generated: '2026-09-19' method: searched source: openapi/_original/execution-market-openapi.json (securitySchemes, paths) + a2a/execution-market-agent-card.json + well-known/ (RFC 9728 / RFC 8414 / RFC 9727 / x402 / MCP server card) + https://execution.market/auth.md + https://docs.execution.market/contracts/audits + https://docs.execution.market/project/security summary: >- Execution Market's contract DECLARES a dense set of agent-era and web3 standards and the pipeline could verify most of them from served documents rather than prose: OAuth 2.1 with PKCE S256 (RFC 8414 metadata + RFC 7591 registration + RFC 9728 protected-resource metadata, all fetched), A2A 0.3.0 (card fetched, graded conformant), MCP Streamable HTTP (server card fetched; live endpoint answers an RFC 9728 challenge), RFC 9727 api-catalog (linkset fetched), RFC 9421 HTTP Message Signatures via ERC-8128 (securityScheme), x402 + EIP-3009 (discovery document fetched), ERC-8004 identity and Sign-In with Ethereum (EIP-4361) with CAIP-10 subjects. NOT conformant: RFC 9457 problem details (FastAPI detail envelope), OIDC (no openid-configuration), RFC 9116 security.txt (absent), RFC 8594 Sunset. No classic sector standard (PCI DSS, ISO 20022, FAPI) is claimed and none applies to a stablecoin escrow marketplace. compliance_program: published: false certifications: [] audits: - subject: Legacy Escrow contract v1.4.0 (deprecated) url: https://docs.execution.market/contracts/audits note: five audit rounds summarised (2 critical, 5 high fixed); auditor not named; applies to the RETIRED contract, not the live x402r escrow note: No SOC 2 / ISO 27001 / PCI attestation is published. No Compliance pointer is emitted. conformance: - id: oauth2 conforms: true evidence: 'securitySchemes.oauthBearer (authorizationCode, authorizationUrl https://auth.execution.market/oauth/authorize); RFC 8414 document fetched — well-known/execution-market-auth-oauth-authorization-server.json (grant_types authorization_code + refresh_token, code_challenge_methods_supported [S256], token_endpoint_auth_methods_supported [none])' - id: oauth2.1-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256]; auth.md: "PKCE S256, mandatory. plain is refused"' - id: rfc8414-authorization-server-metadata conforms: true evidence: https://auth.execution.market/.well-known/oauth-authorization-server (200, issuer + jwks_uri + endpoints) - id: rfc9728-protected-resource-metadata conforms: true evidence: https://mcp.execution.market/.well-known/oauth-protected-resource and /oauth-protected-resource/mcp (200; resource, authorization_servers, scopes_supported, bearer_methods_supported); WWW-Authenticate resource_metadata challenge observed live on POST /mcp/ - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://auth.execution.market/oauth/register in the RFC 8414 document; auth.md names RFC 7591' - id: client-id-metadata-document conforms: true evidence: 'client_id_metadata_document_supported: true in the RFC 8414 document' - id: rfc8707-resource-indicators conforms: true evidence: 'resource_indicators_supported: true; token aud = the MCP endpoint (auth.md)' - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint: https://auth.execution.market/oauth/revoke' - id: rfc7517-jwks conforms: true evidence: https://auth.execution.market/.well-known/jwks.json (200; two ES256 P-256 keys) — well-known/execution-market-auth-jwks.json - id: oidc conforms: false evidence: /.well-known/openid-configuration 404 on every host; the AS issues access tokens for the MCP resource, not ID tokens - id: a2a conforms: true evidence: 'agent card at /.well-known/agent-card.json and /.well-known/agent.json on five hosts; protocolVersion 0.3.0; graded conformant in a2a/execution-market-a2a.yml; x-a2a-protocol-version: 0.3.0 response header; JSON-RPC endpoint /a2a/v1 in the OpenAPI (a2a_jsonrpc_endpoint_a2a_v1_post)' - id: a2a-streaming conforms: false evidence: 'card capabilities.streaming=false; description