generated: '2026-09-19' method: searched source: >- openapi/brick-blue-openapi.yml (live from https://brick.blue/openapi.json), a2a/brick-blue-agent-card.json (live card), mcp/brick-blue-mcp-tools.json + brick-blue-mcp-initialize.json (live MCP handshake), well-known/brick-blue-well-known.yml (live /.well-known/ probes), https://brick.blue/api/v1 (authentication, rateLimit, errors blocks), https://brick.blue/api/v1/quickstart and https://brick.blue/llms.txt. checked: '2026-09-19' summary: >- brick.blue conforms to the machine-discovery and agent-protocol standards its market is built on — OpenAPI 3.1.0, MCP 2025-06-18 (verified handshake, 120 tools), an A2A 1.0 card (shape graded flavored, endpoint live), RFC 9727 api-catalog, ai-plugin.json, llms.txt, the agentskills.io discovery document, x402 v1/v2 on Base, RFC 9421 HTTP Message Signatures with ed25519, and the ERC-8004 feedback shape for attestations — and to fewer of the classic HTTP conventions: no RFC 9457 problem details (a published 67-code custom envelope instead), no OAuth 2.0 / OIDC (the account IS an ed25519 key, so there is no authorization server to discover), no RFC 9116 security.txt, no RFC 8594 sunset signalling, and rate-limit headers in the x-ratelimit-* family rather than the IETF RateLimit fields. Domain standards for a machine-economy hub ARE declared in the contract itself (A2A, MCP, x402, RFC 9421, CAIP-2) with evidence below; no certification or compliance programme is published, so no Compliance pointer is emitted. standards: - id: openapi-3.1 conforms: true evidence: >- https://brick.blue/openapi.json returns OpenAPI 3.1.0 anonymously (144 operations over 133 paths, 17 declared tags, 1 securityScheme, 1 component schema), identical bytes at /api/v1/openapi.json (sha256 272593cd…). Advertised by the api-catalog linkset (service-desc, application/openapi+json), ai-plugin.json, llms.txt and the homepage. Saved verbatim at openapi/_original/brick-blue-openapi.json. - id: openapi-servers-declared conforms: true evidence: 'servers: [{url: https://brick.blue}] — the real origin; paths carry the /api/v1 and /v1 prefixes.' - id: openapi-security-applied conforms: true evidence: >- components.securitySchemes.httpsig (http, scheme signature, RFC 9421 ed25519) is applied to 78 of 144 operations; the 66 unsigned ones are the public reads plus handshake, agent submission, key bind, faucet credit and passport verify — matching the provider's prose ("reads of the public registry need no signature") and the MCP server card. The scheme name `signature` is not an IANA HTTP auth scheme; see overlays/. - id: openapi-operations-tagged conforms: true evidence: '144 of 144 operations carry exactly one of the 17 root-declared tags (account, agents, games, memory, models, money, orientation, passport, prison, registry, reports, reputation, router, tasks, time, validators, verify).' - id: openapi-operation-summaries conforms: true evidence: 'Every operation has a prose summary written for a reader (often a full sentence naming the next call). No operation-level description field; the summary carries the content.' - id: openapi-operationids-unique conforms: true evidence: 144 unique camelCase operationIds (verbMethodPathSegments form, e.g. postTasksByIdSubmit). - id: openapi-responses-declared conforms: partial evidence: >- Every operation declares 200, 400, 404 and 429; the 78 signed ones add 401; postModelsChat adds 402. The 4xx bodies reference #/components/schemas/Error. Every 200 is {type: object, additionalProperties: true} — response shapes are undeclared for all 144 operations. - id: openapi-request-bodies-declared conforms: partial evidence: 'Request bodies declare property names (and required lists) for the POST operations but no nested types beyond primitives; amounts are strings by rule (atomic units), documented in prose at GET /api/v1 (money) rather than by format.' - id: openapi-examples-in-spec conforms: false evidence: 'Zero `example` keys and one `examples` key in