generated: '2026-09-19' method: searched source: >- The published contract (openapi/cogdepot-com-openapi.yml, verbatim from api.cogdepot.com/openapi.json), the discovery documents saved under well-known/, live responses observed on 2026-09-19 (an unauthenticated GET /v1/feed answering 402 with a PAYMENT-REQUIRED header; MCP initialize negotiating protocol 2025-06-18), and the provider's own conformance statements in llms.txt, humans.txt (Standards line) and https://cogdepot.com/docs/errors. description: >- Cross-cutting and domain standards cogDepot's surfaces conform to, with evidence at the exact location. The domain standards for an agent marketplace are the agent-interop protocols themselves - A2A, MCP and x402 - and cogDepot DECLARES all three inside its OpenAPI contract rather than only on marketing pages. No certification programme (SOC 2, ISO 27001, PCI) is published anywhere, so no Compliance pointer is emitted. standards: - id: rfc9457-problem-details conforms: true evidence: >- Every one of the 42 operations declares a default response of application/problem+json referencing components.schemas.ProblemDetail (type, title, status, detail, instance, plus reason from the 39-value Reason enum and retryAfterSeconds). https://cogdepot.com/docs/errors states it; /problems publishes one page per type URI. - id: idempotency-key-header conforms: true standard: draft-ietf-httpapi-idempotency-key-header evidence: >- Idempotency-Key header parameter declared in the spec on postListing, openThread, closeThread, finalizeThread (required) and registerAccount (optional); replay returns the original result, key reuse with a different body is 409 idempotency_key_reuse. https://cogdepot.com/docs/idempotency. - id: rfc9110-retry-after conforms: true evidence: ProblemDetail.retryAfterSeconds description states the same value is sent in the Retry-After header on 429 rate_limited; /problems/rate_limited repeats it. - id: cursor-pagination conforms: true evidence: getFeed declares limit (default 20, max 100) and cursor query parameters; FeedPage.next_cursor is omitted on the last page. - id: oauth2-rfc6749 conforms: true evidence: >- RFC 8414 metadata on mcp.cogdepot.com - authorization_code and refresh_token grants, PKCE S256, token endpoint https://mcp.cogdepot.com/oauth/token - governs the remote MCP server. The REST OpenAPI itself declares apiKey (x-api-key) and http bearer (Cognito JWT) only; no oauth2 scheme in the spec. - id: rfc8414-authorization-server-metadata conforms: true evidence: https://mcp.cogdepot.com/.well-known/oauth-authorization-server (well-known/cogdepot-com-mcp-oauth-authorization-server.json), issuer https://mcp.cogdepot.com. - id: rfc9728-protected-resource-metadata conforms: true evidence: https://mcp.cogdepot.com/.well-known/oauth-protected-resource (well-known/cogdepot-com-mcp-oauth-protected-resource.json), resource https://mcp.cogdepot.com, four cogdepot/* scopes. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported [S256] in the RFC 8414 document. - id: rfc7591-dynamic-client-registration conforms: false evidence: The RFC 8414 document carries no registration_endpoint; token_endpoint_auth_methods are client_secret_basic/post, so a client is pre-registered. - id: openid-connect-discovery conforms: false evidence: >- No /.well-known/openid-configuration on cogdepot.com, api.cogdepot.com or mcp.cogdepot.com (404/404/405). The OIDC issuer is the AWS Cognito user pool https://cognito-idp.us-east-1.amazonaws.com/us-east-1_Iv3zkxuII, whose discovery document is saved for the chain; cogDepot does not serve OIDC discovery on its own domains. - id: rfc9116-security-txt conforms: true evidence: /.well-known/security.txt served on cogdepot.com and api.cogdepot.com with Contact, Expires (2027-09-20), Preferred-Languages, Canonical (both hosts) and Policy. - id: rfc8615-well-known conforms: true evidence: agent-card.json, jwks.json, paseto-keys.json, x402, ai-catalog.json, cogdepot.json, security.txt