generated: '2026-08-25' method: probed source: >- https://www.ministryofsupply.com/.well-known/ucp, https://www.ministryofsupply.com/.well-known/openid-configuration, https://www.ministryofsupply.com/api/ucp/mcp standards: - id: ucp-2026-04-08 name: Universal Commerce Protocol conforms: true domain_standard: true evidence: >- /.well-known/ucp declares ucp.version 2026-04-08 plus supported_versions 2026-04-08 and 2026-01-23, and registers the dev.ucp.shopping service with transport "mcp" and the schema https://ucp.dev/2026-04-08/services/shopping/mcp.openrpc.json. spec: https://ucp.dev/2026-04-08/specification/overview/ served_at: - {path: /.well-known/ucp, status: 200} - {path: /.well-known/ucp.json, status: 200} operator_attribution: platform attribution_note: >- The document is served from the merchant's own domain and names "Ministry of Supply" as the merchant, but the service endpoint it DECLARES is https://mostrial.myshopify.com/api/ucp/mcp — a Shopify domain, not a Ministry of Supply registrable domain. Under the rubric's own rule (grade from the document's declared service endpoints), that is `platform`, not `self`: this is Shopify's UCP implementation shipping under the merchant's name. Recorded rather than rounded up. The same endpoint path DOES answer on www.ministryofsupply.com, which is what was probed for the tool list, but the published profile is the artifact that decides attribution. capabilities_declared: - dev.ucp.shopping.catalog.search - dev.ucp.shopping.catalog.lookup - dev.ucp.shopping.cart - dev.ucp.shopping.checkout - dev.ucp.shopping.fulfillment - dev.ucp.shopping.discount - dev.ucp.shopping.order - dev.shopify.catalog - id: mcp name: Model Context Protocol conforms: true evidence: >- POST https://www.ministryofsupply.com/api/ucp/mcp with {"jsonrpc":"2.0","id":1,"method":"tools/list"} returned HTTP 200 and a well-formed JSON-RPC result with 13 tools, each carrying a JSON Schema 2020-12 inputSchema. - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: Every MCP tool inputSchema declares $schema https://json-schema.org/draft/2020-12/schema. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: The MCP endpoint responds with jsonrpc "2.0" envelopes. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- /.well-known/openid-configuration returns issuer, authorization_endpoint, token_endpoint, jwks_uri, scopes_supported, response_types_supported, id_token_signing_alg_values_supported. - id: rfc8414-oauth-authorization-server-metadata name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with the same metadata document. - id: rfc9728-oauth-protected-resource-metadata name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns {"resource":"https://www.ministryofsupply.com", "authorization_servers":["https://shopify.com/authentication/3092321"], "bearer_methods_supported":["header"]}. - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: code_challenge_methods_supported ["S256"] in the OIDC discovery document. - id: llmstxt name: llms.txt conforms: true evidence: https://www.ministryofsupply.com/llms.txt returns 200 with a real agent-instruction document. - id: agents-md name: AGENTS.md / agents.md conforms: true evidence: >- https://www.ministryofsupply.com/agents.md returns 200 as text/markdown and is listed in sitemap_agentic_discovery.xml with changefreq weekly. - id: rfc9457-problem-details conforms: false evidence: Transport is JSON-RPC 2.0; no application/problem+json surface is published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both returned 404. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found on the storefront host — /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc all 404 or returned the storefront HTML. The MCP tools/list inputSchema set is the machine-readable contract. compliance_program: published: false note: >- Climate Neutral Certification is claimed on the marketing pages, but no security/compliance program (SOC 2, ISO 27001, PCI DSS) is published by the company; card handling is delegated to Shopify and Google Pay. No Compliance pointer emitted.