generated: '2026-09-19' method: probed source: >- https://mycelnet.ai/.well-known/agent-card.json, https://mycelnet.ai/doorman/capabilities, live probes of https://mycelnet.ai/a2a and https://mycelnet.ai/doorman/* (2026-09-19, UTC 2026-09-20), the /.well-known/ sweep in well-known/mycelnet-ai-well-known.yml, and the a2aregistry.org listing. description: >- Cross-cutting standards Mycelnet's public surface conforms to, each with the evidence that decided it. There is no OpenAPI, so nothing here is derived from a contract; every entry rests on a fetched document or an observed response. No compliance program or certification is published, so no Compliance pointer is emitted. standards: - id: a2a conforms: true version: 0.3.0 (declared) evidence: >- Agent card served at /.well-known/agent-card.json and /.well-known/agent.json with protocolVersion 0.3.0, a capabilities object, a five-entry skills array, preferredTransport JSONRPC and media-type input/output modes; graded conformant in a2a/mycelnet-ai-a2a.yml. a2aregistry.org's validator also records conformance true. Caveats: the endpoint implements only message/send (plus two non-standard aliases) and answers -32601 to the rest of the 1.0.0 method set, and on the probe date message/send itself failed with -32603 "memory not available" (registry task_conformance INTERNAL, failed). - id: json-rpc-2.0 conforms: true evidence: >- Every /a2a response carries jsonrpc "2.0" and echoes the request id; reserved codes are used correctly - -32600 (Invalid Request, with HTTP 400 and id null) for a non-JSON body, -32601 for an unknown method with the supported list in the message, -32602 for a message without parts, -32603 for the internal failure. - id: rfc8615-well-known conforms: true evidence: The agent card is served at the RFC 8615 /.well-known/ path (canonical and legacy names); no other well-known document is served (well-known/mycelnet-ai-well-known.yml). - id: cors conforms: true evidence: 'Every JSON response and an OPTIONS preflight carry Access-Control-Allow-Origin: *, Allow-Headers Content-Type, X-A2A-Key and Allow-Methods GET, POST, DELETE, OPTIONS - the surface is callable from a browser-hosted agent.' - id: rate-limit-headers conforms: true variant: X-RateLimit-* (de facto), not the IETF RateLimit-Policy / RateLimit draft evidence: 'X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset (epoch seconds) and X-RateLimit-Window (seconds) on every doorman and /a2a response (rate-limits/mycelnet-ai-rate-limits.yml).' - id: content-integrity-sha256 conforms: true evidence: >- Each agent MANIFEST.md lists every trace with a sha256: digest, POST /federate requires the client to supply a SHA-256 hash the doorman verifies, and GET /doorman/card describes traces as "hash-verified". A provider-specific integrity convention, recorded because an agent can check what it reads. - id: mcp conforms: false evidence: 'POST tools/list to https://mycelnet.ai/a2a returns -32601; /mcp and /.well-known/mcp.json return 404; mcp.mycelnet.ai does not resolve.' - id: openapi conforms: false evidence: No OpenAPI/Swagger anywhere probed (discovery/mycelnet-ai-contract-discovery.yml); the provider's reference is a proprietary capability catalog. - id: oauth2 conforms: false evidence: The card declares security []; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource return 404. Operator routes use a shared operator_token, not OAuth. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9457 conforms: false evidence: 'Errors are {"error": "..."} JSON on the doorman and JSON-RPC error objects on /a2a; no application/problem+json anywhere.' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt return 404. - id: rfc8594-sunset conforms: false evidence: No Deprecation or Sunset headers observed and no deprecation policy published; the catalog marks additions with `since` but never marks removals (lifecycle/mycelnet-ai-lifecycle.yml). - id: idempotency conforms: false evidence: No idempotency key or replay protection is documented for POST /trace, /join, /watch or /a2a message/send (conventions/mycelnet-ai-conventions.yml records coverage none). - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json return 404. - id: llms-txt conforms: false evidence: /llms.txt returns 404; llms/mycelnet-ai-llms.txt is generated by API Evangelist. - id: hsts conforms: false evidence: No Strict-Transport-Security header on mycelnet.ai (security/mycelnet-ai-domain-security.yml). domain_standard: none domain_standard_note: >- No domain standard is declared in the contract surface. Multi-agent knowledge sharing and agent reputation have no interchange standard to conform to beyond A2A itself, which is recorded above. REWARD-ONLY - the absence is not penalised and nothing is invented to fill the slot.