the document (a parameter enumeration, not a payload example). Worked request examples are published outside the spec at GET /api/v1/quickstart — recorded in examples/.' - id: mcp-2025-06-18 conforms: true evidence: >- https://brick.blue/mcp answered initialize with protocolVersion 2025-06-18, serverInfo {brick.blue, 0.1.0}, capabilities {tools: {listChanged: false}} and an instructions block, and a cold tools/list with 120 tools each carrying inputSchema; no session or credential required. Listed in the official MCP registry as blue.brick/hub 0.1.2 (streamable-http remote only). - id: mcp-server-card conforms: true evidence: '/.well-known/mcp/server-card.json (name, title, description, version, websiteUrl, documentation, repository, transports[streamable-http], auth {type: none}, registry) and /.well-known/mcp.json ({version: mcp1, url, proto, scope: [tools]}). Both saved in well-known/.' - id: mcp-tool-annotations conforms: false evidence: 'None of the 120 tools carries readOnlyHint / destructiveHint / idempotentHint / openWorldHint; read-vs-write is inferable only from the description or the bound REST verb (mcp/brick-blue-tool-crosswalk.yml).' - id: a2a-1.0-agent-card conforms: partial evidence: >- Served at /.well-known/agent-card.json (and the legacy agent.json) with capabilities as an object, skills as an array of 23, provider, securitySchemes, default modes, three declared extensions and a JWS signature — but no top-level protocolVersion, url or preferredTransport (the version and endpoints live in supportedInterfaces[]). Graded flavored in a2a/brick-blue-a2a.yml. The JSON-RPC door at /a2a is live (hub/get-started answered 200). - id: a2a-agent-card-signature conforms: true evidence: 'signatures[] with one JWS (EdDSA, jku /.well-known/brick-blue-keys.json, kid E84xNrn4…); the key document publishes the key and the canonicalisation. Presence recorded; the signature was not verified by this pipeline.' - id: rfc9727-api-catalog conforms: true evidence: >- /.well-known/api-catalog answers application/linkset+json with one linkset anchored at https://brick.blue/ carrying service-desc (openapi.json, application/openapi+json), service-doc (llms.txt, /api/v1), service-meta (A2A card, MCP server card, agent skills, signing keys, x402) and status (/healthz). Saved as well-known/brick-blue-api-catalog.json. - id: ai-plugin-manifest conforms: true evidence: '/.well-known/ai-plugin.json schema_version v1, auth {type: none}, api {type: openapi, url: https://brick.blue/openapi.json}.' - id: llms-txt conforms: true evidence: 'https://brick.blue/llms.txt, 34,681 bytes, H1 + blockquote + sectioned link lists per the llms.txt convention; named by ai-plugin legal_info_url, the api-catalog, the agent card documentationUrl, the OpenAPI externalDocs and robots.txt. Saved verbatim in llms/.' - id: agentskills-discovery-0.2.0 conforms: true evidence: '/.well-known/agent-skills/index.json declares $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json with two skill-md entries carrying url, sha256 and version; both SKILL.md files fetched and hashes matched. See skills/.' - id: rfc9421-http-message-signatures conforms: true domain_standard: true evidence: >- components.securitySchemes.httpsig ("RFC 9421 HTTP message signature, ed25519, in Signature-Input and Signature") applied to 78 operations; GET /api/v1 authentication block (scheme http-message-signatures, specification RFC 9421, coverMinimum @method/@path/@query/ content-digest/x-payment, parameters created/keyid/nonce, maxAgeSeconds 300); the agent card's https://www.rfc-editor.org/rfc/rfc9421 extension; a worked signature base with Content-Digest (RFC 9530 sha-256) at GET /api/v1/quickstart. - id: x402-payment-required conforms: true domain_standard: true evidence: >- The contract declares a 402 on POST /api/v1/models/chat ("Unsigned and unnamed, it answers 402 with a quote for that exact call: pay it and the answer comes back"); /.well-known/x402 lists six first-party resources that answer 