ucp-service-production.up.railway.app logo

ucp-service-production.up.railway.app

verified_user Multi-version UCP compliance, backward compatibility & transport audit

schedule Last scanned 5/4/2026

F 53/100

Conformance

42%
45%

Capability

100%
14%

Coverage

33%
12%

Backward Compat

0%
9%

Negative

47%
8%

Transport

100%
8%

Latency

99%
4%

Audit Details

52% Passing Rate
warning DISC-0012
Cache-Control max-age is within recommended bounds

No Cache-Control header — clients may re-fetch every request

Warn
warning DISC-0006
Profile response advertises cache headers

Discovery response has no Cache-Control header

Warn
cancel DISC-0003
Profile declares at least the checkout capability

Profile does not declare dev.ucp.shopping.checkout

Fail
cancel DISC-0016
Capability version strings are valid ISO dates

(instances ?? []) is not iterable

Fail
check_circle DISC-0008
Profile response Content-Type is application/json

Completed in 252ms

Pass
check_circle DISC-0010
Discovery endpoint exposes CORS headers

Completed in 261ms

Pass
check_circle DISC-0007
Profile is served over HTTPS

Completed in 41ms

Pass
check_circle DISC-0011
Two consecutive profile fetches return identical bodies

Completed in 462ms

Pass
check_circle DISC-0020
Signing JWKs use only allowed kty/crv values

Completed in 242ms

Pass
check_circle DISC-0015
No duplicate capability entries (same name + version)

Completed in 252ms

Pass
check_circle DISC-0017
OpenAPI servers[] URL is reachable

Completed in 270ms

Pass
cancel DISC-0001
Business profile has a valid structure

Business profile failed schema validation

Fail
warning DISC-0022
Merchant responses are signed with the published signing_keys

Merchant publishes signing_keys but did not sign this response (no X-UCP-Signature / RFC 9421 / body JWS). Signing is recommended so agents can verify response authenticity.

Warn
check_circle DISC-0021
robots.txt allows AI agents to read the UCP profile

Completed in 629ms

Pass
cancel DISC-0014
All declared schema URLs use HTTPS

(bindings ?? []) is not iterable

Fail
cancel DISC-0019
Signing keys are importable via Web Crypto

1 of 1 signing key(s) failed Web Crypto import

Fail
check_circle DISC-0002
Profile advertises well-formed signing keys

Completed in 247ms

Pass
cancel DISC-0018
Service binding transports are in the allowed set

(bindings ?? []) is not iterable

Fail
check_circle DISC-0005
Profile declares a ucp.version string

Completed in 246ms

Pass
check_circle DISC-0013
Profile ucp.version is one the grader recognizes

Completed in 246ms

Pass
check_circle DISC-0009
Profile is served at the canonical .well-known/ucp path

Completed in 246ms

Pass
check_circle SCHEMA-INT-0004
Declared capabilities match operations in the OpenAPI
Pass
check_circle SCHEMA-INT-0009
Capability JSON Schemas declare a modern $schema draft
Pass
cancel SCHEMA-INT-0003
Capability-level JSON Schemas are well-formed

3 of 4 capability schemas are malformed

Fail
check_circle SCHEMA-INT-0008
OpenAPI components.schemas has no orphans
Pass
check_circle SCHEMA-INT-0002
Service-level OpenAPI document is valid OpenAPI 3.x
Pass
cancel SCHEMA-INT-0006
Every OpenAPI operation declares a 2xx JSON response schema

4 of 15 operations have no 2xx application/json response schema

Fail
check_circle SCHEMA-INT-0005
Every $ref referenced schema document is reachable
Pass
cancel SCHEMA-INT-0001
All declared schema URLs return 200

4 of 6 schema URLs failed to load: [service] https://ucp-service-production.up.railway.app/docs/identity-openapi.json → malformed_json: Unexpected token '<', "<!doctype "... is not valid JSON [capability] https://ucp.dev/schemas/shopping/checkout.json → http_404 [capability] https://ucp.dev/schemas/shopping/fulfillment.json → http_404 [capability] https://ucp.dev/schemas/common/identity_linking.json → http_404

Fail
cancel SCHEMA-0005
Cancel session response matches the OpenAPI schema

Could not create session: 400

Fail
cancel SCHEMA-0002
Create session response matches the OpenAPI schema

Expected 2xx, got 400

Fail
warning SCHEMA-0001
Discovery profile matches the published JSON Schema

ucp.payment_handlers is missing or not an object

Warn
cancel SCHEMA-0003
Get session response matches the OpenAPI schema

Could not create session: 400

Fail
cancel SCHEMA-0004
Update session response matches the OpenAPI schema

Could not create session: 400

Fail
cancel CHK-0008
Canceling a session twice with the same idempotency key is idempotent

createSession returned status=400

Fail
cancel CHK-0007
Cancel a checkout session

createSession returned 400

Fail
cancel CHK-0001
Create checkout session with defaults

createSession returned status=400

Fail
cancel CHK-0002
Repeated createSession with same idempotency key returns same session

First create failed: 400

Fail
cancel CHK-0003
Create session then set shipping address

createSession returned 400

Fail
cancel CHK-0004
Retrieve a checkout session by id

createSession returned 400

Fail
cancel CHK-0009
Reusing an Idempotency-Key with a different body must be rejected

First createSession returned status=400

Fail
cancel CHK-0010
update_checkout is idempotent on replay and rejects conflicting replays

createSession returned status=400

Fail
cancel CHK-0005
Select a shipping method on a checkout session

createSession returned 400

Fail
cancel FUL-0001
Shipping methods are returned after setting an address

createSession returned 400

Fail
warning CAP-CAT-0002
Catalog capability advertised for product lookup

Profile does not declare dev.ucp.shopping.catalog.lookup

Warn
warning CAP-CAT-0001
Catalog capability is declared

Profile does not declare dev.ucp.shopping.catalog.search

Warn
check_circle CAP-CHK-0001
Checkout capability is declared and reachable

Completed in 247ms

Pass
check_circle CAP-FUL-0001
Fulfillment capability is declared
Pass

Business Profile

Services

dev.ucp.shopping
rest
dev.ucp.identity
rest

Capabilities

dev.ucp.shopping.checkout
v2026-01-11
Implemented
Tests: 1/8 passed
dev.ucp.shopping.fulfillment
v2026-01-11
Implemented
Tests: 1/2 passed
dev.ucp.common.identity_linking
v2026-01-11
Implemented
com.example.payment.tokenization
v2026-01-11
Implemented

Payment Handlers

payments
com.example.processor_tokenizer
2 config keys
payments
dev.ucp.mock_payment
1 config key