generated: '2026-07-19' method: searched source: https://www.julep.com/.well-known/ucp name: Julep standards conformance description: >- Cross-cutting standards Julep's public surfaces do and do not conform to, each with the evidence it was asserted from. Every `conforms: true` below is backed by a document fetched from www.julep.com on 2026-07-19. Julep publishes no compliance or certification program of its own. standards: - id: ucp name: Universal Commerce Protocol conforms: true version: '2026-04-08' evidence: >- /.well-known/ucp advertises dev.ucp.shopping services with mcp and embedded transports, and the capability set cart / checkout / fulfillment / discount / order / catalog.search / catalog.lookup. source: https://www.julep.com/.well-known/ucp - id: mcp name: Model Context Protocol conforms: true evidence: >- A live JSON-RPC 2.0 MCP endpoint is advertised and responds at POST /api/ucp/mcp (anonymous tools/list is refused pending an agent profile URI). source: https://www.julep.com/agents.md - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- /.well-known/openid-configuration returns a complete discovery document with issuer, authorization/token/end_session endpoints, jwks_uri, RS256 id_token signing, and the standard claim set. source: https://www.julep.com/.well-known/openid-configuration - id: oauth2 name: OAuth 2.0 (RFC 6749) authorization code conforms: true evidence: 'response_types_supported: [code]; grant_types_supported includes authorization_code and refresh_token.' source: https://www.julep.com/.well-known/oauth-authorization-server - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer and endpoint metadata. source: https://www.julep.com/.well-known/oauth-authorization-server - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: [S256].' source: https://www.julep.com/.well-known/openid-configuration - id: rfc7519 name: JSON Web Token conforms: true evidence: 'id_token_signing_alg_values_supported: [RS256]; a jwks_uri is published; the JWT-bearer grant type is supported.' source: https://www.julep.com/.well-known/openid-configuration - id: llmstxt name: llms.txt conforms: true evidence: /llms.txt returns 200 with agent-facing Markdown mirroring /agents.md. source: https://www.julep.com/llms.txt - id: agents-md name: AGENTS.md / agent instructions conforms: true evidence: >- /agents.md returns 200, is referenced from robots.txt, and is the sole entry in the dedicated /sitemap_agentic_discovery.xml. source: https://www.julep.com/agents.md - id: sitemaps name: sitemaps.org protocol 0.9 conforms: true evidence: /sitemap.xml is a valid sitemapindex linking product, page, collection, blog, and agentic-discovery sitemaps. source: https://www.julep.com/sitemap.xml - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: Error responses return HTML, not application/problem+json. See errors/julep-beauty-problem-types.yml. - id: rfc9116 name: security.txt conforms: false evidence: '/.well-known/security.txt returns 404.' - id: rfc8594 name: Sunset HTTP header conforms: false evidence: No Sunset or Deprecation header observed; no deprecation policy published. - id: idempotency name: Idempotency keys conforms: false evidence: No idempotency key header or retry-safety guidance is published. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming, or webhook surface is published to third parties. - id: openapi name: OpenAPI conforms: false evidence: >- Julep publishes no OpenAPI definition. The description in openapi/ was generated by the API Evangelist pipeline from the provider's own /agents.md and verified live. certifications: published: false notes: >- Julep names no SOC 2, ISO 27001, PCI DSS, HIPAA, or FedRAMP program of its own. Card handling is delegated to Shopify and Google Pay via the UCP payment handlers, so the relevant certifications sit with those platforms, not with the merchant.