d295dhs4zm8zq2.cloudfront.net
verified_user Multi-version UCP compliance, backward compatibility & transport audit
schedule Last scanned 5/4/2026
Conformance
42%Capability
100%Coverage
43%Backward Compat
20%Negative
48%Transport
80%Latency
97%Audit Details
Cache-Control max-age is within recommended bounds
Completed in 19ms
Profile response advertises cache headers
Completed in 36ms
Profile declares at least the checkout capability
Completed in 36ms
Capability version strings are valid ISO dates
Completed in 33ms
Profile response Content-Type is application/json
Completed in 36ms
Discovery endpoint exposes CORS headers
Completed in 33ms
Profile is served over HTTPS
Completed in 33ms
Two consecutive profile fetches return identical bodies
Completed in 43ms
Signing JWKs use only allowed kty/crv values
Completed in 34ms
No duplicate capability entries (same name + version)
Completed in 33ms
OpenAPI servers[] URL is reachable
OpenAPI document at https://d295dhs4zm8zq2.cloudfront.net/mcp/schema/shopping declares no servers[] entry — agents have no endpoint to call. Add a servers[] array per https://spec.openapis.org/oas/v3.1.0#server-object
Business profile has a valid structure
Completed in 33ms
Merchant responses are signed with the published signing_keys
Response signature failed Web Crypto verification: Web Crypto verify returned false
robots.txt allows AI agents to read the UCP profile
robots.txt returned 403
All declared schema URLs use HTTPS
Completed in 34ms
Signing keys are importable via Web Crypto
Completed in 34ms
Profile advertises well-formed signing keys
Completed in 33ms
Service binding transports are in the allowed set
Completed in 35ms
Profile declares a ucp.version string
Completed in 35ms
Profile ucp.version is one the grader recognizes
Completed in 35ms
Profile is served at the canonical .well-known/ucp path
Completed in 39ms
Declared capabilities match operations in the OpenAPI
No OpenAPI operations available to cross-check
Capability JSON Schemas declare a modern $schema draft
Capability-level JSON Schemas are well-formed
OpenAPI components.schemas has no orphans
Service-level OpenAPI document is valid OpenAPI 3.x
Schema document is missing the "openapi" version field
Every OpenAPI operation declares a 2xx JSON response schema
OpenAPI declares no operations
Every $ref referenced schema document is reachable
Completed in 2088ms
All declared schema URLs return 200
2 of 6 schema URLs failed to load: [service] https://ucp.dev/schemas/shopping/openapi.json → http_404 [payment] https://ucp.dev/2026-01-23/schemas/payment-handlers/processor_tokenizer.json → http_404
Cancel session response matches the OpenAPI schema
Could not create session: 400
Create session response matches the OpenAPI schema
Expected 2xx, got 400
Discovery profile matches the published JSON Schema
Completed in 35ms
Get session response matches the OpenAPI schema
Could not create session: 400
Update session response matches the OpenAPI schema
Could not create session: 400
Canceling a session twice with the same idempotency key is idempotent
createSession returned status=400
Canceling a session twice with the same idempotency key is idempotent
createSession returned status=200
Cancel a checkout session
createSession returned 400
Cancel a checkout session
createSession returned 200
Create checkout session with defaults
createSession returned status=400
Create checkout session with defaults
createSession returned status=200
Repeated createSession with same idempotency key returns same session
First create failed: 400
Repeated createSession with same idempotency key returns same session
First create failed: 200
Create session then set shipping address
createSession returned 400
Create session then set shipping address
createSession returned 200
Retrieve a checkout session by id
createSession returned 400
Retrieve a checkout session by id
createSession returned 200
Reusing an Idempotency-Key with a different body must be rejected
First createSession returned status=400
Reusing an Idempotency-Key with a different body must be rejected
First createSession returned status=200
update_checkout is idempotent on replay and rejects conflicting replays
createSession returned status=400
update_checkout is idempotent on replay and rejects conflicting replays
createSession returned status=200
Select a shipping method on a checkout session
createSession returned 400
Select a shipping method on a checkout session
createSession returned 200
Catalog capability advertised for product lookup
Profile does not declare dev.ucp.shopping.catalog.lookup
Catalog capability advertised for product lookup
Profile does not declare dev.ucp.shopping.catalog.lookup
Catalog capability is declared
Profile does not declare dev.ucp.shopping.catalog.search
Catalog capability is declared
Profile does not declare dev.ucp.shopping.catalog.search
Checkout capability is declared and reachable
Completed in 234ms
Checkout capability is declared and reachable
Completed in 445ms
Fulfillment capability is declared
Profile does not declare dev.ucp.shopping.fulfillment
Fulfillment capability is declared
Profile does not declare dev.ucp.shopping.fulfillment