generated: '2026-09-19' method: searched source: >- Live probes of https://opplevagent.no on 2026-09-19 (OpenAPI, agent card, MCP initialize/tools/list, REST responses and headers, /.well-known paths, page JSON-LD) cross-checked against llms.txt and the vilkår/personvern pages. standards: - id: openapi-3.1 name: OpenAPI 3.1 conforms: true evidence: >- https://opplevagent.no/openapi.json (HTTP 200, application/json) declares "openapi": "3.1.0" with 7 paths / 7 operations, unique operationIds, 2 component schemas and in-spec response examples. Saved at openapi/_original/opplevagent-no-openapi.json. caveat: No tags, no securitySchemes, and the 400/404 responses declare no content schema; four documented write operations are absent from the contract (see overlays/). - id: a2a-1.0 name: A2A Agent Card and JSON-RPC binding conforms: true evidence: >- /.well-known/agent-card.json served with protocolVersion 1.0.0 and graded conformant (a2a/opplevagent-no-a2a.yml); a live POST https://opplevagent.no/a2a message/send returned a Task with status.state completed and artifacts. - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: Both /a2a and /mcp answered with jsonrpc "2.0" envelopes; a bare tools/list returned a well-formed error object with code -32000, and prompts/list returned -32601. - id: mcp-streamable-http name: Model Context Protocol — Streamable HTTP transport conforms: true evidence: >- POST https://opplevagent.no/mcp initialize returned 200 text/event-stream with mcp-session-id, protocolVersion 2024-11-05 negotiated; the server card lists supported versions up to 2025-11-25 and states the 2026-07-28 era is not supported. - id: ietf-ratelimit-headers name: IETF RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: true evidence: >- Live responses from /api/opplevelser/categories, /api/opplevelser/discover, /a2a and /mcp carried RateLimit-Policy (300;w=900 or 200;w=900), RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset. - id: rfc8615-well-known name: RFC 8615 Well-Known URIs conforms: true evidence: /.well-known/agent-card.json, /.well-known/mcp/server-card.json, /.well-known/mcp.json and /.well-known/agents.txt all 200 (well-known/opplevagent-no-well-known.yml). - id: llms-txt name: llms.txt conforms: true evidence: https://opplevagent.no/llms.txt HTTP 200 text/plain, 12,421 bytes, saved verbatim to llms/opplevagent-no-llms.txt. - id: hsts name: HTTP Strict Transport Security conforms: true evidence: strict-transport-security max-age=31536000; includeSubDomains on every response; TLS 1.3 (security/opplevagent-no-domain-security.yml). - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: Errors are plain application/json objects {"error":"Invalid query","details":[...]} and {"error":"Not found"}; no application/problem+json anywhere. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returned 404. - id: oauth2 conforms: false evidence: No OAuth flow; the surface is anonymous with an optional X-API-Key. /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc9727-api-catalog name: RFC 9727 API Catalog conforms: false evidence: >- /.well-known/api-catalog returned 404 on opplevagent.no. The Link: response header advertises an api-catalog on rettfrabonden.com (a sibling site by the same operator), which is not this provider's catalog. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json all 404. - id: pagination-cursor conforms: false evidence: Discovery accepts only limit (default 20, max 100) and returns count/total; there is no offset, page or cursor parameter. - id: idempotency-key conforms: false evidence: No Idempotency-Key header or replay key is documented on any write path; the MCP book_gardssalg tool declares idempotentHint false. domain_standard: - id: schema-org-tourist-attraction name: Schema.org TouristAttraction / Offer (tourism vocabulary) conforms: true surface: html-json-ld evidence: >- Each experience page embeds application/ld+json with @type TouristAttraction, touristType, PostalAddress (addressCountry NO), an Offer (price, priceCurrency NOK, availability) and a provider Organization — e.g. https://opplevagent.no/opplevelse/forsvarsmuseet-akershus-festning-medieval-fortress-military-museum-oslo--6d325224. The home page embeds a WebSite with SearchAction. This is the HTML surface, not the API contract: the OpenAPI Experience schema uses its own field names (fylke, kommune, price_from) rather than schema.org terms. compliance_program: published: false note: >- No certifications, trust center or compliance claims are published. The provenance page explicitly says it "is not a claim of certification or compliance with any specific regulation". No Compliance pointer is emitted.