generated: '2026-09-19' method: probed source: >- Live probes of https://www.easyfence.cn on 2026-09-19 (openapi.json, /.well-known/agent.json, POST /api/deliver 402 challenge, POST /a2a JSON-RPC errors, /api/registry, /healthz, /facilitator/healthz, the /.well-known/ path list) plus openapi/easyfence-cn-store-api-openapi.yml. Every conforms: true below is backed by a response body that was actually received; claims the provider makes in prose but that could not be observed are recorded as claimed, not conformant. standards: - id: x402 conforms: true evidence: >- POST https://www.easyfence.cn/api/deliver with a known service id and no payment returned HTTP 402 with an application/json body {"x402Version":1,"error":"Payment required","accepts":[...]} and an "accept: exact" response header. accepts[] carries two "exact" scheme requirements (base chainId 8453 USDC and bsc chainId 56) with resource, payTo, asset, maxAmountRequired, maxTimeoutSeconds, facilitator and extra{name,version}. The Base entry additionally carries the x402 "bazaar" discovery extension with a JSON Schema 2020-12 input schema. This is a live, mainnet x402 surface (healthz payment_mode "mainnet-real"); the rubric deliberately does not score x402, so this entry is a record, not a credit. - id: x402-facilitator conforms: true evidence: >- GET https://www.easyfence.cn/facilitator/healthz returned {"status":"ok","role":"x402-facilitator", "networks":["base","base-sepolia","bsc","bsc-testnet"]}; the OpenAPI declares POST /facilitator/verify and POST /facilitator/settle with free-form JSON bodies, and the 402 challenge names this facilitator for the bsc route. The verify/settle bodies were not exercised (they move money). - id: a2a conforms: true evidence: >- Agent card at /.well-known/agent.json graded conformant against the A2A 1.0.0 hard checks (capabilities object, protocolVersion 0.3.0, skills array of 7) - a2a/easyfence-cn-a2a.yml. POST https://www.easyfence.cn/a2a answers JSON-RPC 2.0 (-32601 for tasks/get, tools/list and an unknown method). Deviations: served at the legacy path only, tasks/send rather than message/send, a private auth block instead of securitySchemes. - id: json-rpc-2.0 conforms: true evidence: >- The /a2a endpoint returned {"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"方法不存在: tasks/get"}} - a well-formed JSON-RPC 2.0 error object with the reserved method-not-found code, although over HTTP 400 rather than 200. - id: erc-8004 conforms: claimed evidence: >- The card's auth.identity is "erc8004", /api/registry names itself "X402 ERC-8004 Trust Registry" with an issuer address, and /api/identity/issue describes an "ERC-8004 style" card signed with EIP-712. No card was issued or verified in this pass and the registry holds 0 agents, so on-chain conformance to ERC-8004 (Trustless Agents) is the provider's claim, not an observation. The provider's own word "风格" (style) is noted. - id: eip-3009 conforms: claimed evidence: The /a2a explainer says the buyer signs an EIP-3009 transfer authorization and retries; this is the x402 "exact" scheme's standard mechanism on USDC. Not exercised. - id: json-schema-2020-12 conforms: true evidence: The x402 bazaar extension in the 402 body carries "$schema":"https://json-schema.org/draft/2020-12/schema" describing the /api/deliver input; the OpenAPI is 3.1.0, whose schema dialect is 2020-12. - id: openapi-3.1 conforms: true evidence: https://www.easyfence.cn/openapi.json is openapi 3.1.0 with 16 paths and 20 operations, generated by FastAPI; Swagger UI at /docs and ReDoc at /redoc render it. - id: rfc8615-well-known conforms: true evidence: The agent card is served under /.well-known/ (legacy agent.json path); every other named well-known document 404s (well-known/easyfence-cn-well-known.yml). - id: mcp conforms: false evidence: 'POST tools/list to https://www.easyfence.cn/a2a returns JSON-RPC -32601; /.well-known/mcp.json 404. No MCP server is published.' - id: oauth2 conforms: false evidence: No securitySchemes in the OpenAPI, no security in the agent card, /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on both hosts. The paid surface is gated by payment, not authorization. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on www.easyfence.cn and easyfence.cn. - id: rfc9457 conforms: false evidence: >- Errors are FastAPI {"detail":...} objects (404 {"detail":"Not Found"}, 422 HTTPValidationError), a flat {"error":"未知服务","known":[...]} on /api/deliver, JSON-RPC error objects on /a2a, an x402 body on 402 and an HTML hint on 401. No application/problem+json anywhere. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both hosts. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on both hosts. The provider's /api/catalog is a service/price catalog, not an RFC 9727 linkset. - id: pagination conforms: na evidence: No list endpoint takes paging parameters; /api/catalog returns all 7 services and /api/registry all 0 agents in one body. - id: idempotency conforms: false evidence: No Idempotency-Key header, no replay semantics in the OpenAPI, on the /a2a explainer or in the 402 body. See conventions/easyfence-cn-conventions.yml. - id: rfc8594-sunset conforms: false evidence: No Deprecation or Sunset headers observed on any response; no deprecated flag in the OpenAPI. domain_standard: note: >- The market here is agent commerce. The contract declares two domain standards by shape rather than by prose - the x402 402 body (x402Version, accepts[].scheme/network/payTo/asset/maxAmountRequired) and an A2A agent card at a well-known path - and both were observed live. Neither is currently in the scoring.yml standards[] list for any regime, so this is recorded for the reader and for a future rubric, not as a domain_standard_conformance credit.