generated: '2026-09-19' method: searched source: https://optionsahoy.com/openapi.json derived_from: openapi/optionsahoy-com-openapi.json docs: - https://optionsahoy.com/for-agents - https://optionsahoy.com/verification - https://optionsahoy.com/methodology summary: >- OptionsAhoy's conformance profile is the open agent-protocol stack rather than any enterprise or financial interchange standard: OpenAPI 3.1.0, an MCP server at protocol version 2024-11-05 with tool annotations and outputSchema, an A2A 0.3.0 agent card, JSON-RPC 2.0 on both, llms.txt, RFC 9116 security.txt on two hosts, an MCP Registry server.json, SLSA build provenance on npm, and a robots.txt Content-Signal. It declares no OAuth/OIDC (keyless by design), no RFC 9457 problem details, no RFC 9727 API catalog, no APIs.json and no RFC 8594 sunset signalling. Its market — equity-compensation tax calculation — has no interchange standard to conform to; the domain claims it does make are about correctness against IRS published constants and independent tax engines, which are verification claims, not protocol conformance, and are recorded below as such. standards: - id: openapi-3.1 conforms: true version: 3.1.0 evidence: 'openapi/optionsahoy-com-openapi.json openapi "3.1.0"; parses; 11 paths, 11 operations, 21 component schemas, 3 component responses; every operation has operationId, summary, description and tags; 8 request-body examples; servers[] https://optionsahoy.com; info.contact, info.license and externalDocs present; no securitySchemes (keyless).' gaps: - Operation optimizeRsuLotOrder is tagged RsuLotOptimize, which tags[] does not declare. - The generic CalculatorSuccess response says "sample a call to discover the full structure", although per-calculator result schemas are in fact declared. - info.version 1.10.1 lags the live server (1.10.2). - id: json-schema-2020-12 conforms: true evidence: OpenAPI 3.1 schema objects (const, pattern, format date, enum) in components.schemas; MCP tools carry inputSchema with required[] and outputSchema per tool (mcp/optionsahoy-com-mcp-tools.json). - id: mcp name: Model Context Protocol version: '2024-11-05' conforms: true evidence: 'POST https://optionsahoy.com/mcp initialize returned protocolVersion "2024-11-05", serverInfo {OptionsAhoy, 1.10.2}, capabilities tools/resources/prompts, an mcp-session-id header; tools/list returned 8 tools with inputSchema, outputSchema and annotations (readOnlyHint, idempotentHint, destructiveHint, openWorldHint); resources/list 9; prompts/list 8. See mcp/optionsahoy-com-mcp.yml.' note: The server negotiates 2024-11-05 even when a client offers 2025-03-26; Streamable HTTP transport with the newer session header is in use, so the declared version is conservative. - id: mcp-registry-server-json name: MCP Registry server.json (schema 2025-12-11) conforms: true evidence: https://github.com/AlvisoOculus/optionsahoy-mcp/blob/main/server.json declares $schema static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json, name io.github.AlvisoOculus/optionsahoy-mcp, remotes[] streamable-http https://optionsahoy.com/mcp; the Official MCP Registry lists it as active (latest 1.10.1). - id: a2a name: Agent2Agent protocol version: '0.3.0' conforms: true evidence: a2a/optionsahoy-com-agent-card.json — protocolVersion "0.3.0", url https://optionsahoy.com/a2a, preferredTransport JSONRPC, capabilities object, skills[] of 8, provider block; POST https://optionsahoy.com/a2a answered tasks/get with A2A error -32001 and message/send with -32602. Graded conformant in a2a/optionsahoy-com-a2a.yml. - id: json-rpc-2.0 conforms: true evidence: 'Both /mcp and /a2a answer {"jsonrpc":"2.0", ...} with standard error objects (-32602 Invalid params observed).' - id: llms-txt name: llms.txt (llmstxt.org) conforms: true evidence: https://optionsahoy.com/llms.txt (200, text/plain, 17,230 bytes) — H1, blockquote summary, sectioned link lists with absolute URLs; a companion llms-full.txt is also served (190 KB, not committed). robots.txt carries a "# llms-txt:" hint. Saved verbatim under llms/. - id: rfc9116-security-txt conforms: true evidence: 'https://optionsahoy.com/.well-known/security.txt (200; Contact, Preferred-Languages, Canonical, Expires) and https://api.optionsahoy.com/.well-known/security.txt (200; adds Policy). Both saved under well-known/.' gaps: - The api host's Policy URL (https://optionsahoy.com/security-policy) returns 404. - No Encryption or Acknowledgments field; the apex file has no Policy field. - id: content-signals name: Content Signals (contentsignals.org) in robots.txt conforms: true evidence: 'https://optionsahoy.com/robots.txt carries "Content-Signal: search=yes, ai-input=yes, ai-train=yes" with an explanatory comment, and an explicit per-crawler Allow list for GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and a dozen others. A published machine-readable consent statement for AI crawling.' - id: slsa-provenance name: SLSA build provenance (npm) conforms: true evidence: 'https://registry.npmjs.org/-/npm/v1/attestations/optionsahoy-mcp@1.10.2 returns two attestations (predicate types github.com/npm/attestation/.../specs/publish/v0.1 and https://slsa.dev/provenance/v1); the provider documents "published with provenance ... verify with npm audit signatures".' - id: cors conforms: true evidence: 'Observed access-control-allow-origin: * on /api/v1, /api/v1/qsbs (400), /mcp and the agent card; OPTIONS /api/v1/qsbs returns 204 with allow-methods POST, OPTIONS and max-age 86400. The contract states "Unauthenticated, wide-open CORS".' - id: schema-org-jsonld name: schema.org WebApplication JSON-LD on tool pages conforms: false claimed: true evidence: The for-agents page claims "schema.org WebApplication JSON-LD on every tool page, including a featureList array". The server-rendered HTML of https://optionsahoy.com/tools/amt-iso fetched 2026-09-19 contained zero