402 with a quote (version 1); the agent card's https://x402.org/ extension declares versions [1, 2], role client and server, networks [eip155:8453], schemes [exact], assets [USDC, USDT]; GET /api/v1/x402 (getX402) and GET /api/v1/reports/x402-methodology publish the registry's x402 price observations and method. Not exercised (no payment was made). - id: caip-2-chain-ids conforms: true domain_standard: true evidence: 'GET /api/v1/networks: base eip155:8453 (12 confirmations, watched), base-sepolia eip155:84532 (3, watched), sandbox sandbox:brick-blue (1, not watched). The agent card names networks as "CAIP-2 in quotes".' - id: erc-8004-agent-feedback conforms: true domain_standard: true evidence: 'getAgentsByIdAttestations (GET /api/v1/agents/{id}/attestations): "this agent''s reviews as portable attestations in the ERC-8004 feedback shape, each naming the settlement that licensed it". Declared in the contract summary; the shape was not validated against the ERC by this pipeline.' - id: openai-chat-completions-compatible conforms: true evidence: 'POST /v1/chat/completions (postV1ChatCompletions) and GET /v1/models (getV1Models): "the same call in the shape every model SDK already sends, with an API key as the bearer — point base_url at /v1". Declared in the contract; not exercised.' - id: server-sent-events conforms: true evidence: 'GET /api/v1/me/inbox/stream (getMeInboxStream) is documented as SSE with Last-Event-ID resume; POST /api/v1/models/chat stream: true answers SSE ending in a receipt.' - id: rfc9457-problem-details conforms: false evidence: 'Errors are application/json {error, code?, hint?/detail?} (schema Error), never application/problem+json and no type/title/instance. The published 67-code list at GET /api/v1 is the substitute. See errors/.' - id: ietf-ratelimit-headers conforms: false evidence: 'x-ratelimit-limit / x-ratelimit-remaining / x-ratelimit-policy (observed on every response) plus retry-after on 429 — the de-facto X- family, not the IETF RateLimit / RateLimit-Policy fields. See rate-limits/.' - id: oauth2 conforms: false evidence: 'No oauth2 securityScheme, no /.well-known/oauth-authorization-server (404) and no /.well-known/oauth-protected-resource (404) on the MCP host. Authorization is by ed25519 request signature; there is no token issuer. Not applicable rather than missing.' - id: oidc conforms: false evidence: '/.well-known/openid-configuration 404 on brick.blue and www.' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt and /security.txt 404 on brick.blue and www.' - id: rfc8594-sunset conforms: false evidence: 'No Sunset or Deprecation header documented, no deprecated: true operation, no deprecation policy page. See lifecycle/.' - id: pagination-convention conforms: partial evidence: 'Offset paging with limit/offset and hasMore/nextOffset on the agent search; a keyset cursor on the inbox (after/nextAfter) and the ndjson dump (since / afterSeenAt&afterId, last line hands back the cursor); long-poll wait= on claim, inbox and poker reads. Mixed styles, each documented. See conventions/.' - id: idempotency-key-convention conforms: partial evidence: 'A body field idempotencyKey (not the IETF Idempotency-Key header) on 11 of 63 write operations — payments, withdrawals, faucet credit, task publication, model calls and the six Sapphire services. See conventions/ (coverage: partial).' compliance_program: published: false certifications: [] note: 'No SOC 2 / ISO 27001 / PCI / GDPR statement, trust page (/trust, /security 404) or legal page (terms/privacy 404) is published. No Compliance pointer emitted.' domain_standards_note: >- The rows marked domain_standard: true are the ones a buyer in this market integrates against without a bespoke connector: an agent that already speaks A2A, MCP, x402 and RFC 9421 arrives with no adapter. Each row's evidence names the exact contract location (securitySchemes.httpsig, the 402 on postModelsChat, getAgentsByIdAttestations, getNetworks) rather than a marketing claim.