midwoodflowershop.com logo

midwoodflowershop.com

verified_user Multi-version UCP compliance, backward compatibility & transport audit

schedule Last scanned 5/4/2026

B- 82/100

Conformance

97%
45%

Capability

100%
14%

Coverage

37%
12%

Backward Compat

0%
9%

Negative

100%
8%

Transport

100%
8%

Latency

99%
4%

Audit Details

53% Passing Rate
check_circle DISC-0012
Cache-Control max-age is within recommended bounds

Completed in 70ms

Pass
check_circle DISC-0006
Profile response advertises cache headers

Completed in 95ms

Pass
check_circle DISC-0003
Profile declares at least the checkout capability

Completed in 104ms

Pass
check_circle DISC-0016
Capability version strings are valid ISO dates

Completed in 101ms

Pass
check_circle DISC-0008
Profile response Content-Type is application/json

Completed in 95ms

Pass
cancel DISC-0010
Discovery endpoint exposes CORS headers

Discovery response is missing Access-Control-Allow-Origin header

Fail
check_circle DISC-0007
Profile is served over HTTPS

Completed in 97ms

Pass
check_circle DISC-0011
Two consecutive profile fetches return identical bodies

Completed in 162ms

Pass
check_circle DISC-0020
Signing JWKs use only allowed kty/crv values

Completed in 98ms

Pass
check_circle DISC-0015
No duplicate capability entries (same name + version)

Completed in 97ms

Pass
warning DISC-0017
OpenAPI servers[] URL is reachable

Profile has no loadable service-level OpenAPI document

Warn
check_circle DISC-0001
Business profile has a valid structure

Completed in 100ms

Pass
warning DISC-0022
Merchant responses are signed with the published signing_keys

Merchant publishes signing_keys but did not sign this response (no X-UCP-Signature / RFC 9421 / body JWS). Signing is recommended so agents can verify response authenticity.

Warn
check_circle DISC-0021
robots.txt allows AI agents to read the UCP profile

Completed in 765ms

Pass
check_circle DISC-0014
All declared schema URLs use HTTPS

Completed in 100ms

Pass
check_circle DISC-0019
Signing keys are importable via Web Crypto

Completed in 119ms

Pass
check_circle DISC-0002
Profile advertises well-formed signing keys

Completed in 98ms

Pass
check_circle DISC-0018
Service binding transports are in the allowed set

Completed in 98ms

Pass
check_circle DISC-0005
Profile declares a ucp.version string

Completed in 98ms

Pass
check_circle DISC-0013
Profile ucp.version is one the grader recognizes

Completed in 95ms

Pass
check_circle DISC-0009
Profile is served at the canonical .well-known/ucp path

Completed in 96ms

Pass
warning SCHEMA-INT-0004
Declared capabilities match operations in the OpenAPI

No OpenAPI operations available to cross-check

Warn
check_circle SCHEMA-INT-0009
Capability JSON Schemas declare a modern $schema draft
Pass
check_circle SCHEMA-INT-0003
Capability-level JSON Schemas are well-formed
Pass
warning SCHEMA-INT-0008
OpenAPI components.schemas has no orphans

Profile has no loadable service-level OpenAPI document

Warn
warning SCHEMA-INT-0002
Service-level OpenAPI document is valid OpenAPI 3.x

No service-level OpenAPI schema was loaded

Warn
warning SCHEMA-INT-0006
Every OpenAPI operation declares a 2xx JSON response schema

Profile has no loadable service-level OpenAPI document

Warn
check_circle SCHEMA-INT-0005
Every $ref referenced schema document is reachable

Completed in 253ms

Pass
check_circle SCHEMA-INT-0001
All declared schema URLs return 200
Pass
help SCHEMA-0005
Cancel session response matches the OpenAPI schema

Merchant gates checkout creation behind authentication (HTTP 401); cannot validate cancel_session shape without credentials

Skip
help SCHEMA-0002
Create session response matches the OpenAPI schema

Merchant gates checkout creation behind authentication (HTTP 401); cannot validate the response shape without credentials

Skip
check_circle SCHEMA-0001
Discovery profile matches the published JSON Schema

Completed in 94ms

Pass
help SCHEMA-0003
Get session response matches the OpenAPI schema

Merchant gates checkout creation behind authentication (HTTP 401); cannot validate get_session shape without credentials

Skip
help SCHEMA-0004
Update session response matches the OpenAPI schema

Merchant gates checkout creation behind authentication (HTTP 401); cannot validate update_session shape without credentials

Skip
help CHK-0008
Canceling a session twice with the same idempotency key is idempotent

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0007
Cancel a checkout session

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0001
Create checkout session with defaults

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0002
Repeated createSession with same idempotency key returns same session

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0003
Create session then set shipping address

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0004
Retrieve a checkout session by id

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0009
Reusing an Idempotency-Key with a different body must be rejected

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0010
update_checkout is idempotent on replay and rejects conflicting replays

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help CHK-0005
Select a shipping method on a checkout session

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
help FUL-0001
Shipping methods are returned after setting an address

Merchant gates checkout creation behind authentication (HTTP 401); cannot probe further without credentials

Skip
warning CAP-CAT-0002
Catalog capability advertised for product lookup

Profile does not declare dev.ucp.shopping.catalog.lookup

Warn
warning CAP-CAT-0001
Catalog capability is declared

Profile does not declare dev.ucp.shopping.catalog.search

Warn
check_circle CAP-CHK-0001
Checkout capability is declared and reachable

Completed in 96ms

Pass
check_circle CAP-FUL-0001
Fulfillment capability is declared
Pass

Business Profile

Services

dev.ucp.shopping
rest

Capabilities

dev.ucp.shopping.checkout
v2026-04-08
Implemented
Tests: 2/8 passed
dev.ucp.shopping.discount
v2026-04-08
Implemented
Tests: 0/1 passed
dev.ucp.shopping.fulfillment
v2026-04-08
Implemented
Tests: 1/2 passed
dev.ucp.shopping.order
v2026-04-08
Implemented

Payment Handlers

account_balance_wallet
Google Pay
com.google.pay
5 config keys