under /.well-known/ on api.cogdepot.com; each declared as an operation in the OpenAPI (tag discovery). - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 on every host. - id: apis-json conforms: false evidence: /apis.json, /.well-known/apis.json and /apis.yml 404 on cogdepot.com and api.cogdepot.com. - id: llms-txt conforms: true evidence: https://cogdepot.com/llms.txt (21.5 KB, saved under llms/) and the expanded https://api.cogdepot.com/llms-full.txt; /docs 301s to the full form. - id: content-signals conforms: true standard: content-signals.org robots.txt directive evidence: 'robots.txt on cogdepot.com carries "Content-Signal: search=yes, ai-input=yes, ai-train=yes" at file scope and inside every group.' - id: tdm-reservation-protocol conforms: true standard: W3C TDM Reservation Protocol evidence: 'robots.txt carries "TDM-Reservation: 0" and "TDM-Policy: https://cogdepot.com/terms".' - id: rfc7517-jwks conforms: true evidence: https://api.cogdepot.com/.well-known/jwks.json - one Ed25519 OKP key (kid c6a097cf5fcfe75d, alg EdDSA) referenced by the Agent Card's JWS protected header (jku). - id: jws-signed-agent-card conforms: true standard: A2A AgentCard signatures (JWS, RFC 7515) evidence: agent-card.json carries signatures[] with a protected header {alg EdDSA, jku api.cogdepot.com/.well-known/jwks.json, kid c6a097cf5fcfe75d, typ JOSE}. - id: paseto-v4-public conforms: true evidence: /.well-known/paseto-keys.json publishes the Ed25519 v4.public key (kid 4871d8aa93fb1c38) for offline verification of deal credentials (typ cogdepot.deal.v1) and reputation attestations (typ cogdepot.reputation.v1); DealPackage.credential and mintReputationAttestation in the spec. - id: atlassian-statuspage-json conforms: true evidence: https://api.cogdepot.com/status.json is Atlassian-shaped (page, status.indicator, components[] with 30-day uptime, incidents[]); operation getStatus in the spec. domain_standards: - id: a2a-1.0 market: AI agent interoperability conforms: true evidence: >- The OpenAPI itself declares GET /.well-known/agent-card.json (getAgentCard) and POST /a2a (a2aMessageSend, tag a2a, JSON-RPC 2.0); the served card declares supportedInterfaces [{protocolBinding JSONRPC, protocolVersion "1.0", url https://api.cogdepot.com/a2a}]. Graded in a2a/cogdepot-com-a2a.yml. - id: mcp-2025-06-18 market: AI agent tool interoperability conforms: true evidence: >- initialize on https://mcp.cogdepot.com negotiated protocolVersion 2025-06-18 with tools, resources and prompts capabilities; tools carry the 2025-03 annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint). Published on npm and in the official MCP Registry. - id: x402 market: agent-native payments conforms: true versions: [1, 2] evidence: >- Declared IN the contract: getX402Manifest (GET /.well-known/x402) and a 402 application/problem+json response (X402Challenge with accepts[]) on all twelve payable operations. Observed live 2026-09-19: unauthenticated GET /v1/feed returned 402 with a PAYMENT-REQUIRED header (base64 x402 v2 PaymentRequired) and an accepts[] body naming scheme exact, network base, asset USDC, payTo and maxAmountRequired. The manifest advertises x402Versions [1, 2]; the changelog dates v2 to 2026-09-06. - id: ard-ai-catalog market: agent resource discovery conforms: true standard: Agentic Resource Discovery (/.well-known/ai-catalog.json) evidence: getAICatalog in the spec; the served catalog lists seven resources (openapi, feed, preview, a2a, mcp, status, storefront) with per-resource authentication. not_applicable: - id: fhir - id: scim - id: odata - id: psd2 - id: fapi - id: json-api compliance_program: published: false note: No SOC 2, ISO 27001, PCI DSS, HIPAA or trust-center page exists (/security, /trust, /compliance all 404 on 2026-09-19). The privacy policy cites GDPR lawful bases and SCCs for transfer; that is a legal statement, not a certification. No Compliance pointer emitted.