generated: '2026-08-17' method: searched source: https://docs.cometh.io/llms.txt docs: - https://docs.cometh.io/quick-start/cometh-documentation - https://docs.cometh.io/advanced/session-keys/erc7579-actions - https://docs.cometh.io/advanced/capabilities - https://cometh.io/ - https://security.cometh.io/ - https://kaiko.com/news/Kaiko-Acquires-Cometh-to-Scale-MiCA-Regulated-Onchain-Data-Infrastructure note: >- Cometh's conformance story is almost entirely Ethereum-standards conformance plus an EU regulatory perimeter; the usual web-API standards (OAuth 2.0, OIDC, RFC 9457, RFC 8594, SCIM, OData, JSON:API) are all absent. Regulatory and certification claims are recorded with their source: the DASP registration and MiCA alignment are stated by Cometh on its own homepage and docs; the CASP licence number (AMF No. A2025-008) and the ISO 27001:2022 certification are stated in the acquisition announcement published by Kaiko, Cometh's acquirer. The Vanta-hosted trust centre at security.cometh.io is live (HTTP 200, title "Cometh Trust Center") but renders its certification list client-side, so the certifications could not be read from the HTML; they are attributed to the announcement instead of to the trust centre. standards: - id: erc-4337 name: ERC-4337 Account Abstraction (Bundler + Paymaster + EntryPoint) conforms: true evidence: >- Publishes an ERC-4337 bundler JSON-RPC (eth_sendUserOperation, eth_estimateUserOperationGas, eth_getUserOperationByHash, eth_getUserOperationReceipt, eth_supportedEntryPoints) and a paymaster JSON-RPC (pm_sponsorUserOperation, pm_supportedEntryPoints); pm_supportedEntryPoints returns EntryPoint 0x0000000071727De22E5E9d8BAf0edAc6f37da032 (v0.7). source: https://docs.cometh.io/bundler/bundler-api - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: Every bundler and paymaster request/response example carries "jsonrpc":"2.0" with id and result/error. source: https://docs.cometh.io/paymaster/paymaster-api - id: erc-7579 name: ERC-7579 Minimal Modular Smart Accounts conforms: true evidence: >- Documents installModule / uninstallModule / isModuleInstalled fallback methods and ships session keys as ERC-7579 smart sessions with sudo and action policies. source: https://docs.cometh.io/advanced/session-keys/erc7579-actions - id: erc-5792 name: EIP-5792 Wallet Call API (sendCalls / getCallsStatus / getCapabilities) conforms: true evidence: A documented "Capabilities" section implementing sendCalls, getCallsStatus, getCapabilities and grantPermissions. source: https://docs.cometh.io/advanced/capabilities - id: erc-1271 name: ERC-1271 Contract Signature Validation conforms: true evidence: >- Sign/verify-a-message flow for smart accounts, plus the first-party cometh-hq/eip1271-signature-validation repository. source: https://docs.cometh.io/core-features/sign-verify-a-message - id: webauthn-fido2 name: W3C WebAuthn / FIDO2 passkeys conforms: true evidence: >- Wallet owners are passkey signers; docs enumerate platform support (Android 9+, iOS 16+, macOS 13+, Windows 11 22H2) and secure-context requirements, and the first-party p256-signer / SafeWebAuthnSharedSigner contracts validate P-256 signatures on-chain. source: https://docs.cometh.io/resources/faq - id: safe-smart-account name: Safe (Gnosis Safe) smart account, 1.4.1 + 4337 module conforms: true evidence: >- Accounts are Safe smart accounts; the legacy-to-4337 migration guide migrates Safe 1.3.0 accounts to 1.4.1, and cometh-hq/safe-4337-contracts is published. source: https://docs.cometh.io/resources/migrate-from-the-connect-legacy-sdk - id: mica name: EU Markets in Crypto-Assets Regulation (MiCA) / CASP licence conforms: true evidence: >- Cometh describes a "MiCA-aligned regulatory perimeter" in its docs and a registered DASP status on its homepage; Kaiko's acquisition announcement states a MiCA/CASP licence, AMF No. A2025-008, granted December 2025. source: https://kaiko.com/news/Kaiko-Acquires-Cometh-to-Scale-MiCA-Regulated-Onchain-Data-Infrastructure - id: iso-27001 name: ISO/IEC 27001:2022 conforms: true evidence: >- Stated as "ISO 27001:2022 certified" in Kaiko's acquisition announcement; a Vanta trust centre is live at https://security.cometh.io/ (HTTP 200) but its certificate list is rendered client-side and could not be read anonymously. source: https://kaiko.com/news/Kaiko-Acquires-Cometh-to-Scale-MiCA-Regulated-Onchain-Data-Infrastructure - id: oauth2 conforms: false evidence: No OAuth 2.0 anywhere in the docs; API access is project apikey/apisecret only. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (all 404/401) and no OIDC in the docs. - id: rfc9457-problem-details conforms: false evidence: >- Errors are JSON-RPC error objects or Kong gateway {"message": ...} bodies; no application/problem+json is served or documented. - id: rfc8594-sunset-header conforms: false evidence: Zero occurrences of "sunset" or "deprecat" in the published documentation. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 (cometh.io, docs.cometh.io, bundler) or 401 (paymaster, api.4337). - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented (zero occurrences of "webhook"). compliance_program: published: true trust_center: https://security.cometh.io/ trust_center_platform: Vanta certifications: - {name: 'ISO/IEC 27001:2022', source: 'https://kaiko.com/news/Kaiko-Acquires-Cometh-to-Scale-MiCA-Regulated-Onchain-Data-Infrastructure'} - {name: 'MiCA/CASP licence AMF No. A2025-008', source: 'https://kaiko.com/news/Kaiko-Acquires-Cometh-to-Scale-MiCA-Regulated-Onchain-Data-Infrastructure'} - {name: 'Registered DASP (Digital Asset Service Provider)', source: 'https://cometh.io/'} summary: standards_asserted: 9 standards_denied: 7 family: ethereum-account-abstraction regulatory_regime: EU MiCA