generated: '2026-08-06' method: probed source: live probes of https://www.arobiotx.com (2026-08-06) scope: >- Aro Biotherapeutics publishes no OpenAPI, AsyncAPI, GraphQL SDL or developer documentation, so there is no contract to assert API-design standards against. The entries below are limited to what was directly observed on the live host. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- POST https://www.arobiotx.com/_api/mcp with method tools/list returned HTTP 200 and a valid JSON-RPC 2.0 result containing 9 tools, each with a draft-07 inputSchema. Server issued an mcp-session-id header. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: The MCP endpoint accepts and answers JSON-RPC 2.0 envelopes. - id: json-schema-draft-07 name: JSON Schema draft-07 conforms: true evidence: Every tool inputSchema declares $schema http://json-schema.org/draft-07/schema#. - id: llmstxt name: llms.txt conforms: true evidence: >- https://www.arobiotx.com/llms.txt returns HTTP 200 text/plain with a conforming llms.txt document (H1, blockquote summary, sectioned link lists). Auto-generated by the Wix platform. - id: openapi name: OpenAPI conforms: false evidence: >- /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs and /api all miss on www.arobiotx.com; no api./developer./docs. subdomain resolves. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both return 400. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization server metadata published; the MCP endpoint uses an anonymous GenerateVisitorToken session instead of OAuth. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 400. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: No API error contract is published. x-notes: - >- No Compliance pointer is wired. Aro publishes no certifications, trust centre or compliance programme — /security, /trust and /compliance all return 404. - >- The conforming surfaces here are Wix platform defaults, not choices Aro made. Read them as "the host platform is agent-aware", not "the company runs an API programme".