generated: '2026-09-19' method: searched source: >- Live probes on 2026-09-19 (402 challenges, 429, security.txt, agent card, JSON-RPC endpoint) plus the two published OpenAPI documents, llms.txt, and the @agentum/mcp-server source (index.js, manifest.json, server.json). Every `conforms: true` below points at the exact document or response where the standard is declared or observed; nothing is asserted from prose alone. standards: - id: x402-v2 name: x402 payment protocol, version 2 (exact scheme) conforms: true evidence: >- Every documented paid route answers HTTP 402 with a PAYMENT-REQUIRED header (base64 JSON) and a JSON body whose x402Version is 2, accepts[0].scheme "exact", network "eip155:8453", asset USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, maxTimeoutSeconds 300 — observed on GET https://agentum.lat/taxas-brasil, /verificar-cnpj, /fx-rates, POST /business-intelligence, GET https://business.agentum.lat/company-intelligence and /preflight. A negative-control path returns a plain 404 with no challenge. The provider's own client (@agentum/mcp-server) settles with @x402/fetch 2.x. - id: x402-bazaar-discovery name: x402 Bazaar discovery extension conforms: true evidence: >- The 402 body carries extensions.bazaar.info {input: {type http, method, queryParams|body}, output: {type json, example}} and extensions.bazaar.schema (JSON Schema 2020-12 describing input/output), on every route probed; llms.txt states "Discovery: extensão Bazaar do x402 habilitada em todas as rotas pagas" and the homepage marks each route "x402 DISCOVERABLE". Note: as of 2026-09-19 no AGENTUM resource appears in the first page of the CDP Bazaar index (api.cdp.coinbase.com/platform/v2/x402/discovery/resources, 14,957 resources) nor on x402-list.com (25 services) — the extension is served, indexing was not verified. - id: caip-2 name: CAIP-2 chain identifiers conforms: true evidence: The challenge names the network as the CAIP-2 identifier "eip155:8453" (Base mainnet); llms.txt and both OpenAPI x-guidance strings use the same form. - id: ietf-ratelimit-headers name: IETF RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: true evidence: 'RateLimit-Policy: 10;w=60, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset on every response from agentum.lat (120;w=60 on business.agentum.lat); see rate-limits/agentum-lat-rate-limits.yml.' - id: http-429-retry-after name: HTTP 429 Too Many Requests with Retry-After (RFC 6585 / RFC 9110) conforms: true evidence: Eleventh request inside one minute to https://agentum.lat/taxas-brasil returned 429 with Retry-After 60 and a JSON body. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: true evidence: https://agentum.lat/.well-known/security.txt (200, text/plain) carries the two REQUIRED fields, Contact (mailto) and Expires (2027-01-01T00:00:00Z). No Policy, Encryption, Canonical or signature. Saved to well-known/agentum-lat-security.txt. - id: llms-txt name: llms.txt conforms: true evidence: https://agentum.lat/llms.txt (200, text/plain) — H1, blockquote summary, route list, MCP and security sections. Saved to llms/agentum-lat-llms.txt. - id: openapi-3.1 name: OpenAPI 3.1.0 conforms: true evidence: >- https://agentum.lat/openapi.json (info.title "AGENTUM — APIs Brasil", 4 operations, unique operationIds, summaries, tags, 200 + 402 responses with response schemas and examples) and https://business.agentum.lat/openapi.json (info.title "AGENTUM Business", 3 operations, 200/400/402 plus 404 or 502). Neither declares components or securitySchemes (there is no authentication); both carry a vendor extension x-payment-info {price {mode fixed, currency USD, amount}, protocols [{x402: {}}]} per operation. The apis.lat document is partial by the provider's own statement (llms.txt). - id: a2a-1.0-agent-card name: A2A 1.0 Agent Card at /.well-known/agent-card.json conforms: true evidence: https://business.agentum.lat/.well-known/agent-card.json (200, application/json) — supportedInterfaces[0] {url, protocolBinding JSONRPC, protocolVersion "1.0"}, capabilities object, skills array; graded conformant in a2a/agentum-lat-a2a.yml. The JSON-RPC root enforces the version (-32009 VERSION_NOT_SUPPORTED without an A2A-Version 1.0 header). - id: mcp-server-json name: MCP server.json (static.modelcontextprotocol.io schema 2025-12-11) and stdio transport conforms: true evidence: server.json in github.com/orionlabsai/agentum-mcp-server declares name io.github.orionlabsai/agentum-mcp-server, npm package @agentum/mcp-server 1.2.4, transport stdio, environment variable AGENTUM_MCP_WALLET_KEY (isSecret). Eleven tools registered with zod inputSchema/outputSchema and MCP tool annotations. - id: oauth2 conforms: false evidence: No securitySchemes in either OpenAPI, no /.well-known/oauth-authorization-server or oauth-protected-resource on any host (well-known/). The API has no authentication; access is gated by payment. