generated: '2026-09-19' method: probed source: >- Live probes 2026-09-19: https://graphadvocate.com/.well-known/agent-card.json, POST https://graphadvocate.com/mcp (initialize + tools/list), anonymous POST https://graphadvocate.com/route (HTTP 402 + PAYMENT-REQUIRED header), https://graphadvocate.com/.well-known/x402, https://graphadvocate.com/openapi.json, the /.well-known/ sweep in well-known/, and the provider's docs (https://docs.graphadvocate.com/x402, /agent-card, /quickstart). standards: - id: a2a conforms: true evidence: >- A2A agent card served at the canonical /.well-known/agent-card.json (200, application/json), protocolVersion 0.3.0, preferredTransport JSONRPC, capabilities object, 26-skill array — graded conformant in a2a/graphadvocate-com-a2a.yml. POST / speaks JSON-RPC 2.0 message/send per the quickstart. - id: a2a-payments-extension-x402 conforms: true evidence: >- capabilities.extensions[0].uri = https://x402.org/ext/a2a-payments/v1 with params (network eip155:8453, USDC asset, payTo, paymentHeader X-PAYMENT, httpEndpoint, bazaarDiscovery) in the served card. - id: mcp conforms: true evidence: >- POST https://graphadvocate.com/mcp answered initialize with protocolVersion 2024-11-05 (serverInfo graph-advocate-mcp 1.0.0) and tools/list with 3 tools carrying JSON-Schema inputSchema, anonymously. Advertised SSE path /mcp/sse returned 404. - id: x402 conforms: true evidence: >- Anonymous POST /route returned HTTP 402 with a base64 `payment-required` response header and a JSON body {x402Version: 2, accepts: [{scheme: exact, network: eip155:8453, asset: 0x8335…2913, amount: "10000", payTo, maxTimeoutSeconds: 300}], output_example, hint}. Discovery document at /.well-known/x402 (version 1, 24 resources). Docs name the CDP facilitator (api.cdp.coinbase.com/platform/v2/x402) as settlement. - id: x402-bazaar-discovery conforms: true evidence: /.well-known/x402 served (200, application/json) with resources[], instructions, documentation, capabilities and catalogs keys; the 402 body's extensions.bazaar block carries input/output schema. - id: erc-8004 conforms: true evidence: >- Card description, llms.txt, capabilities.json identity block and openapi.json x-discovery declare ERC-8004 agent #734 on Arbitrum and #41034 on Base under graphadvocate.eth; the source repo publishes erc8004-registration.json (type https://eips.ethereum.org/EIPS/eip-8004#registration-v1). Not independently verified on-chain by this pipeline. - id: json-rpc-2.0 conforms: true evidence: A2A endpoint (POST /) and MCP endpoint (POST /mcp) both accept and return JSON-RPC 2.0 envelopes (observed on /mcp; documented for /). - id: openapi-3.1 conforms: true evidence: https://graphadvocate.com/openapi.json is OpenAPI 3.1.0 with 23 operations, servers[] https://graphadvocate.com, info.contact graphadvocate.com; carries x-payment-info per operation and x-discovery/x-llms-txt/x-agents-index extensions. - id: llms-txt conforms: true evidence: /llms.txt served on both graphadvocate.com and docs.graphadvocate.com (200, text/plain); docs host also serves llms-full.txt. - id: agent-skills-discovery conforms: true evidence: docs.graphadvocate.com/.well-known/agent-skills/index.json ($schema agentskills.io discovery/0.2.0) lists one skill-md with sha256 digest; skill served at the referenced path. - id: oauth2 conforms: false evidence: No OAuth anywhere — no securitySchemes in the OpenAPI, /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on both hosts. Access is payment-gated (x402), not credential-gated; this is by design, not an omission. - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration 404 on both hosts. - id: rfc8414-authorization-server-metadata conforms: false evidence: 404 on both hosts. - id: rfc9728-protected-resource-metadata conforms: false evidence: 404 on the host that serves the MCP endpoint (graphadvocate.com) — no authorization server exists to point at. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on both hosts. - id: rfc9457-problem-details conforms: false evidence: Errors are application/json; the only declared non-2xx is 402 with the x402 envelope. No application/problem+json. - id: rfc8594-deprecation-sunset conforms: false evidence: No Deprecation/Sunset response headers documented; the legacy agent.json deprecation is signalled in-band via a `_deprecation` JSON member instead. - id: graphql conforms: false evidence: Graph Advocate exposes no GraphQL endpoint of its own; it RETURNS GraphQL queries to run against The Graph gateway. Not a conformance of this API. domain_standard: market: onchain data / agent-to-agent commerce declared_in_contract: - standard: x402 location: openapi.json paths.*.post.x-payment-info.protocols[0].x402 + price {mode fixed, currency USD, amount} note: every one of the 23 operations declares its x402 price in the contract itself - standard: A2A a2a-payments extension location: agent-card.json capabilities.extensions[0].uri https://x402.org/ext/a2a-payments/v1 - standard: ERC-8004 location: openapi.json x-discovery.agent.erc8004 ("Agent #734 on Arbitrum"); capabilities.json identity.erc8004_id compliance_program: published: false note: No SOC 2 / ISO 27001 / trust-center page; see security/ (probe-security-programs found vdp=none trust=none). No Compliance pointer emitted.