ucpchecker.com
verified_user Multi-version UCP compliance, backward compatibility & transport audit
schedule Last scanned 5/4/2026
Conformance
79%Capability
100%Coverage
40%Backward Compat
20%Negative
0%Transport
100%Latency
98%Audit Details
Cache-Control max-age is within recommended bounds
Completed in 327ms
Profile response advertises cache headers
Completed in 346ms
Profile declares at least the checkout capability
Profile does not declare dev.ucp.shopping.checkout
Capability version strings are valid ISO dates
Completed in 357ms
Profile response Content-Type is application/json
Completed in 346ms
Discovery endpoint exposes CORS headers
Discovery response is missing Access-Control-Allow-Origin header
Profile is served over HTTPS
Completed in 309ms
Two consecutive profile fetches return identical bodies
Completed in 734ms
Signing JWKs use only allowed kty/crv values
Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant
No duplicate capability entries (same name + version)
Completed in 403ms
OpenAPI servers[] URL is reachable
OpenAPI document at https://ucpchecker.com/.well-known/mcp.json declares no servers[] entry — agents have no endpoint to call. Add a servers[] array per https://spec.openapis.org/oas/v3.1.0#server-object
Business profile has a valid structure
Completed in 388ms
Merchant responses are signed with the published signing_keys
Profile declares no signing_keys; nothing to verify against. DISC-0002 tracks absence separately.
robots.txt allows AI agents to read the UCP profile
5 of 5 AI agents are disallowed from /.well-known/ucp
All declared schema URLs use HTTPS
Completed in 383ms
Signing keys are importable via Web Crypto
Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant
Profile advertises well-formed signing keys
Profile declares no signing_keys array — the field is optional per the UCP spec, but agents cannot verify signed payloads from this merchant
Service binding transports are in the allowed set
Completed in 417ms
Profile declares a ucp.version string
Completed in 423ms
Profile ucp.version is one the grader recognizes
Completed in 342ms
Profile is served at the canonical .well-known/ucp path
Completed in 318ms
Declared capabilities match operations in the OpenAPI
No OpenAPI operations available to cross-check
Capability JSON Schemas declare a modern $schema draft
Profile declares no capability JSON Schemas
Capability-level JSON Schemas are well-formed
Profile declares zero capability-level schemas
OpenAPI components.schemas has no orphans
Service-level OpenAPI document is valid OpenAPI 3.x
Schema document is missing the "openapi" version field
Every OpenAPI operation declares a 2xx JSON response schema
OpenAPI declares no operations
Every $ref referenced schema document is reachable
All declared schema URLs return 200
2 of 3 schema URLs failed to load: [service] https://ucpchecker.com/api/v1/schema → http_404 [payment] https://ucpchecker.com/methodology#pricing → malformed_json: Unexpected token '<', "<!DOCTYPE "... is not valid JSON
Discovery profile matches the published JSON Schema
Completed in 344ms
Catalog capability advertised for product lookup
Profile does not declare dev.ucp.shopping.catalog.lookup
Catalog capability is declared
Profile does not declare dev.ucp.shopping.catalog.search
Checkout capability is declared and reachable
Profile does not declare dev.ucp.shopping.checkout
Fulfillment capability is declared
Profile does not declare dev.ucp.shopping.fulfillment