generated: '2026-09-19' method: derived source: openapi/_original/moirailabs-com-openapi.json; a2a/moirailabs-com-agent-card.json; well-known/moirailabs-com-ai-plugin.json; live probes 2026-09-19 note: Moirai Labs publishes no compliance program (no SOC 2 / ISO 27001 claim on any public page; /security, /trust and /compliance are SPA-shell 200s with no content). Everything below is derived from the machine-readable surfaces. No domain standard applies to an EVM analytics API — this is a reward-only slot and nothing is invented to fill it. standards: - id: openapi-3.0 conforms: true evidence: 'https://moirailabs.com/openapi.json declares openapi: 3.0.1 with 36 operations; parses' - id: a2a-1.0 conforms: true evidence: a2a/moirailabs-com-agent-card.json — capabilities object, protocolVersion 1.0 on supportedInterfaces[], 11-skill array; graded conformant in a2a/moirailabs-com-a2a.yml - id: mcp conforms: true evidence: MCP bridge declared at https://agent.moirailabs.com/a2a/v1/mcp (agent card extension https://api.moirailabs.com/mcp/v1); tools/list answers 401, so protocol revision unverified gated: true - id: openai-plugin-manifest conforms: true evidence: https://moirailabs.com/.well-known/ai-plugin.json schema_version v1, api.type openapi - id: llms-txt conforms: true evidence: https://moirailabs.com/llms.txt - id: rfc9116-security-txt conforms: true evidence: https://moirailabs.com/.well-known/security.txt with Contact, Expires, Canonical, Policy, Preferred-Languages - id: http-bearer-jwt conforms: true evidence: securitySchemes.bearerAuth type http, scheme bearer, bearerFormat JWT - id: oauth2 conforms: false evidence: no oauth2 securityScheme; no /.well-known/oauth-authorization-server on any host (404 apex, 401 agent host) - id: oidc conforms: false evidence: no /.well-known/openid-configuration (404 apex/api, 401 agent host) - id: rfc9728-protected-resource-metadata conforms: false evidence: '/.well-known/oauth-protected-resource: 404 on moirailabs.com and api.moirailabs.com, 401 on agent.moirailabs.com' - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 on all hosts - id: apis-json conforms: false evidence: /apis.json, /.well-known/apis.json, /apis.yml 404 - id: rfc9457-problem-details conforms: false evidence: errors use a vendor ErrorResponse {code, message, details} envelope over application/json; no application/problem+json - id: rfc7240-prefer conforms: true evidence: 'POST /analytics/invocations honours Prefer: wait=N and Prefer: respond-async, returning 202 + Location + Retry-After for async' - id: idempotency-key-header conforms: true partial: true evidence: 'Idempotency-Key header declared on 1 of 13 mutating operations (create); see conventions/ idempotency.coverage: partial' - id: rfc8594-sunset conforms: false evidence: no Sunset/Deprecation headers, no deprecated operations - id: pagination conforms: false evidence: no page/cursor/limit parameters on any list operation - id: json-api conforms: false evidence: plain JSON bodies, no JSON:API media type - id: hsts conforms: true evidence: moirailabs.com strict-transport-security max-age=31536000; includeSubDomains (api.moirailabs.com sends no HSTS header) domain_standards: sector: blockchain / web3 analytics checked: - EIP-155 chainId as the chain discriminator (ContractInfoRequest.chainId integer, WalletProfilingSimpleRequest.chainId) - ERC-20-style 0x addresses (42-character address constraint) declared_in_contract: false note: The contract uses EVM-native identifiers (integer chainId, 42-char 0x addresses) but declares no formal standard, URN or schema for them. Recorded as an observation, not a conformance claim. compliance_program: published: false probed: - url: https://moirailabs.com/security status: 200 note: SPA shell - url: https://moirailabs.com/legal/subprocessors status: 200 note: SPA shell - url: https://moirailabs.com/accessibility status: 200 note: SPA shell