generated: '2026-08-09' method: derived source: openapi/_original/serbia-company-data-openapi.json + live probes + examples/serbia-company-data-402-payment-required.json standards: - id: openapi-3.1 conforms: true evidence: 'Served OpenAPI declares openapi: 3.1.0 with three paths and unique operationIds.' - id: apisjson-0.21 conforms: true evidence: >- The provider self-serves /.well-known/apis.json with specificationVersion 0.21, an aid, and typed properties (OpenAPI, Documentation, Pricing, License). - id: x402-v2 conforms: true evidence: >- Live 402 responses carry a base64 PAYMENT-REQUIRED header with x402Version 2, an accepts[] entry using scheme "exact" on network eip155:8453, and maxTimeoutSeconds — matching the x402 HTTP transport v2 spec. - id: x402-bazaar-extension conforms: true evidence: >- Each PAYMENT-REQUIRED document carries extensions.bazaar with an info block (input/output example) and a JSON Schema, the discovery payload the x402 Bazaar indexes. - id: json-schema-2020-12 conforms: true evidence: >- The bazaar extension schemas declare $schema https://json-schema.org/draft/2020-12/schema — harvested to json-schema/. - id: rfc9457-problem-details conforms: false evidence: 'Errors are a bare {"error":"..."} object; no application/problem+json media type is used.' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers and no deprecation policy. - id: oauth2 conforms: false evidence: No securitySchemes in the OpenAPI and no OAuth discovery documents; access is payment-gated, not identity-gated. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404. - id: a2a-agent-card conforms: false evidence: Both /.well-known/agent-card.json and /.well-known/agent.json return 404. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists — this is a synchronous read-only lookup API. - id: hsts conforms: true evidence: 'strict-transport-security: max-age=63072000; includeSubDomains; preload observed on every route.' - id: eip-3009-transfer-with-authorization conforms: true evidence: >- The accepts[] entry names USD Coin version 2 on Base with an exact-scheme payTo address, the EIP-3009 authorization form the x402 exact/EVM scheme settles with. discovery_index: registered: false index: Coinbase CDP x402 bazaar discovery index url: https://api.cdp.coinbase.com/platform/v2/x402/discovery/resources checked: '2026-08-14' resources_scanned: 15392 matches: 0 notes: >- Every 402 challenge this API returns carries a complete bazaar extension block — the exact discovery payload the x402 Bazaar indexes — yet the resource does not appear anywhere in the CDP discovery index. The full index was paged (offset pagination, 15,392 resources, 2026-08-14) with zero matches on the host or the description. The service is machine-discoverable at the endpoint but not from the catalog a buyer agent browses, which is the single cheapest agent-reach fix available to this provider. data_licensing: license: Serbian Open Data License 1.0 identifier: SODL-1.0 url: https://data.gov.rs/sr/terms/ attribution: >- Publisher named as the Serbian Business Registers Agency (APR); the provider documents that the two APR whole-dataset snapshots were joined on registration number, compacted and normalized, with no fields added from APR's website or paid services. redistribution_disclosure: true compliance_program: published: false certifications: [] notes: >- No SOC 2, ISO 27001, PCI, GDPR or trust-centre claims are published. This is a single-purpose open-data republisher handling no customer data, no accounts and no PII — there is nothing to certify, and no Compliance pointer is emitted.