/info - https://agentopt.app/upgrade summary: >- Priorflow's conformance profile is a single agent-discovery standard and a set of explicit negatives. It publishes an A2A agent card that passes every A2A 1.0.0 hard check (graded conformant in a2a/agentopt-app-a2a.yml) while stating in the card itself that no A2A runtime and no MCP server stand behind it; the actual interaction is a proprietary JSON call to POST /v1/select. It declares no OpenAPI, no OAuth/OIDC, no RFC 9457 problem details, no RFC 9116 security.txt, no RFC 9727 API catalog, no RFC 9728 protected-resource metadata and no RFC 8594 sunset signalling. No certifications or compliance programme are published, so no Compliance pointer is emitted. There is no domain standard for agent-selection ranking to declare; the reward-only domain_standard_conformance slot is left empty rather than filled. standards: - id: a2a name: Agent2Agent protocol (agent card) version: '1.0 (as declared)' conforms: true scope: agent card only evidence: >- a2a/agentopt-app-agent-card.json — protocolVersion "1.0", capabilities object, skills[] of 2, url https://agentopt.app, defaultInputModes/defaultOutputModes present; served at both /.well-known/agent-card.json and /.well-known/agent.json (200, application/json, 8,377 bytes). Graded conformant in a2a/agentopt-app-a2a.yml. caveat: >- The card declares a2a_runtime.enabled false and interaction "POST /v1/select JSON skill", and /ready reports a2a_runtime_enabled false, so no A2A JSON-RPC method (message/send, tasks/get) is served. Conformance is of the discovery document, not of an agent runtime. Not live-tested: robots.txt disallows /a2a and /v1/. - id: a2a-runtime name: A2A JSON-RPC runtime (message/send, tasks/*) conforms: false evidence: 'card priorflow.a2a_runtime {enabled: false, endpoint: null, methods: []}; not_full_a2a_runtime true; /ready a2a_runtime_enabled false; /a2a disallowed in robots.txt' - id: mcp name: Model Context Protocol conforms: false evidence: 'card not_an_mcp_server true, mcp_server {enabled: false, endpoint: null, tools: [], transport: null}; /ready mcp_enabled false; GET /mcp 404 and disallowed in robots.txt' note: An explicit, provider-stated negative. No mcp/ artifact is written and no MCPServer or X-MCPServerCandidate pointer is emitted — there is no OpenAPI to derive a candidate from and the operator says the adapter is off. - id: openapi conforms: false evidence: '/openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /docs, /redoc, /api-docs all 404 (uvicorn/FastAPI host with auto-docs disabled). The card''s priorflow.api block is the only machine-readable description of POST /v1/select.' - id: rfc8615-well-known name: RFC 8615 well-known URIs conforms: true evidence: The agent card is served at the RFC 8615 path /.well-known/agent-card.json (well-known/agentopt-app-well-known.yml). - id: oauth2 conforms: false evidence: 'Card securitySchemes declares apiKey only; /.well-known/oauth-authorization-server 404.' - id: oidc conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc9728-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource 404; no MCP resource server exists to carry it. - id: rfc9457-problem-details conforms: false evidence: 'Errors are FastAPI {"detail": ...} objects (observed on 404) and, per the docs, JSON bodies with a vendor upgrade object on 402/429. No application/problem+json. See errors/agentopt-app-problem-types.yml.' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt both 404. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog and /.well-known/api-catalog.json both 404. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json all 404. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header documented; no deprecation policy (lifecycle/agentopt-app-lifecycle.yml). - id: llms-txt conforms: false evidence: /llms.txt and /llms-full.txt both 404; llms/agentopt-app-llms.txt is generated by API Evangelist, not provider-authored. - id: robots-txt name: robots.txt (Robots Exclusion Protocol) conforms: true evidence: 'https://agentopt.app/robots.txt 200 — Allow / plus /info /try /upgrade /status /explore /v1/public/; Disallow /upgrade/success /ops /v1/ /mcp /a2a. Honored by this pass.' - id: idempotency conforms: false applicability: na evidence: 'The API surface is a read (select); no Idempotency-Key exists on the one write (billing checkout). conventions/agentopt-app-conventions.yml records coverage na.' - id: pagination conforms: false applicability: na evidence: A select returns at most top_n results; no paging. compliance_programme: published: false evidence: 'No trust center, certification, terms of service or privacy policy found (/security, /terms, /privacy, /legal 404; probe-security-programs.py vdp=none trust=none).'