Draft rubric

Rubric 0.1.0

Each dimension is a ladder of rungs. A dimension's level is its highest rung whose criteria are all met; the headline is the highest level whose requirements are met.

SHA-256
0xd8355a9820ed2774d250900c3530f3084c70a8039123718204601d011d2dac6a
Discoverable
R1 ≥ 2
Transactable
R2 ≥ 3, R3 ≥ 2
Agreeable
R4 ≥ 4, R5 ≥ 4
Provable
R6 ≥ 3, R7 ≥ 2, R8 ≥ 2

R1

Discoverable

Can an agent find and read what is sold?

R1.2

Rung 2

Do the site's product pages describe their products in structured data an agent can read without a browser?

A structured product is a schema.org/Product item, in JSON-LD or microdata in the HTML as served (no script executed), that has a `name` and an `offers` whose `price` (or `priceSpecification.price`) and `priceCurrency` an agent can read: the price a non-negative decimal with no currency symbol, thousands separator, sign or trailing unit, as schema.org requires, and the currency a three-letter alphabetic code, ISO 4217's form; case is not required, because sellers write `usd`. An `AggregateOffer` may carry its readable price in `lowPrice`, where schema.org puts the lowest of the offers it aggregates. Zero is a readable price. A field carried as written is structured data only when what is written can be acted on: `call us`, `POA`, `$19.99` and `DOLLARS` are all prose an agent would have to parse.

Pass
The sampled product page (or the home page, when no product page is found) is not a refusal and carries a structured product.
Evidence
the page's response
Probe
product, home (anon)
Standards
schema.org Product and Offer, Google merchant listing structured data
Remedy
Publish JSON-LD Product with an Offer on every product page, in the served HTML.

R1.3

Rung 3

Does the site serve its catalogue from a platform endpoint an agent can call?

A catalogue product has a title and a price in the endpoint's documented shape. The endpoints are the rubric's catalogue-endpoint list.

Pass
At least one endpoint in the catalogue-endpoint list answers 200 with JSON, is not a refusal, and lists at least one catalogue product.
Evidence
the endpoint responses
Probe
catalogue (anon)
Standards
Shopify products.json, WooCommerce Store API
Remedy
Leave the platform's public catalogue enabled; better, serve the catalogue through an agent protocol (R1.4).

R1.4

Rung 4

Can an agent ask the seller's own agent interface what it sells?

A UCP business profile is the document at /.well-known/ucp that answers 200 with JSON whose `ucp.version` is a date and whose `ucp.services` and `ucp.payment_handlers` are objects. It declares catalogue search when its capabilities include dev.ucp.shopping.catalog.search or dev.ucp.shopping.catalog.lookup and a service binding the probe can reach. A paid-resource catalogue is at least one entry for the target's registrable domain, with a description and a price, in a facilitator's public x402 discovery listing, or at least one operation in /openapi.json carrying `x-payment-info`. ACP offers no catalogue a probe can read.

Pass
Either the profile declares catalogue search, the handshake completes in whichever era the server speaks, and the search answer (its structuredContent, or content[0].text) holds at least one product with an id, a title and a price; or a paid-resource catalogue is found.
Evidence
the profile; every JSON-RPC request and response of the handshake; the listing or OpenAPI document
Probe
wellknown, ucp.handshake, payment (anon, ucp)
Standards
UCP 2026-08-25 (Catalog MCP binding, search_catalog), MCP 2026-07-28 (backward compatibility), x402 discovery, MPP
Remedy
Publish a UCP business profile with the catalogue capability (Shopify stores have one by default).

R2

Transactable

Can an agent buy?

R2.2

Rung 2

Can an agent construct a link that puts an item in the site's cart?

The cart-link list names each platform's documented cart link and the catalogue fields that build it: Shopify's cart permalink (/cart/<variant id>:<quantity>) and WooCommerce's ?add-to-cart=<product id>.

Pass
The platform is identified, and the fields its cart link needs are read from at least one catalogue product. The probe does not follow the link.
Evidence
the platform signal; the catalogue response
Probe
home, catalogue (anon)
Standards
Shopify cart permalinks, WooCommerce add-to-cart links
Remedy
An agent commerce protocol (R2.3), which is where cart links lead in any case.

R2.3

Rung 3

Does the site offer an agent a protocol path from cart to checkout?

A UCP business profile declares checkout when its capabilities include dev.ucp.shopping.checkout with a service binding the handshake completed against. The checkout tools are create_checkout, get_checkout, update_checkout, complete_checkout and cancel_checkout. An ACP discovery document is /.well-known/acp.json answering 200 with JSON in which `protocol.name` is "acp", `protocol.version` and `supported_versions` are present, `api_base_url` is an absolute https URL, `transports` is a non-empty subset of rest and mcp, and `capabilities.services` includes checkout.

