generated: '2026-09-19' method: searched source: >- openapi/moltrust-ch-openapi.yml + openapi/moltrust-ch-moltguard-openapi.yml + a2a/moltrust-ch-agent-card.json + well-known/ (did.json, jwks.json, x402.json, agent-registration.json, registry-key.json) + live MCP initialize + https://moltrust.ch/compliance.html + https://moltrust.ch/bindings/trust-registry/v1.html + https://moltrust.ch/terms.html + https://moltrust.ch/privacy.html + https://api.moltrust.ch/llms.txt standards: - id: openapi-3.1 conforms: true evidence: >- Two OpenAPI 3.1.0 documents served live: https://api.moltrust.ch/openapi.json (MolTrust API 2.5, 181 paths / 186 operations, FastAPI-generated, no servers[] or securitySchemes) and https://api.moltrust.ch/guard/openapi.json (MoltGuard 1.5.0, 70 paths / 71 operations, servers[], x402 securityScheme, Apache-2.0 license, contact CryptoKRI GmbH). Captured to openapi/_original/. - id: a2a-1.0 conforms: true evidence: >- Signed AgentCard at /.well-known/agent-card.json on api.moltrust.ch and moltrust.ch, graded conformant against the 1.0.0 hard checks (a2a/moltrust-ch-a2a.yml). The declared JSONRPC interface does not implement A2A task methods (tasks/get -> -32601); skills are served over the provider's published custom "Trust Registry Binding v1". verification: probed - id: mcp conforms: true evidence: >- Hosted streamable-HTTP MCP server at https://api.moltrust.ch/mcp answered initialize with protocolVersion 2025-06-18 and returned 53 tools from tools/list anonymously; /.well-known/mcp.json discovery stub also served. Same server on PyPI as moltrust-mcp-server. verification: probed - id: w3c-did-core conforms: true evidence: >- DID Documents served at https://api.moltrust.ch/.well-known/did.json (did:web:api.moltrust.ch, Ed25519VerificationKey2020, service[]) and https://moltrust.ch/.well-known/did.json (JsonWebKey2020). Own DID method did:moltrust with a published method specification (https://moltrust.ch/did-method-spec.html), a Universal Resolver driver (uresolver.moltrust.ch, DIF PR #540) and a W3C did-extensions registration PR (#696). Spec location: GET /.well-known/did.json, GET /identity/resolve/{did}. verification: probed - id: w3c-verifiable-credentials-2.0 conforms: true evidence: >- POST /credentials/issue and /credentials/verify in the spec; the sample declaration on compliance.html carries @context https://www.w3.org/ns/credentials/v2 and issuer did:web:api.moltrust.ch; the MoltGuard spec issues AgentTrustCredential / BuyerAgentCredential / TravelAgentCredential / VerifiedSkillCredential / PredictionTrackCredential as JWS. Provider states "DID Core + Verifiable Credentials v2 conformance" (compliance.html). Claim + contract; no third-party test-suite result published. verification: claim-plus-contract - id: x402 conforms: true evidence: >- x402 v2 discovery document served at /.well-known/x402.json on both hosts (11 priced endpoints, USDC on eip155:8453, facilitator https://x402.org/facilitator); MoltGuard OpenAPI declares securitySchemes.x402 (apiKey header X-PAYMENT, "x402 v2 payment receipt"), 402 responses with a PaymentRequired (x402.accepts[]) body on 11 operations and x-moltrust-pricing on each. The provider is listed as a Circle Alliance member (pricing page). verification: probed - id: erc-8004 conforms: true evidence: >- /.well-known/agent-registration.json served (agentId 21023 on eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432); agent card erc8004 extension (agentId 33553); spec operations GET /agents/{did}/erc8004, GET /resolve/erc8004/{agent_id}, POST /identity/erc8004/register|validate. Note the two different agent ids. verification: probed - id: rfc7517-jwks conforms: true evidence: >- RFC 7517 JWK Set at /.well-known/jwks.json on both hosts (four OKP/Ed25519 EdDSA keys); the agent card JWS and trust-score registry_signature resolve to keys in it. verification: probed - id: ucan-0.10.0 conforms: true evidence: >- POST /delegation/create description in the spec - "Mint a UCAN 0.10.0 delegation JWT (capabilities, attenuation, proof chain)"; compliance.html repeats it. Contract-declared; token format not independently verified. verification: claim-plus-contract - id: spiffe conforms: true evidence: >- SPIFFE-URI-to-DID binding surface in the spec (GET /identity/spiffe/{spiffe_uri}, POST /identity/spiffe/bind, DELETE /identity/spiffe/bind/{spiffe_uri}, GET /identity/spiffe). An identity-federation bridge, not a SPIFFE workload API implementation. verification: contract - id: ietf-draft-kroehl-agentic-trust-aae conforms: true evidence: >- The provider's own IETF Internet-Draft (draft-kroehl-agentic-trust-aae-00) for the Agent Authorization Envelope; /proof/info reports aae_profile "draft-kroehl-agentic-trust-aae-00"; conformance vectors published at github.com/MoltyCel/aae-conformance-vectors. verification: self-authored-standard - id: oauth2 conforms: false evidence: No oauth2 securityScheme in either spec, no RFC 8414 / 9728 metadata on any host. GET /auth/github + /auth/github/callback exist for signup via GitHub login, which is the provider consuming OAuth, not offering it. - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration 404 on moltrust.ch, api.moltrust.ch and uresolver.moltrust.ch. - id: rfc9728-protected-resource-metadata conforms: false evidence: /.well-known/oauth-protected-resource 404 on the MCP host (api.moltrust.ch); the MCP server needs no OAuth so none is expected. