generated: '2026-08-02' method: probed source: - https://www.brooklinen.com/.well-known/ucp - https://www.brooklinen.com/.well-known/oauth-authorization-server - https://www.brooklinen.com/.well-known/oauth-protected-resource - https://www.brooklinen.com/agents.md standards: - id: ucp-2026-04-08 name: Universal Commerce Protocol, version 2026-04-08 conforms: true evidence: >- /.well-known/ucp declares ucp.version 2026-04-08 with a version-specific profile document, the dev.ucp.shopping service over MCP transport, and eight negotiated capabilities. spec: https://ucp.dev/2026-04-08/specification/overview/ - id: ucp-2026-01-23 name: Universal Commerce Protocol, version 2026-01-23 conforms: true evidence: Listed in /.well-known/ucp `supported_versions` with its own profile document. - id: mcp name: Model Context Protocol conforms: true evidence: >- Live JSON-RPC 2.0 MCP endpoint at https://www.brooklinen.com/api/ucp/mcp declared as services["dev.ucp.shopping"][transport=mcp].endpoint. Responds to JSON-RPC with structured JSON-RPC error objects. tools/list is gated on agent identity. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- MCP endpoint accepts and returns JSON-RPC 2.0 envelopes (jsonrpc, id, result/error). - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- Authorization code grant with refresh_token and jwt-bearer, client_secret_basic token endpoint auth, advertised at /.well-known/oauth-authorization-server. - id: rfc8414-oauth-authorization-server-metadata name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer, token_endpoint, authorization_endpoint, jwks_uri, scopes_supported and grant_types_supported. - id: rfc9728-oauth-protected-resource-metadata name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: /.well-known/oauth-protected-resource returns 200 with resource, authorization_servers and bearer_methods_supported. - id: rfc7636-pkce name: RFC 7636 Proof Key for Code Exchange conforms: true evidence: code_challenge_methods_supported includes S256. - id: oidc name: OpenID Connect conforms: partial evidence: >- The authorization server advertises an OIDC posture — issuer, jwks_uri, RS256 id_token signing, subject_types_supported, standard claims and an `openid` scope — but no /.well-known/openid-configuration document is served at the store origin (404). - id: llmstxt name: llms.txt conforms: true evidence: /llms.txt returns 200 text/markdown mirroring /agents.md. - id: agents-md name: agents.md agent instruction document conforms: true evidence: >- /agents.md returns 200 text/markdown, is referenced from /robots.txt, and is the sole entry in /sitemap_agentic_discovery.xml. - id: sitemaps-0.9 name: sitemaps.org protocol 0.9 conforms: true evidence: /sitemap.xml returns a valid sitemapindex including a dedicated agentic discovery sitemap. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 on www.brooklinen.com and on brooklinen2.myshopify.com. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json is used. The MCP surface uses JSON-RPC error objects and the UCP shopping error_response shape; the storefront surface returns bare HTTP status codes. - id: rfc8594-sunset-header name: RFC 8594 Sunset HTTP header conforms: false evidence: No Sunset or Deprecation headers observed; no deprecation policy published. - id: openapi name: OpenAPI conforms: false evidence: >- Brooklinen publishes no OpenAPI document. openapi/brooklinen-storefront-openapi.yml is generated by API Evangelist from the provider's own documented endpoint list plus live probes. - id: asyncapi name: AsyncAPI conforms: false evidence: No public event, streaming or webhook surface was found. Not applicable to this provider. - id: idempotency-key name: Idempotency-Key request header conforms: true evidence: >- meta.idempotency-key (uuid) maps to the HTTP Idempotency-Key header in the UCP shopping schema at the version Brooklinen's discovery profile declares. compliance_program: published: false note: >- No trust center, certification listing (SOC 2, ISO 27001, PCI DSS) or compliance page was found on brooklinen.com. The store publishes a CCPA notice, a do-not-sell request page and a website accessibility notice, which are consumer-privacy disclosures rather than a published security compliance program. No `Compliance` pointer is emitted. consumer_privacy_pages: - https://www.brooklinen.com/policies/privacy-policy - https://www.brooklinen.com/pages/ccpa-notice - https://www.brooklinen.com/pages/do-not-sell-request - https://www.brooklinen.com/pages/website-accessibility-notice x-evidence: fetched: '2026-08-02'