generated: '2026-08-16' method: derived source: >- Derived from artifacts in this repo that were themselves probed or searched: well-known/futureverse-openid-configuration.json (live OIDC discovery), graphql/futureverse-asset-register.graphql (live introspection), mcp/futureverse-mcp.yml (live tools/list), a2a/futureverse-agent-card.json (live agent card), openapi/futureverse-rootrewards-quest-api-openapi.yml, and the Futureverse documentation pages cited per entry. scope: >- Cross-cutting industry standards only. Chain-level standards the Root Network runtime implements (ERC-20, ERC-721, ERC-1155, ERC-165, ERC-5484, EIP-2470) are recorded at the bottom as implemented_chain_standards, not as API conformance. standards: - id: oidc name: OpenID Connect Core / Discovery 1.0 conforms: true evidence: >- https://login.futureverse.app/.well-known/openid-configuration returns HTTP 200 with a complete discovery document: issuer, authorization/token/userinfo/jwks endpoints, response_types_supported, subject_types_supported [public], id_token_signing_alg_values [RS256], claims_supported, end_session_endpoint. Saved verbatim to well-known/. confidence: high - id: oauth2 name: OAuth 2.0 (RFC 6749) + PKCE (RFC 7636) conforms: true evidence: >- code_challenge_methods_supported [S256]; grant_types_supported includes authorization_code, refresh_token, client_credentials and urn:ietf:params:oauth:grant-type:jwt-bearer; five token_endpoint_auth_methods including private_key_jwt. confidence: high - id: oauth2-par name: OAuth 2.0 Pushed Authorization Requests (RFC 9126) conforms: true evidence: 'pushed_authorization_request_endpoint: https://login.futureverse.app/request' confidence: high - id: oauth2-introspection name: OAuth 2.0 Token Introspection (RFC 7662) and Revocation (RFC 7009) conforms: true evidence: introspection_endpoint and revocation_endpoint both advertised in the discovery document. confidence: high - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: >- https://login.futureverse.app/.well-known/oauth-authorization-server returns 404. The server is discoverable as OIDC but not at the RFC 8414 path. confidence: high - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: false evidence: >- /.well-known/oauth-protected-resource returns 404 on login.futureverse.app and on docs.therootnetwork.com. This is the document an MCP client looks for to discover how to authenticate against a protected resource. confidence: high - id: siwe name: Sign-In With Ethereum (EIP-4361) conforms: true evidence: >- https://docs.therootnetwork.com/asset-register/authentication states SIWE is used to create access tokens for authenticated Asset Register endpoints, and publishes a SIWE generator tool. confidence: medium note: Conformance is asserted by the docs; the token format was not independently verified. - id: graphql-relay name: Relay Cursor Connections Specification conforms: true evidence: >- https://docs.therootnetwork.com/asset-register/getting-started states "The API is fully Relay specification compliant". Corroborated by the reflected SDL: a Node interface, a node(id) root field, ten *Connection types and PageInfo with hasNextPage/hasPreviousPage/startCursor/endCursor. confidence: high - id: graphql-introspection name: GraphQL introspection (June 2018 spec) conforms: true evidence: >- Anonymous POST of the full IntrospectionQuery to https://ar-api.futureverse.app/graphql returned HTTP 200 and a complete 186-type __schema. Introspection is not disabled in production. confidence: high - id: mcp name: Model Context Protocol conforms: true version: '2025-06-18' evidence: >- https://docs.therootnetwork.com/mcp answered initialize with protocolVersion 2025-06-18 and serverInfo {name: "The Root Network", version: "1.0.0"}, and tools/list with three tools carrying draft-07 inputSchemas. Streamable HTTP with text/event-stream responses. confidence: high scope_note: Documentation search only. No product API is exposed through MCP. - id: a2a name: A2A Agent Card conforms: true version_declared: '0.3' grade: conformant evidence: >- https://docs.therootnetwork.com/.well-known/agent-card.json returns HTTP 200 with capabilities as an object, protocolVersion present and skills as an array. Graded in a2a/futureverse-a2a.yml; deviations recorded there (skills[] is empty, no A2A task endpoint). confidence: high - id: llmstxt name: llms.txt conforms: true evidence: >- https://docs.therootnetwork.com/llms.txt returns HTTP 200 with a 125-entry index, and /llms-full.txt returns a 751KB corpus. Both are platform-generated by Mintlify. confidence: high - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- No application/problem+json anywhere. The Asset Register uses typed GraphQL success/failure unions; RootRewards documents bare status codes with no error body shape. confidence: high - id: rfc8594 name: Sunset HTTP Header (RFC 8594) conforms: false evidence: No Sunset or Deprecation header is documented on any surface. See lifecycle/. confidence: high - id: openapi name: OpenAPI conforms: false evidence: >- Futureverse publishes no OpenAPI for any API. Probed docs.therootnetwork.com/openapi.json, /docs.json, /mint.json and /api-reference/openapi.json — all 404. The description in openapi/ was generated by API Evangelist from the published RootRewards reference and is labelled as such in its info.x-provenance. confidence: high - id: asyncapi name: AsyncAPI conforms: false evidence: >- A real webhook surface exists (see asyncapi/futureverse-asset-register-events.yml) but no AsyncAPI document is published; /asyncapi.yaml and /asyncapi.json both 404. confidence: high - id: idempotency-key name: Idempotency-Key (IETF draft) conforms: false evidence: >- No idempotency key on any surface. Per-address nonces protect the Asset Register ledger against replay but do not make a client retry safe. See conventions/. confidence: high - id: ratelimit-headers name: RateLimit header fields for HTTP (IETF draft) conforms: false evidence: No rate-limit headers documented or observed. See rate-limits/. confidence: high - id: security-txt name: security.txt (RFC 9116) conforms: false evidence: /.well-known/security.txt returns 404 or 403 on every Futureverse host probed. confidence: high compliance_program: published: false certifications: [] detail: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim, and no vulnerability disclosure policy was found by probe or search. No Compliance pointer is emitted. implemented_chain_standards: note: >- Implemented by the Root Network runtime and its EVM precompiles, per the published changelog. Recorded for completeness; these are protocol standards, not API conformance. standards: [ERC-20, ERC-721, ERC-1155, ERC-165, ERC-5484, EIP-2470, EIP-4361] counts: standards_asserted: 19 conforms_true: 10 conforms_false: 9