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt 404 on every host. A security contact (security@moltrust.ch) exists only in the GitHub README. - id: rfc9457-problem-details conforms: false evidence: >- Main API returns FastAPI {"detail": ...} bodies as application/json (135 declared 422s, live 400/401/404 observed); MoltGuard returns {"error","message"} objects. Zero application/problem+json media types across 257 operations. See errors/moltrust-ch-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: No Deprecation/Sunset headers documented, no deprecation policy page, no operation marked deprecated in either spec. - id: idempotency-key conforms: false evidence: Zero matches for "idempoten" / "Idempotency-Key" in either spec or the public docs. (An internal "credit-middleware idempotency" design spec exists in the provider's GitHub repo docs/specs/, but it is not a published contract.) - id: pagination conforms: true evidence: offset/limit query parameters on 5 operations (credits transactions, skills list, agents recent, etc.) and a cursor-style limit+since on GET /caep/pending/{did} (since = last event_id). No Link headers; no uniform envelope documented. verification: contract - id: openid-caep-shared-signals conforms: false evidence: The provider's "MolTrust CAEP Profile v1" is self-described (agent card + docs/caep.html) as "NOT SET/RFC 8417 compliant - not a Shared Signals stream/transmitter/receiver implementation". Recorded as non-conformant to avoid the name collision. - id: gdpr conforms: true evidence: >- Terms of Service section 6 ("GDPR Compliance ... data subject rights, lawful processing, and cross-border data transfers") and a versioned Privacy Notice (v1.1, 2026-06-04) with controller, Art. 27 EU representative status, legal bases (Art. 6(1)(a)/(b)/(c)/(f)), Art. 46 transfer safeguards (SCCs), retention periods and an Art. 15-21 rights table. Statement of posture, not a certification. verification: claim-only - id: swiss-nfadp conforms: true evidence: Terms 6 "Swiss nFADP Compliance"; Privacy Notice "Swiss FADP (nDSG)" section naming the FDPIC as supervisory authority. Controller is CryptoKRI GmbH, CHE-115.481.407, Zurich. verification: claim-only - id: soc2-type-ii conforms: false evidence: No SOC 2 report, trust center or certification claim found on moltrust.ch, api.moltrust.ch or the GitHub org. - id: iso-27001 conforms: false evidence: Not claimed anywhere. (ISO 42001 is named only as a mapping target in the "Sample Audit Evidence Bundle", not as a certification held.) domain_standards: note: >- Domain-standard signatures read from the CONTRACT (0.12.0 domain_standard_conformance). This provider's market - agent identity, authorization and trust - has real standards and the contract declares them. declared: - standard: W3C DID Core spec_location: openapi/moltrust-ch-openapi.yml#/paths/~1.well-known~1did.json (did_web_document__well_known_did_json_get) and #/paths/~1identity~1resolve~1{did} live: https://api.moltrust.ch/.well-known/did.json (200, @context https://www.w3.org/ns/did/v1) - standard: W3C Verifiable Credentials spec_location: openapi/moltrust-ch-openapi.yml#/components/schemas/IssueVCRequest, VerifyVCRequest, DelegationChainRequest; moltguard spec tags credential-issuance / shopping-vc / travel-vc live: sample MolTrustConformityDeclaration with @context https://www.w3.org/ns/credentials/v2 (compliance.html) - standard: A2A 1.0.0 AgentCard spec_location: a2a/moltrust-ch-agent-card.json (supportedInterfaces[], capabilities.extensions[], skills[]); openapi/moltrust-ch-openapi.yml#/components/schemas/A2ARequest, SendMessageRequest, GetTaskRequest ... live: https://api.moltrust.ch/.well-known/agent-card.json (200, signed) - standard: x402 v2 spec_location: openapi/moltrust-ch-moltguard-openapi.yml#/components/securitySchemes/x402 (X-PAYMENT), #/components/schemas/PaymentRequired, x-moltrust-pricing on 14 operations live: https://api.moltrust.ch/.well-known/x402.json (200) - standard: ERC-8004 Trustless Agents spec_location: openapi/moltrust-ch-openapi.yml#/paths/~1.well-known~1agent-registration.json, ~1agents~1{did}~1erc8004, ~1resolve~1erc8004~1{agent_id}, ~1identity~1erc8004~1register live: https://api.moltrust.ch/.well-known/agent-registration.json (200) - standard: MCP 2025-06-18 spec_location: mcp/moltrust-ch-mcp-tools.json (53 tools with inputSchema) live: https://api.moltrust.ch/mcp initialize -> protocolVersion 2025-06-18 - standard: UCAN 0.10.0 spec_location: openapi/moltrust-ch-openapi.yml#/paths/~1delegation~1create (description) + #/components/schemas/DelegationCreateRequest (capabilities, proofs[], ttl_seconds) - standard: SPIFFE ID binding spec_location: openapi/moltrust-ch-openapi.yml#/paths/~1identity~1spiffe~1bind, ~1identity~1spiffe~1{spiffe_uri} regulatory_alignment_claims: note: Prose claims on compliance.html / llms.txt that are NOT contract conformance and are recorded as claims only - EU AI Act Article 12 logging support (with the provider's own caveat that Art. 12(1) responsibility stays with the AI-system provider), Singapore IMDA MGF for Agentic AI alignment, NIST AI RMF and EU AI Act article mappings (PDFs), OWASP LLM Top 10 / MITRE ATLAS alignment, Agent Trust Framework ecosystem listing, Circle Alliance membership. compliance_pointer_basis: >- A Compliance pointer is emitted to https://moltrust.ch/compliance.html on the strength of the published GDPR / Swiss nFADP posture (Terms 6, Privacy Notice v1.1) and the compliance page's standards-and- references section. No third-party certification (SOC 2, ISO 27001) is published and there is no trust center; the pointer asserts a published compliance posture, not an audit.