practical.stream logo

practical.stream

verified_user Multi-version UCP compliance, backward compatibility & transport audit

schedule Last scanned 5/4/2026

F 54/100

Conformance

49%
45%

Capability

100%
14%

Coverage

24%
12%

Backward Compat

0%
9%

Negative

44%
8%

Transport

100%
8%

Latency

99%
4%

Audit Details

57% Passing Rate
check_circle DISC-0012
Cache-Control max-age is within recommended bounds

Completed in 33ms

Pass
check_circle DISC-0006
Profile response advertises cache headers

Completed in 74ms

Pass
check_circle DISC-0003
Profile declares at least the checkout capability

Completed in 65ms

Pass
check_circle DISC-0016
Capability version strings are valid ISO dates

Completed in 66ms

Pass
check_circle DISC-0008
Profile response Content-Type is application/json

Completed in 74ms

Pass
cancel DISC-0010
Discovery endpoint exposes CORS headers

Discovery response is missing Access-Control-Allow-Origin header

Fail
check_circle DISC-0007
Profile is served over HTTPS

Completed in 54ms

Pass
check_circle DISC-0011
Two consecutive profile fetches return identical bodies

Completed in 104ms

Pass
warning DISC-0020
Signing JWKs use only allowed kty/crv values

Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant

Warn
check_circle DISC-0015
No duplicate capability entries (same name + version)

Completed in 65ms

Pass
check_circle DISC-0017
OpenAPI servers[] URL is reachable

Completed in 332ms

Pass
cancel DISC-0001
Business profile has a valid structure

Business profile failed schema validation

Fail
help DISC-0022
Merchant responses are signed with the published signing_keys

Profile declares no signing_keys; nothing to verify against. DISC-0002 tracks absence separately.

Skip
check_circle DISC-0021
robots.txt allows AI agents to read the UCP profile

Completed in 108ms

Pass
cancel DISC-0014
All declared schema URLs use HTTPS

(bindings ?? []) is not iterable

Fail
warning DISC-0019
Signing keys are importable via Web Crypto

Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant

Warn
warning DISC-0002
Profile advertises well-formed signing keys

Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant

Warn
cancel DISC-0018
Service binding transports are in the allowed set

(bindings ?? []) is not iterable

Fail
check_circle DISC-0005
Profile declares a ucp.version string

Completed in 66ms

Pass
check_circle DISC-0013
Profile ucp.version is one the grader recognizes

Completed in 74ms

Pass
check_circle DISC-0009
Profile is served at the canonical .well-known/ucp path

Completed in 113ms

Pass
warning SCHEMA-INT-0004
Declared capabilities match operations in the OpenAPI

No OpenAPI operations available to cross-check

Warn
check_circle SCHEMA-INT-0009
Capability JSON Schemas declare a modern $schema draft
Pass
check_circle SCHEMA-INT-0003
Capability-level JSON Schemas are well-formed
Pass
check_circle SCHEMA-INT-0008
OpenAPI components.schemas has no orphans
Pass
cancel SCHEMA-INT-0002
Service-level OpenAPI document is valid OpenAPI 3.x

OpenAPI document declares zero path operations

Fail
warning SCHEMA-INT-0006
Every OpenAPI operation declares a 2xx JSON response schema

OpenAPI declares no operations

Warn
check_circle SCHEMA-INT-0005
Every $ref referenced schema document is reachable

Completed in 1800ms

Pass
check_circle SCHEMA-INT-0001
All declared schema URLs return 200
Pass
cancel SCHEMA-0005
Cancel session response matches the OpenAPI schema

Could not create session: 405

Fail
cancel SCHEMA-0002
Create session response matches the OpenAPI schema

Expected 2xx, got 405

Fail
check_circle SCHEMA-0001
Discovery profile matches the published JSON Schema

Completed in 64ms

Pass
cancel SCHEMA-0003
Get session response matches the OpenAPI schema

Could not create session: 405

Fail
cancel SCHEMA-0004
Update session response matches the OpenAPI schema

Could not create session: 405

Fail
cancel CHK-0008
Canceling a session twice with the same idempotency key is idempotent

createSession returned status=405

Fail
cancel CHK-0007
Cancel a checkout session

createSession returned 405

Fail
cancel CHK-0001
Create checkout session with defaults

createSession returned status=405

Fail
cancel CHK-0002
Repeated createSession with same idempotency key returns same session

First create failed: 405

Fail
cancel CHK-0003
Create session then set shipping address

createSession returned 405

Fail
cancel CHK-0004
Retrieve a checkout session by id

createSession returned 405

Fail
cancel CHK-0009
Reusing an Idempotency-Key with a different body must be rejected

First createSession returned status=405

Fail
cancel CHK-0010
update_checkout is idempotent on replay and rejects conflicting replays

createSession returned status=405

Fail
cancel CHK-0005
Select a shipping method on a checkout session

createSession returned 405

Fail
warning CAP-CAT-0002
Catalog capability advertised for product lookup

Profile does not declare dev.ucp.shopping.catalog.lookup

Warn
warning CAP-CAT-0001
Catalog capability is declared

Profile does not declare dev.ucp.shopping.catalog.search

Warn
check_circle CAP-CHK-0001
Checkout capability is declared and reachable

Completed in 65ms

Pass
warning CAP-FUL-0001
Fulfillment capability is declared

Profile does not declare dev.ucp.shopping.fulfillment

Warn

Business Profile

Services

dev.ucp.shopping
rest

Capabilities

dev.ucp.shopping.catalog
v2026-01-11
Implemented
Tests: 2/2 passed
dev.ucp.shopping.checkout
v2026-01-11
Implemented
Tests: 3/8 passed

Payment Handlers

payments
dev.ucp.payment.stripe
4 config keys