states message/stream is not implemented (proprietary POST /a2a/v1/stream instead)' - id: mcp conforms: true evidence: 'server card https://execution.market/.well-known/mcp/server-card.json ($schema server-card-v1, transport streamable-http, endpoint https://mcp.execution.market/mcp/); live POST answers 401 with an RFC 9728 challenge — the MCP authorization spec behaviour' - id: rfc9727-api-catalog conforms: true evidence: https://execution.market/.well-known/api-catalog (200, application/linkset+json, two anchors with service-desc/service-doc/service-meta/status) — well-known/execution-market-api-catalog.json - id: rfc9421-http-message-signatures conforms: true evidence: 'securitySchemes.erc8128 (Signature-Input header) — "ERC-8128 (RFC 9421 HTTP Message Signatures). Requires the Signature + Signature-Input + Content-Digest headers"; RFC 9530 Content-Digest named' - id: erc-8128 conforms: true evidence: securitySchemes.erc8128; card securitySchemes.erc8128; x-authentication-schemes in both RFC 9728 documents (spec https://eips.ethereum.org/EIPS/eip-8128) - id: erc-8004-agent-identity conforms: true evidence: 'Reputation / Identity tags in the OpenAPI (register_agent_endpoint_api_v1_reputation_register_post, lookup_identity_by_wallet_…); RFC 9728 x-authentication-schemes.identity_registry "ERC-8004 (Base mainnet, agent #2106)"; registry 0x8004A169FB4a3325136EB29fA0ceB6D2e539a432' - id: x402 conforms: true evidence: https://execution.market/.well-known/x402 (200; version 1.0, capabilities.payments/escrow/gasless/eip3009, per-route pricing models) — well-known/execution-market-x402.json; securitySchemes.x402Payment (X-Payment-Auth); 402 responses declared on 3 operations - id: eip-3009-transfer-with-authorization conforms: true evidence: 'x402 doc capabilities.eip3009: true; securitySchemes.x402Payment description "signed EIP-3009 ReceiveWithAuthorization"' - id: eip-4361-sign-in-with-ethereum conforms: true evidence: 'securitySchemes.oauthBearer description: "sign-in is Sign-In with Ethereum (EIP-4361) and the token subject is a CAIP-10 account"' - id: caip-10 conforms: true evidence: 'token sub is a CAIP-10 account (eip155:8453:0x…) — auth.md §5' - id: eip-712-typed-data conforms: true evidence: 'securitySchemes.releaseApproval (X-EM-Approval, "Per-operation EIP-712 ReleaseApproval"); walletSession SessionGrant built as EIP-712 typed data' - id: rfc9457-problem-details conforms: false evidence: 'all 339 error responses are application/json with the FastAPI {"detail": …} envelope; no application/problem+json anywhere in the spec' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on api/mcp/auth/docs hosts; SPA shell on apex/www - id: rfc8594-sunset conforms: false evidence: no Deprecation/Sunset header in any response schema or docs; two operations carry deprecated:true with no policy - id: idempotency-key conforms: true evidence: 'X-Idempotency-Key documented for POST /api/v1/tasks (skill.md STEP 2: repeat POST with the same key returns the ORIGINAL task with X-Idempotent: true); scoped to create — see conventions/' - id: pagination conforms: true evidence: 'limit/offset query parameters on list operations (docs sdk/python list_tasks(limit=20, offset=0)); Plugin SDK exposes list_page' - id: world-id-proof-of-personhood conforms: true evidence: 'World ID tag (2 operations); skill.md: bounty >= $500 requires an Orb-verified worker' domain_standards: note: >- REWARD-ONLY. The provider's market (agent task marketplace / stablecoin escrow) has no classic sector standard in the scoring regime lists; the standards the CONTRACT itself declares — A2A, MCP, x402/EIP-3009, ERC-8004, ERC-8128/RFC 9421, RFC 9728/8414/9727 — are recorded above with spec-location evidence and are the domain signature of an agent-native provider. declared_in_contract: [a2a, mcp, x402, erc-8004-agent-identity, erc-8128, rfc9421-http-message-signatures, rfc9728-protected-resource-metadata, rfc9727-api-catalog]