generated: '2026-09-19' method: searched source: >- Live probes of kannkidas.de discovery documents (2026-09-19), the OpenAPI at https://kannkidas.de/openapi.json, auth.md, AGENTS.md and the /agents/ protocol register. Each entry names the document or spec location that carries the evidence. No certification or compliance programme is published, so no Compliance pointer is emitted. standards: - id: oauth2 conforms: true evidence: openapi components.securitySchemes.oauth2 clientCredentials flow, tokenUrl https://kannkidas.de/api/oauth/token, scopes sponsorship:read / sponsorship:write; applied on createSponsorPurchase and getSponsorPurchase. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://kannkidas.de/.well-known/oauth-authorization-server (200) — issuer, token_endpoint, registration_endpoint, grant_types_supported, scopes_supported. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://kannkidas.de/.well-known/oauth-protected-resource (200) — resource https://kannkidas.de/api, authorization_servers, scopes_supported, bearer_methods_supported. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://kannkidas.de/api/agent/register in the served metadata; OpenAPI registerAgentClient (POST, anonymous, returns credentials once). Not probed — registration creates server-side state. - id: oidc-discovery conforms: partial evidence: /.well-known/openid-configuration is served (200) but response_types_supported is ["none"], only client_credentials is supported, and jwks.json is an empty key set — an OAuth-only issuer wearing the OIDC path, not an OpenID Provider. - id: rfc9727-api-catalog conforms: true evidence: https://kannkidas.de/.well-known/api-catalog (200, application/linkset+json) with anchors and service-doc relations. - id: a2a-agent-card conforms: true evidence: https://kannkidas.de/.well-known/agent-card.json, protocolVersion 0.3.0, graded conformant in a2a/kannkidas-de-a2a.yml; live message/send answered. - id: mcp-streamable-http conforms: true evidence: https://kannkidas.de/api/mcp initialize returned protocolVersion 2025-06-18; tools/list returned two tools with inputSchema/outputSchema/annotations. - id: agent-skills-discovery conforms: true evidence: https://kannkidas.de/.well-known/agent-skills/index.json declares $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json; both skill digests verified. - id: ucp conforms: true evidence: https://kannkidas.de/.well-known/ucp (200) — ucp.version 2026-04-08, one service and one capability on the provider's own domain, payment handler com.stripe.checkout. Served without the .json extension. - id: x402-v2 conforms: true evidence: GET https://kannkidas.de/api/v1 returned 402 with a base64 PAYMENT-REQUIRED header decoding to x402Version 2, scheme exact, network eip155:84532 (Base Sepolia), asset USDC, amount 1000; Vary PAYMENT-SIGNATURE. Testnet demo only, per AGENTS.md. - id: idempotency-key-header conforms: true evidence: openapi createSponsorPurchase declares a required Idempotency-Key header parameter (8-128 chars); auth.md instructs reuse of the same key for retries. Scoped to the one commercial write. - id: llms-txt conforms: true evidence: https://kannkidas.de/llms.txt (200, text/plain, 76,643 bytes) in llms.txt format. - id: agents-md conforms: true evidence: https://kannkidas.de/AGENTS.md (200, text/markdown) — protocol register, content rules, sponsoring guardrails. - id: content-signal conforms: true evidence: 'robots.txt line "Content-Signal: ai-train=no, search=yes, ai-input=yes".' - id: dns-aid conforms: partial evidence: '_index._agents.kannkidas.de TXT "agents=sponsorship:a2a,sponsorship:mcp"; the per-agent _mcp._agents and _a2a._agents names returned no TXT record at probe time.' - id: json-schema-2020-12 conforms: true evidence: https://kannkidas.de/schema/agent-purchase.json declares $schema draft/2020-12 and is $ref'd by the OpenAPI PurchaseRequest schema. - id: schema-org-json-ld conforms: true evidence: /schema/product.json (TechArticle graph) and /schema/page.json (WebSite graph) anchored by the api-catalog and /schemamap.xml. - id: markdown-content-negotiation conforms: true evidence: GET /produkte/asana/ with Accept text/markdown returned 200 text/markdown; AGENTS.md documents every indexable page as a Markdown twin. - id: pagination conforms: true evidence: searchProductsAndCategories page/perPage (1-60) offset pagination; response carries found/page/perPage. - id: rfc9457-problem-details conforms: false evidence: 'Error schema is {message: string} as application/json; no application/problem+json.' - id: rfc8594-sunset-deprecation-headers conforms: false evidence: No Sunset/Deprecation headers declared or observed; no deprecation policy published. - id: openid-connect conforms: false evidence: No id_token, no authorization_code flow, response_types_supported ["none"]. - id: security-txt-rfc9116 conforms: false evidence: /.well-known/security.txt and /security.txt both 404. domain_standard: market: sponsored placements / advertising on an editorial site declared: none note: >- No OpenRTB, IAB or other advertising-market standard is declared in the contract; the placement is a fixed slot sold through Stripe Checkout, not a programmatic bid surface. Reward-only check — nothing is asserted. compliance_program: published: false note: No SOC 2 / ISO 27001 / trust-center page found (/trust, /security, /compliance all 404). Datenschutz names AWS (EMEA), HitKeep Cloud EU and Stripe as processors and states a preference for European processing locations.