generated: '2026-08-29' method: derived source: >- Derived from openapi/autogpt-external-api-openapi.json, openapi/autogpt-agent-server-openapi.json, https://agpt.co/docs/platform/api-and-integrations/oauth-guide.md and https://agpt.co/docs/integrations/block-integrations/block.md; live probes of https://backend.agpt.co and the /.well-known/ paths on 2026-08-29. description: >- Which cross-cutting and domain standards the AutoGPT Platform contract actually conforms to, each with the evidence that decided it. AutoGPT's real standards story is on the CLIENT side — it speaks MCP fluently as a consumer — while its own published API conforms to OpenAPI and OAuth 2.0 and little else. standards: - id: openapi name: OpenAPI Specification version: 3.1.0 conforms: true evidence: >- Two documents published and parsing: /openapi.json (AutoGPT Agent Server, 293 paths / 347 operations / 458 schemas) and /external-api/openapi.json (AutoGPT External API, 20 operations / 36 schemas), both HTTP 200 from https://backend.agpt.co on 2026-08-29. - id: oauth2 name: OAuth 2.0 authorization code grant conforms: true evidence: >- Documented flow with client_id, redirect_uri, scope, state and response_type=code, exchanged at POST /api/oauth/token for an agpt_xt_ access token plus a refresh token. https://agpt.co/docs/platform/api-and-integrations/oauth-guide.md - id: rfc7636 name: PKCE (Proof Key for Code Exchange) conforms: true evidence: >- code_challenge and code_challenge_method are both marked Required in the authorization request table, and code_challenge_method "Must be S256". code_verifier is required at the token exchange. - id: rfc7662 name: OAuth 2.0 Token Introspection conforms: partial evidence: >- POST /api/oauth/introspect exists and is unauthenticated at the operation level in the spec. The response schema is not published as an RFC 7662 introspection response, so conformance to the response shape is unverified. - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: partial evidence: >- POST /api/oauth/revoke exists. The request/response shape is not documented against RFC 7009. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns 404 on agpt.co, platform.agpt.co and backend.agpt.co (probed 2026-08-29). The authorization server is real but undiscoverable. - id: oidc name: OpenID Connect conforms: false evidence: >- /.well-known/openid-configuration 404 on all three hosts. AutoGPT offers "Sign in with AutoGPT" via the IDENTITY OAuth scope rather than OIDC id tokens; there is no openIdConnect securityScheme in either spec. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json anywhere in either spec. Errors use FastAPI's {"detail":...} and an AutoGPT {"message","detail","hint"} envelope. See errors/autogpt-problem-types.yml. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: >- 404 on all three hosts. A real disclosure policy exists in the repo's SECURITY.md — see security/autogpt-vulnerability-disclosure.yml. - id: rfc8594 name: RFC 8594 Sunset header / Deprecation header conforms: false evidence: No Sunset or Deprecation response header declared in either spec; no deprecated:true flags. - id: idempotency name: Idempotency-Key (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: >- No Idempotency-Key parameter or header in 613KB of contract. One operation (finalize_brain_dump) is naturally idempotent per recording_id; the credit-spending execute operations are not. See conventions/autogpt-conventions.yml. - id: ratelimit-headers name: draft-ietf-httpapi-ratelimit-headers conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers observed on live 200/401/422 responses from https://backend.agpt.co on 2026-08-29, and none declared in either spec. - id: pagination name: Consistent pagination contract conforms: partial evidence: >- Three idioms coexist across the Agent Server API — page/page_size (16 operations), limit/offset (9), and bare limit (23). No cursor pagination, no Link header. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on all three hosts (probed 2026-08-29). No agent card is published. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document published. Event surfaces exist (inbound provider webhooks, websocket streaming) but are undescribed. See asyncapi/autogpt-webhooks.yml. domain_standards: - id: mcp name: Model Context Protocol role: client conforms: true evidence: >- The MCP Tool block "uses JSON-RPC 2.0 over HTTP to communicate with MCP servers. When configuring, it sends an initialize request followed by tools/list to discover available tools and their input schemas. On execution, it calls tools/call". Transport is Streamable HTTP. Auth is OAuth 2.0 with PKCE and automatic token refresh. Backed by POST /api/mcp/discover-tools, /api/mcp/oauth/login, /api/mcp/oauth/callback and /api/mcp/token in openapi/autogpt-agent-server-openapi.json. source: https://agpt.co/docs/integrations/block-integrations/block.md note: >- This is genuine MCP conformance in the consumer direction. AutoGPT publishes NO MCP server of its own — see mcp/autogpt-mcp.yml. The distinction matters: an agent cannot call AutoGPT over MCP, but AutoGPT can call anything over MCP. - id: agent-skills name: Agent Skills (SKILL.md) role: host conforms: partial evidence: >- POST /api/skills accepts "a SKILL.md file" and GET /api/skills/{name} returns "the full SKILL.md body", so the platform stores and executes SKILL.md-shaped copilot skills. The format it validates against is not published, and the skills surface is on the undocumented Agent Server API rather than the External API. - id: prometheus name: Prometheus exposition format conforms: true evidence: >- GET /external-api/metrics ("Metrics", tag monitoring) and GET /api/store/metrics/cache ("Get cache metrics in Prometheus format"). sector_standards_checked: note: >- AutoGPT sells agent automation, a market with no ratified interchange standard. SCIM, OData, OpenRTB, Sparkplug, ActivityPub, LTI/OneRoster, OAI-PMH, HL7v2, X12 and ISO 20022 were all checked against the contract and none applies. REWARD-ONLY dimension — recorded as not-applicable, not as a failure. applicable: false certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published. trust.agpt.co does not resolve; agpt.co/trust, /security and /compliance all 404 (probed 2026-08-29). No Compliance pointer is emitted. maintainers: - FN: Kin Lane email: kin@apievangelist.com