generated: '2026-09-19' method: searched source: https://agent-economy.kgninja.dev/.well-known/api-catalog derived_from: openapi/kgninja-dev-openapi.json docs: - https://agent-economy.kgninja.dev/auth.md - https://agent-economy.kgninja.dev/docs/mcp-x402-interoperability - https://agent-economy.kgninja.dev/docs/security-and-trust summary: >- KG-NINJA's conformance profile is the agent-discovery and agent-commerce protocol stack, implemented unusually completely on one host: an A2A 1.0 agent card and JSON-RPC responder, an MCP server at 2025-06-18/2026-07-28 with server card, registry document and ownership proof, an RFC 9727 API catalog served with the linkset media type, x402 v2 (exact scheme, USDC on Base) with a self-hosted manifest and Bazaar extension, an Agent Skills discovery index with SHA-256 integrity, an RFC 7517 JWKS publishing an Ed25519 (RFC 8032 / RFC 8037 EdDSA) evidence key, RFC 6901 JSON Pointers as the assertion addressing scheme, CAIP-2 chain identifiers, IETF Content Signals, and schema.org JSON-LD on the landing page. It deliberately declines OAuth 2.0 / OIDC / RFC 9728 ("this is not an OAuth-protected resource"), does not use RFC 9457 problem details, and publishes neither security.txt nor RFC 8594 sunset signalling. No certifications or compliance program are published, so no Compliance pointer is emitted. standards: - id: a2a name: Agent2Agent protocol version: '1.0' conforms: true evidence: >- a2a/kgninja-dev-agent-card.json — supportedInterfaces[0] {url https://agent-economy.kgninja.dev/a2a, protocolBinding JSONRPC, protocolVersion "1.0"}, capabilities object, skills[] of 1; POST /a2a with A2A-Version: 1.0 answered GetTask with -32001 TASK_NOT_FOUND and ListTasks with an empty collection, and rejected an unversioned request with -32009 VERSION_NOT_SUPPORTED ("use 1.0"). Graded conformant in a2a/kgninja-dev-a2a.yml. - id: mcp name: Model Context Protocol version: '2025-06-18 (negotiated live); 2026-07-28 declared on the server card' conforms: true evidence: >- POST https://agent-economy.kgninja.dev/mcp initialize returned protocolVersion 2025-06-18, serverInfo dev.kgninja/agent-verification-utility 0.4.3; tools/list returned 5 tools with JSON Schema 2020-12 inputSchema and tool annotations. See mcp/kgninja-dev-mcp.yml. - id: mcp-server-card name: MCP Server Card (experimental v1) + MCP Registry server.json (schema 2025-12-11) conforms: true evidence: https://agent-economy.kgninja.dev/mcp/server-card (application/mcp-server-card+json, $schema static.modelcontextprotocol.io/schemas/v1/server-card.schema.json) and https://agent-economy.kgninja.dev/server.json ($schema …/2025-12-11/server.schema.json, remotes[] streamable-http); /.well-known/mcp-registry-auth serves an ed25519 ownership proof. - id: json-rpc-2.0 conforms: true evidence: '/mcp and /a2a both answer {"jsonrpc":"2.0",...} with -32601 Method not found for unimplemented methods (resources/list, prompts/list, tasks/get).' - id: x402 name: x402 HTTP payment protocol version: 2 (scheme exact) conforms: true verification: partial domain_standard_signature: true evidence: >- well-known/kgninja-dev-x402.json (x402Version 2, two resources — POST /verify-evidence and POST /mcp — each accepting {scheme exact, network eip155:8453, amount 10000, asset 0x8335…2913, payTo 0x4D7d…aDE3, maxTimeoutSeconds 300} with a bazaar extension; simulation false); openapi/kgninja-dev-openapi.json verifyEvidence declares 402 with a PAYMENT-REQUIRED header and the X402PaymentRequired schema (x402Version const 2, accepts[] of X402PaymentRequirement), PAYMENT-SIGNATURE request header, and PAYMENT-RESPONSE on 200; the MCP server card's _meta dev.kgninja/x402 names verify_evidence as the paid tool; every response exposes PAYMENT-REQUIRED and PAYMENT-RESPONSE via CORS. note: >- The x402 manifest and the contract were fetched and read; a live 402 was NOT observed, because /verify-evidence refuses an empty body with 409 PRECHECK_REQUIRED before creating a quote, and reaching the 402 means posting a complete paid intent, which this pipeline does not do. Recorded as conforming on the provider's served manifest and contract, with the live payload unverified. This is the contract-level domain-standard signature for the agent-commerce market this provider sells into. - id: caip-2 name: CAIP-2 chain identifier conforms: true evidence: eip155:8453 (Base) and eip155:84532 (Base Sepolia) enumerated in Price.network, VerificationSpendPolicy.network and X402PaymentRequirement.network; the served manifest uses eip155:8453 only. - id: rfc9727-api-catalog name: RFC 9727 API Catalog conforms: true evidence: >- GET https://agent-economy.kgninja.dev/.well-known/api-catalog returned 200 with Content-Type application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727" and a linkset[] carrying service-desc, service-doc, service-meta and status relations for one anchor; every response on the host also carries Link: ; rel="api-catalog". Saved as well-known/kgninja-dev-api-catalog.json. - id: rfc8288-web-linking conforms: true evidence: Link response header on every response with rel="api-catalog", rel="service-desc" (typed), rel="service-doc" and rel="alternate" (text/markdown). - id: rfc8615-well-known