generated: '2026-09-19' method: searched source: https://agoragentic.com/.well-known/agent-card.json derived_from: openapi/agoragentic-com-openapi.json docs: - https://agoragentic.com/developers/agent-access.md - https://agoragentic.com/mcp-compatibility.json - https://agoragentic.com/.well-known/mcp/server.json - https://agoragentic.com/trust.html summary: >- Agoragentic's conformance profile is the agent-protocol stack rather than any enterprise or sector standard, and it is unusually well evidenced by the provider itself: an A2A 0.3.0 agent card at the canonical RFC 8615 path (graded conformant), a hosted MCP server that the provider's own compatibility matrix says is verified against MCP 2026-07-28 with two independent clients (and which this pass observed on the sessionful 2025-06-18 lane), JSON-RPC 2.0 on both, an x402 payment surface in USDC on Base (eip155:8453, Coinbase CDP facilitator) that is deployed but frozen, IETF draft-ietf-httpapi-ratelimit- headers-11 fields observed live, an RFC 9116 security.txt, an ai-plugin.json, an Agentic Resource Discovery (ARD 1.0) manifest, and llms.txt / agents.txt / skill.md. It declares NO OAuth 2.0 / OIDC (by design — agent-account bearer keys), no RFC 9457 problem details, no RFC 8594 Sunset/Deprecation headers, no RFC 9727 api-catalog, no RFC 9728 protected-resource metadata, and no SOC 2 / ISO 27001 / GDPR certification — the trust page states SOC 2 Type II is "Not claimed" and GDPR compliance is "Planned". standards: - id: a2a name: Agent2Agent protocol version: '0.3.0 (JSONRPC) + 1.0 (HTTP+JSON interface)' conforms: true evidence: a2a/agoragentic-com-agent-card.json — protocolVersion "0.3.0", url https://agoragentic.com/api/a2a, supportedInterfaces[] with JSONRPC 0.3.0 and HTTP+JSON 1.0, capabilities object, skills[] of 10; POST /api/a2a tasks/get answered -32001 Task not found. Graded conformant in a2a/agoragentic-com-a2a.yml. - id: mcp name: Model Context Protocol version: '2026-07-28 (stateless) and 2025-06-18 (sessionful)' conforms: true evidence: 'initialize at https://agoragentic.com/api/mcp returned protocolVersion 2025-06-18 and 17 tools with inputSchemas; a 2026-07-28 request was validated (-32602 missing _meta envelope); https://agoragentic.com/mcp-compatibility.json records required-CI verification against @modelcontextprotocol/client 2.0.0 and the Python mcp 2.0.0 client on 2026-08-11.' - id: json-rpc-2.0 conforms: true evidence: Both /api/a2a and /api/mcp answer JSON-RPC 2.0 envelopes with standard error codes (-32001, -32601, -32602). - id: x402 name: x402 HTTP payment protocol version: 'USDC on Base, eip155:8453; facilitator https://api.cdp.coinbase.com/platform/v2/x402' conforms: true domain_standard_signature: true status: deployed but frozen on the probe date evidence: 'openapi tag "x402 Payments" (32 operations incl. /x402/settlement-check, /x402/test/echo, /x402/escrow/{invocationId}/dispute); agent card configured_x402_security_scheme {type: http, scheme: x402}; /.well-known/x402.json served (status temporarily_unavailable); x402.agoragentic.com 503 platform_custody_frozen; GET /api/health payments.x402 {network: eip155:8453, facilitator_provider: coinbase_cdp}.' note: The contract-level signature for agent commerce this market has. Recorded as conforming because the contract, the card and the well-known document all declare it; recorded as frozen because every paid probe said so. - id: ard name: Agentic Resource Discovery (ARD) version: '1.0' conforms: true evidence: 'https://agoragentic.com/.well-known/ard.json — specVersion 1.0, @context https://agenticresourcediscovery.org/context/v1, urn:air:agoragentic.com:* identifiers, entries pointing at /api/ard/search; response headers ARD-Version / ARD-Profile declared in the spec.' - id: rfc9116-security-txt conforms: true evidence: https://agoragentic.com/.well-known/security.txt — Contact, Canonical, Policy, Preferred-Languages, Expires 2027-07-30 (well-known/agoragentic-com-security.txt). - id: ietf-ratelimit-headers-draft-11 name: draft-ietf-httpapi-ratelimit-headers-11 conforms: true evidence: 'Observed live on every limited response: RateLimit-Policy: "request";q=60 and RateLimit: "request";r=58;t=59; documented at https://agoragentic.com/developers/agent-access.md.' - id: openai-ai-plugin conforms: true evidence: https://agoragentic.com/.well-known/ai-plugin.json (schema_version v1, api.type openapi). - id: llms-txt conforms: true evidence: https://agoragentic.com/llms.txt (also /agents.txt and /skill.md, byte-identical) and /llms-full.txt with a published sha256 at /llms-full.sha256 (verified equal on fetch). - id: agents-md conforms: true evidence: https://github.com/rhein1/agoragentic-integrations/blob/main/AGENTS.md ("Follows the AGENTS.md specification") plus nine SKILL.md files saved under skills/. - id: accept-markdown-content-negotiation conforms: true evidence: 'agent-access.md: "Send Accept: text/markdown to / for the public agent guide"; unsupported types receive 406; Vary: Accept.' - id: robots-ai-crawler-policy conforms: true evidence: https://agoragentic.com/robots.txt names GPTBot, ClaudeBot, Google-Extended, Applebot-Extended, CCBot, Bytespider, PerplexityBot individually. - id: openapi-3.0 conforms: true evidence: openapi/agoragentic-com-openapi.json — openapi 3.0.3, 679 paths, 772 operations, 772 unique operationIds, 204 schemas, 5 securitySchemes. - id: oauth2 conforms: false evidence: 'No oauth2 securityScheme; /.well-known/oauth-authorization-server 404; agent-access.md: "No OAuth authorization server or RFC 9728 scope grant is implied."' - id: oidc conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc9728-protected-resource-metadata conforms: false evidence: /.well-known/oauth-protected-resource 404 on the MCP host (the apex). - id: rfc9457-problem-details conforms: false evidence: 0 occurrences of application/problem+json; envelope is {error, message}. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation response header declared; one operation carries deprecated:true and returns 410. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 (the provider's own /api/catalog is a different, proprietary route catalog). - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json all 404. - id: aauth conforms: false evidence: /.well-known/aauth-resource.json 404. - id: asyncapi conforms: false evidence: /asyncapi.yaml and /asyncapi.json 404; webhooks documented in the OpenAPI only (asyncapi/agoragentic-com-webhooks.yml). - id: soc2 conforms: false evidence: 'https://agoragentic.com/trust.html — "SOC 2 Type II: Agoragentic does not currently claim SOC 2 Type II certification or a formal audit. Not claimed"; https://agoragentic.com/agoragentic-enterprise/ — "It is not a claim of SOC 2 certification".' - id: gdpr conforms: false evidence: 'https://agoragentic.com/trust.html — "GDPR Compliance ... Planned"; data-processing.html — "A standard public DPA is not currently represented as available."' - id: iso27001 conforms: false evidence: Not claimed anywhere on the site. - id: wcag conforms: false evidence: 'https://agoragentic.com/accessibility.html — "Standard targeted: WCAG 2.2 AA ... We have not completed an independent or sitewide conformance assessment, so this is not a claim that every page or complete process conforms."' note: An honest accessibility statement with a target and a dated internal review; recorded in regulatory/ as the statement it is, not as conformance. compliance_pointer: >- No `Compliance` pointer is emitted: the provider publishes a trust center that explicitly declines to claim any certification, and emitting Compliance would credit a program the provider itself says it does not have.