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc9457-problem-details conforms: false evidence: 'Errors are ad hoc JSON: {"error":"PAYMENT_REQUIRED","message":"Payment required"} (business), {} (apis brasil 402), {"error":"muitas tentativas — espera um pouco"} (429); no application/problem+json. See errors/agentum-lat-problem-types.yml.' - id: json-api conforms: false evidence: Plain JSON objects, no JSON:API envelope. - id: pagination conforms: false evidence: Every operation returns a single object; no list endpoints. - id: idempotency-key conforms: false evidence: No Idempotency-Key header or equivalent in either contract; the surface is read-only queries paid per call (conventions/agentum-lat-conventions.yml). domain_standards: - id: iso-17442-lei name: ISO 17442 Legal Entity Identifier (GLEIF) conforms: true evidence: >- openapi/agentum-lat-business-openapi.json#preflight — parameter q description "CNPJ brasileiro (14 dígitos, com ou sem máscara), código LEI (20 caracteres) ou nome de empresa" and response entity.identifier {type, value} with query.type enum [cnpj, lei, name]; the company-enrich route (llms.txt: "Identificação global de empresa via LEI (GLEIF)") and MCP tool company_enrich input lei "Código LEI de 20 caracteres". The contract accepts and returns the LEI identifier scheme; it does not implement the GLEIF API itself. - id: iso-4217-currency-codes conforms: true evidence: >- The fx-rates route's Bazaar schema (served in its 402 challenge) and the MCP tool fx_rates describe base as "Moeda base (código ISO 4217, ex: USD)" and symbols as comma-separated ISO codes. - id: eu-vies-vat-number name: EU VAT identification number validation (VIES) conforms: true evidence: The vat-validate route (llms.txt "Validação de VAT europeu em tempo real (VIES, oficial da UE)") and MCP tool vat_validate {country, vat "Número de VAT, sem o prefixo do país"}; live GET returns the x402 challenge. Not in the published OpenAPI. - id: br-cnpj name: Brazilian CNPJ (Receita Federal company registry number) conforms: true evidence: openapi/agentum-lat-apis-brasil-openapi.json#verificarCnpj parameter cnpj "CNPJ brasileiro, 14 dígitos, apenas números"; #businessIntelligence requestBody.cnpj; openapi/agentum-lat-business-openapi.json#company, #companyIntelligence. Response fields razao_social/razaoSocial, situacao/situacaoCadastral, natureza_juridica, cnaePrincipal (CNAE activity classification), simplesNacional, porte. - id: br-cep name: Brazilian CEP postal code conforms: true evidence: openapi/agentum-lat-apis-brasil-openapi.json#verificarCep parameter cep "CEP brasileiro, 8 dígitos, apenas números"; response cep, logradouro, bairro, municipio, uf, regiao, ddd. - id: br-cpf name: Brazilian CPF check-digit validation conforms: true evidence: validar-cpf route (llms.txt, homepage) and MCP tool validar_cpf input cpf "CPF brasileiro, 11 dígitos"; check-digit arithmetic only, no lookup. Not in the published OpenAPI. - id: br-bcb-sgs name: Banco Central do Brasil SGS series (Selic, CDI, PTAX commercial dollar) conforms: true evidence: openapi/agentum-lat-apis-brasil-openapi.json#taxasBrasil response {selic_meta_aa, cdi_ad, dolar_comercial_venda} each {valor, data, unidade}, fonte "Banco Central do Brasil (SGS)". - id: br-public-integrity-registries name: Brazilian public-integrity registries (TCU, CEIS, CNEP, CNJ/CNIA, CVM) conforms: true evidence: openapi/agentum-lat-business-openapi.json#companyIntelligence description and findings[].source/sourceType enum [official_api, official_dataset]; #preflight components[].source and flags[].source. not_applicable: - fhir - fapi - scim - odata - psd2 - openrtb - sparkplug - activitypub - lti - oai-pmh - hl7v2 - iso-20022 compliance_program: null note: No certifications (SOC 2, ISO 27001, PCI DSS, LGPD program) or trust center are published; no Compliance pointer is emitted.