conforms: true evidence: 12 distinct documents served under /.well-known/ (see well-known/kgninja-dev-well-known.yml). - id: rfc7517-jwks name: JSON Web Key Set conforms: true evidence: https://agent-economy.kgninja.dev/.well-known/jwks.json — one key {kty OKP, crv Ed25519, alg EdDSA, use sig, key_ops [verify], kid https://agent-economy.kgninja.dev/agent.json#evidence-key-1}; the same key is embedded in agent.json verification_keys[] with not_before 2026-08-08. - id: eddsa-ed25519 name: EdDSA over Ed25519 (RFC 8032 / RFC 8037) conforms: true evidence: SignedEvidence.signature.alg Ed25519 in the OpenAPI; the receipts guide instructs verification "directly over the decoded signed_payload_b64url bytes" without re-serialisation. - id: rfc6901-json-pointer conforms: true evidence: JsonPointer schema (RFC 6901) is the addressing scheme for json_pointer_exists, json_pointer_equals and json_type_is assertions; the docs page names RFC 6901. - id: agent-skills-discovery name: Agent Skills discovery (schemas.agentskills.io v0.2.0) + SKILL.md conforms: true evidence: https://agent-economy.kgninja.dev/.well-known/agent-skills/index.json ($schema …/discovery/0.2.0/schema.json) with a sha256 digest that matches the fetched SKILL.md (skills/kgninja-dev-verify-json-evidence.md). - id: content-signals name: Content Signals (robots.txt Content-Signal directive) conforms: true evidence: 'robots.txt line "Content-Signal: ai-train=no, search=yes, ai-input=yes" and the same value as a content-signal response header on every response.' - id: ai-catalog name: AI Catalog (draft 1.0) conforms: true evidence: https://agent-economy.kgninja.dev/.well-known/ai-catalog.json served as application/ai-catalog+json with one entry of type application/mcp-server-card+json. - id: schema-org-json-ld conforms: true evidence: Landing page embeds a JSON-LD @type [SoftwareApplication, WebAPI] block with an Offer (price 0.01, priceCurrency USDC) and provider Person @kgninja; each docs page embeds a TechArticle. - id: llms-txt conforms: true evidence: /llms.txt and /llms-full.txt served as text/markdown; saved verbatim as llms/kgninja-dev-llms.txt. - id: openapi-3.1 conforms: true version: 3.1.0 evidence: openapi/kgninja-dev-openapi.json parses; 44 operations across 44 paths, every operation has an operationId, a summary and tags (8 declared tags, all used); 47 component schemas; 1 securityScheme; 3 reusable parameters; 7 reusable responses. gaps: - servers[] is a single relative entry "/" ("Relative to the current deployment origin"), so the contract names no host of its own; the origin is https://agent-economy.kgninja.dev. - Only one example/examples key in the whole document (Price.amount); request and response examples live in the x402 manifest's bazaar extension and in SKILL.md instead. - Most 4xx/5xx responses are $ref'd reusable responses without per-operation descriptions. - info.license is "UNLICENSED"; no termsOfService or contact. - id: idempotency-key-header name: Idempotency-Key request header (draft-ietf-httpapi-idempotency-key-header) conforms: true verification: partial evidence: POST /quote requires an Idempotency-Key header (16-128 chars; reuse with a different request hash returns 409) and the three MCP purchase tools require an idempotency_key argument; POST /verify-evidence carries no such header. See conventions/kgninja-dev-conventions.yml. - id: rfc9457-problem-details conforms: false evidence: Errors are application/json in a provider envelope {error:{code, message, request_id, retryable, details}}; no application/problem+json anywhere in the contract or observed live. See errors/kgninja-dev-problem-types.yml. - id: oauth2 conforms: false claimed: false evidence: 'No oauth2 securityScheme; /.well-known/oauth-authorization-server 404. auth.md: "OAuth authorization-server and protected-resource metadata are intentionally not published because this is not an OAuth-protected resource."' - id: oidc conforms: false evidence: No openIdConnect securityScheme; /.well-known/openid-configuration 404 (intentional, see above). - id: rfc9728-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource 404 on the MCP host (intentional, see above). - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt both 404. - id: rfc8594-sunset-header conforms: false evidence: No Deprecation/Sunset headers, no deprecation policy, no operation marked deprecated. - id: mpp name: Machine Payments Protocol conforms: false claimed: partial evidence: 'llms.txt: "MPP clients can consume this service through MPP''s x402 compatibility. The server ... does not advertise a native MPP challenge." agent.json protocols.mpp {mode client-compatibility-via-x402, native_challenge false}.' - id: ucp conforms: false evidence: /.well-known/ucp.json 404. - id: acp conforms: false evidence: /.well-known/acp.json 404; no ACP channel is claimed. - id: aauth conforms: false evidence: /.well-known/aauth-resource.json 404. compliance_program: published: false certifications: [] note: No SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim anywhere on the host; the security-and-trust page describes architecture and non-guarantees, not an audit. No Compliance or TrustCenter pointer is emitted.