generated: '2026-08-02' method: probed source: well-known/cirkul-well-known.yml, mcp/cirkul-mcp.yml notes: >- Every assertion below is grounded in a document Cirkul serves from its own host or a live probe recorded in this repo. Cirkul makes no compliance claims of its own — there is no trust center, no certifications page and no security.txt — so no Compliance pointer is emitted. standards: - id: mcp name: Model Context Protocol conforms: true evidence: 'POST https://drinkcirkul.com/api/mcp tools/list returned HTTP 200 with a JSON-RPC 2.0 result containing 5 tools, each with a JSON Schema 2020-12 inputSchema' - id: ucp-2026-04-08 name: Universal Commerce Protocol 2026-04-08 conforms: true evidence: 'GET https://drinkcirkul.com/.well-known/ucp returned HTTP 200 declaring ucp.version 2026-04-08, the dev.ucp.shopping service over MCP transport, and eight capabilities' - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: both MCP endpoints answer with jsonrpc/id/result or jsonrpc/id/error envelopes - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: every MCP tool inputSchema declares $schema https://json-schema.org/draft/2020-12/schema - id: oauth2 name: OAuth 2.0 conforms: true evidence: /.well-known/oauth-authorization-server advertises authorization_code and refresh_token grants against the Shopify authorization server for shop 5052170330 - id: oidc name: OpenID Connect conforms: true evidence: /.well-known/openid-configuration returns an issuer, jwks_uri, RS256 id token signing and the openid/email scopes - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: '/.well-known/oauth-authorization-server returns HTTP 200 application/json' - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: '/.well-known/oauth-protected-resource returns resource, authorization_servers and bearer_methods_supported' - id: pkce name: RFC 7636 PKCE conforms: true evidence: code_challenge_methods_supported S256 - id: llmstxt name: llms.txt conforms: true evidence: 'GET /llms.txt returns HTTP 200 text/plain agent instructions; /agents.md is declared the canonical form and is listed in sitemap_agentic_discovery.xml' - id: robots-txt name: robots.txt conforms: true evidence: 'GET /robots.txt returns HTTP 200 with explicit agent-conduct rules and pointers to the UCP/MCP surfaces' - id: openapi name: OpenAPI conforms: false evidence: no OpenAPI or Swagger document found; /openapi.json, /openapi.yaml, /swagger.json, /api-docs all 404 or return the storefront HTML shell - id: graphql name: GraphQL conforms: false evidence: no first-party GraphQL endpoint published or discovered - id: asyncapi name: AsyncAPI conforms: false evidence: no event, streaming or webhook surface is published to third parties; Shopify webhooks are merchant-configured, not a Cirkul-published catalog - id: a2a name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json both returned HTTP 404 on drinkcirkul.com' - id: rfc9116 name: security.txt conforms: false evidence: '/.well-known/security.txt returned HTTP 404' - id: rfc9727 name: RFC 9727 api-catalog conforms: false evidence: '/.well-known/api-catalog returned HTTP 404' - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: no application/problem+json response observed; errors are JSON-RPC 2.0 error objects - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: no deprecation or sunset policy published compliance_program: published: false certifications: [] note: no trust center, compliance page or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA) is published on any Cirkul host. Payment card handling is delegated to Shopify and the declared payment handlers.