generated: '2026-08-11' method: probed source: 'live probes of www.curehydration.com — /.well-known/ucp, /.well-known/openid-configuration, /api/ucp/mcp, /api/2026-04/graphql.json, /robots.txt, /llms.txt, /agents.md' summary: >- Cure Hydration makes no first-party standards claim. Everything asserted below was read off a live response. The conformance profile is that of a Shopify-hosted merchant that has the current agentic-commerce stack switched on: UCP 2026-04-08 over MCP, OIDC + RFC 8414 discovery, llms.txt and agents.md, and an agent-discovery sitemap. standards: - id: ucp name: Universal Commerce Protocol 2026-04-08 conforms: true evidence: url: https://www.curehydration.com/.well-known/ucp http_status: 200 detail: >- Declares ucp.version 2026-04-08 with 2026-01-23 also supported, the dev.ucp.shopping service over mcp and embedded transports, eight capabilities (checkout, fulfillment, discount, cart, order, catalog.search, catalog.lookup, dev.shopify.catalog) and three payment handlers. spec: https://ucp.dev/2026-04-08/specification/overview/ - id: mcp name: Model Context Protocol conforms: true version: '2024-11-05' evidence: url: https://www.curehydration.com/api/ucp/mcp http_status: 200 detail: >- initialize returns serverInfo universal-commerce 0.1.0 and protocolVersion 2024-11-05; tools/list returns 13 tools with JSON Schema 2020-12 inputSchemas. - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: url: https://www.curehydration.com/api/ucp/mcp http_status: 200 detail: 'Requests and responses carry jsonrpc "2.0"; errors use the standard error object with an application code of -32001.' - id: json-schema name: JSON Schema 2020-12 conforms: true evidence: url: https://www.curehydration.com/api/ucp/mcp http_status: 200 detail: 'Every MCP tool inputSchema declares $schema https://json-schema.org/draft/2020-12/schema.' - id: openid-connect name: OpenID Connect Discovery 1.0 conforms: true evidence: url: https://www.curehydration.com/.well-known/openid-configuration http_status: 200 detail: 'Full discovery document — issuer, authorization/token/jwks endpoints, RS256 id tokens, claims_supported.' - id: rfc8414 name: 'RFC 8414 — OAuth 2.0 Authorization Server Metadata' conforms: true evidence: url: https://www.curehydration.com/.well-known/oauth-authorization-server http_status: 200 - id: rfc7636 name: 'RFC 7636 — PKCE' conforms: true evidence: url: https://www.curehydration.com/.well-known/openid-configuration http_status: 200 detail: 'code_challenge_methods_supported: ["S256"]. Plain is not offered.' - id: oauth2 name: OAuth 2.0 conforms: true evidence: url: https://www.curehydration.com/.well-known/oauth-authorization-server http_status: 200 detail: 'authorization_code, refresh_token and urn:ietf:params:oauth:grant-type:jwt-bearer grants.' - id: graphql name: GraphQL (Shopify Storefront API 2026-04) conforms: true evidence: url: https://www.curehydration.com/api/2026-04/graphql.json http_status: 200 detail: 'Full introspection answered anonymously — 416 types, 35 root queries, 41 mutations.' - id: graphql-cursor-connections name: GraphQL Cursor Connections Specification conforms: true evidence: url: https://www.curehydration.com/api/2026-04/graphql.json http_status: 200 detail: '30 connection types with edges/node/cursor/pageInfo in the introspected SDL.' - id: llmstxt name: llms.txt conforms: true evidence: url: https://www.curehydration.com/llms.txt http_status: 200 detail: 'Served as text with agent instructions; mirrors /agents.md.' - id: agents-md name: AGENTS.md / agents.md agent instructions conforms: true evidence: url: https://www.curehydration.com/agents.md http_status: 200 content_type: 'text/markdown; charset=utf-8' detail: 'Served with a real text/markdown content type and listed in a dedicated agentic-discovery sitemap.' - id: sitemaps-org name: 'sitemaps.org protocol 0.9' conforms: true evidence: url: https://www.curehydration.com/sitemap.xml http_status: 200 detail: 'Sitemap index over products, pages, collections, blogs and a dedicated agentic-discovery sitemap.' - id: idempotency name: Idempotent write semantics conforms: partial evidence: url: https://www.curehydration.com/api/ucp/mcp http_status: 200 detail: >- meta["idempotency-key"] is a REQUIRED field on complete_checkout, and the GraphQL mutation shopPayPaymentRequestSessionSubmit takes idempotencyKey: String! with an IDEMPOTENCY_KEY_ALREADY_USED replay error. Cart and checkout-create/update operations have no idempotency key. - id: rfc9457 name: 'RFC 9457 — Problem Details for HTTP APIs' conforms: false evidence: url: https://www.curehydration.com/api/ucp/mcp http_status: 422 detail: 'Errors are JSON-RPC error objects, not application/problem+json.' - id: rfc9116 name: 'RFC 9116 — security.txt' conforms: false evidence: url: https://www.curehydration.com/.well-known/security.txt http_status: 404 - id: rfc9727 name: 'RFC 9727 — api-catalog well-known URI' conforms: false evidence: url: https://www.curehydration.com/.well-known/api-catalog http_status: 404 - id: a2a name: 'A2A Agent Card' conforms: false evidence: url: https://www.curehydration.com/.well-known/agent-card.json http_status: 404 detail: 'Also 404 at the legacy /.well-known/agent.json, on both www.curehydration.com and cure-hydration.myshopify.com.' - id: openapi name: OpenAPI conforms: false evidence: url: https://www.curehydration.com/openapi.json http_status: 404 detail: 'No OpenAPI or Swagger document on any probed path or host. The MCP tool inputSchemas and the GraphQL SDL are the machine-readable contract instead.' - id: asyncapi name: AsyncAPI conforms: false evidence: url: https://www.curehydration.com/agents.md http_status: 200 detail: 'No event, streaming or webhook surface is published to the public. Not applicable rather than failed.' compliance_certifications: [] compliance_note: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA claim, and no compliance page is published on curehydration.com. Payment card handling is delegated entirely to Shopify and its payment handlers (Shop Pay, Google Pay, Shopify card), so the store makes no PCI claim of its own. Consumer privacy surfaces do exist — a CCPA request form at /pages/california-consumer-privacy-act-ccpa-form and a data-sharing opt-out at /pages/data-sharing-opt-out — but those are rights-request forms, not a certification.