generated: '2026-08-30' method: probed source: 'live probes of https://truebotanicals.com/.well-known/ucp, /.well-known/openid-configuration, /api/ucp/mcp and /api/2026-01/graphql.json, 2026-08-30' standards: - id: ucp name: Universal Commerce Protocol conforms: true version: '2026-08-25' evidence: 'GET /.well-known/ucp returns HTTP 200 with a UCP merchant profile declaring version 2026-08-25 and supported_versions 2026-08-25, 2026-04-08 and 2026-01-23, service dev.ucp.shopping over transport mcp, and capabilities dev.ucp.shopping.{cart,checkout,fulfillment,discount,order,catalog.search,catalog.lookup}.' spec: https://ucp.dev/2026-08-25/specification/overview/ file: well-known/true-botanicals-ucp.json - id: mcp name: Model Context Protocol conforms: true evidence: 'POST /api/ucp/mcp with method tools/list returns a JSON-RPC 2.0 result carrying 13 tools, each with a JSON Schema 2020-12 inputSchema. Response header x-shopify-ucp-mcp-api-version: 2026-08-25.' file: mcp/true-botanicals-tools-list.json - id: jsonrpc2 name: JSON-RPC 2.0 conforms: true evidence: 'Both success and error payloads carry jsonrpc "2.0" with matching id; errors use the reserved negative code space (-32001 UCP discovery failed, -32000 AuthenticationRequired).' - id: json-schema-2020-12 name: JSON Schema 2020-12 conforms: true evidence: 'Every MCP tool inputSchema declares $schema https://json-schema.org/draft/2020-12/schema.' - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: 'GET /.well-known/openid-configuration returns HTTP 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri, response_types_supported, subject_types_supported and id_token_signing_alg_values_supported.' file: well-known/true-botanicals-openid-configuration.json - id: oauth2 name: OAuth 2.0 conforms: true evidence: 'Authorization-code flow with refresh_token and urn:ietf:params:oauth:grant-type:jwt-bearer grants; client_secret_basic and client_secret_post token-endpoint auth.' - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: 'GET /.well-known/oauth-authorization-server returns HTTP 200 with authorization-server metadata.' file: well-known/true-botanicals-oauth-authorization-server.json - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: [S256] in the discovery document.' - id: rfc7523 name: JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants (RFC 7523) conforms: true evidence: 'grant_types_supported includes urn:ietf:params:oauth:grant-type:jwt-bearer.' - id: iso4217 name: ISO 4217 currency minor units conforms: true evidence: 'Every price-bearing MCP tool description states prices are integers in the currency''s ISO 4217 minor units paired with a currency code.' - id: llmstxt name: llms.txt conforms: true evidence: 'GET /llms.txt returns HTTP 200 with a real agent-instruction document (4,341 bytes), mirrored at /agents.md and advertised from robots.txt and /sitemap_agentic_discovery.xml.' file: llms/true-botanicals-llms.txt - id: graphql name: GraphQL conforms: true evidence: 'POST /api/2026-01/graphql.json answers introspection unauthenticated — 424 types, QueryRoot and Mutation root types; field errors carry the standard errors[] envelope with locations, path and extensions.' - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: 'No application/problem+json response was observed on any surface. Errors use the JSON-RPC 2.0 error object (MCP) and the GraphQL errors[] envelope instead — both are correct for their protocol.' - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: 'GET /.well-known/security.txt returned HTTP 404 on both truebotanicals.com and tnbotanicals.myshopify.com.' - id: rfc8594 name: Sunset header (RFC 8594) conforms: false evidence: 'No Sunset or Deprecation header observed on any probed response.' domain_standard: id: ucp market: agentic retail commerce declared_in_contract: true evidence: 'The contract declares the standard rather than a marketing page claiming it: /.well-known/ucp is a UCP merchant profile whose service identifier is the UCP namespace dev.ucp.shopping, whose capability identifiers are the UCP namespaces dev.ucp.shopping.checkout / .cart / .fulfillment / .discount / .order / .catalog.search / .catalog.lookup, and whose schema pointers resolve to ucp.dev/2026-08-25/schemas/shopping/*. The MCP endpoint echoes it back as the response header x-shopify-ucp-mcp-api-version: 2026-08-25.' extension: 'One vendor extension is declared alongside the standard ones — dev.shopify.catalog, which extends dev.ucp.shopping.catalog.search and .lookup and requires protocol >= 2026-08-25.' buyer_note: 'An agent that already speaks UCP can search, cart and check out here with no bespoke connector. That is platform-conferred: every Shopify merchant gets it, so it distinguishes the platform more than it distinguishes True Botanicals.' certifications: published: false note: 'No SOC 2, ISO 27001, PCI DSS or other infosec certification is published by True Botanicals; no trust centre and no security disclosure programme were found (probe-security-programs.py: vdp=none trust=none). The company does publish a product-safety certification, MADE SAFE, which is a cosmetics-ingredient certification and not an information-security or API compliance programme — it is recorded here so nobody mistakes it for one, and it is deliberately NOT wired as a Compliance pointer.'