Pass
Either the profile declares checkout and tools/list advertises all five checkout tools, or the site publishes an ACP discovery document. No checkout is created.
Evidence
the profile and the tools/list response; or the ACP document
Probe
wellknown, ucp.handshake (anon, ucp)
Standards
UCP 2026-08-25 (checkout capability), ACP 2026-04-17 (rfc.discovery.md §4)
Remedy
Publish the UCP checkout capability, or ACP's discovery document.

R2.4

Rung 4

Can an agent pay through a protocol built for agents?

A recognised payment challenge is a 402 response carrying an x402 PaymentRequired document, at least one of whose options @integraledger/lcp's pairingOf maps to a pairing; an MPP challenge counts in the same way (pairingsOfPlaced), as does an OpenAPI operation with `x-payment-info` giving intent, method and amount. An AP2 declaration is a UCP profile declaring dev.ucp.common.payment.ap2_mandate with `extends` including dev.ucp.shopping.checkout and at least one EC key (P-256, P-384 or P-521) in keys[], or an A2A agent card declaring the AP2 extension.

Pass
At least one recognised payment challenge or declaration is observed.
Evidence
the 402 responses; the profile
Probe
home, payment, wellknown (anon)
Standards
x402 (v2 PaymentRequired), MPP (draft-ryan-httpauth-payment), AP2 v0.2 (checkout and payment mandates)
Remedy
Accept x402 or MPP, or AP2 mandates through UCP.

R3

Admits agents

Does the site let an identified agent in?

R3.2

Rung 2

Does the site answer an agent that says honestly what it is?

An agent surface is any document or endpoint the wellknown step found present (a UCP profile, a legal context, an ACP document, an agent card, an MCP server card) and the UCP service endpoint the profile names. Admitted is the response class of rubric §1.

Pass
Identity A, or identity S, is admitted at the home page and at every agent surface the site publishes. The report names which identity was admitted.
Evidence
the home-page and agent-surface responses, per identity
Probe
home, wellknown, ucp.handshake, signed (anon, signed)
Standards
RFC 9309, Web Bot Auth
Remedy
Admit declared agents, rate-limited, instead of treating every non-browser client as hostile.

R3.3

Rung 3

Does the site treat an agent that proves who it is differently from one that does not?

Identity S is Lens's signed agent (Web Bot Auth). An edge that cannot yet verify Lens is one on the rubric's list of edges without Lens's verification, identified by its response headers.

Pass
Met when identity A is refused or challenged on a step and identity S is admitted on the same step; or a refusal carries Accept-Signature; or a 402 carries x402's http-message-signatures extension. Not tested when A and S are both admitted and no signature is asked for, when identity S is not configured, or at an edge that cannot yet verify Lens.
Evidence
the paired responses of identities A and S; the challenge or Accept-Signature response
Probe
home, wellknown, signed, payment (anon, signed)
Standards
Web Bot Auth (draft-ietf-webbotauth-httpsig-protocol), RFC 9421, x402 http-message-signatures extension
Remedy
Verify signed agents at the edge (Cloudflare and AWS WAF both can), and let verified agents through.

R4

Terms

Can an agent know what it is agreeing to?

R4.2

Rung 2

Can an agent read the site's terms with an ordinary HTTP request?

The terms candidates are found, in order, from the legal context's `terms`, the UCP policy entries denoting terms of service, a Link header or <link rel="terms-of-service"> on the home page, home-page links matching the terms pattern, and the platform's conventional path; the first three found are captured. Extracted text is the served body with script and style removed.

Pass
A candidate answers 200, is not a refusal, and its extracted text has at least `termsMinWords` words and contains the terms pattern in its first `termsPatternWithin` characters.
Evidence
the candidate's response
Probe
terms (anon)
Standards
LCP §2.3
Remedy
Serve the terms in the page as delivered, not assembled by script.

R4.3

Rung 3

Does the document say when it took effect or was last changed?

The date pattern is a label (last updated, last modified, last revised, effective, effective as of, effective date) followed within `dateWindow` characters by a date in one of the pattern list's forms.

Pass
A candidate that meets R4.2 has extracted text matching the date pattern.
Evidence
the candidate's response
Probe
terms (anon)
Remedy
State the effective date in the document.

R4.4

Rung 4

Can an agent tell which version of the terms it saw?

A version identifier is `version` followed by a number, or `v` followed by a dotted number. A version segment of a URL path is /v<n>/ or an ISO date.

Pass
For a candidate that meets R4.2: its extracted text carries a version identifier, or its URL path carries a version segment, or it is the legal context's terms document and R5.5 is met.
Evidence
the candidate's response and URL
Probe
terms, terms.refetch, wellknown (anon)
Standards
LCP §12.3
Remedy
Give each version of the terms an identifier and a stable URL.

R4.5

Rung 5

Could an agent pin the terms by their hash?

The stability interval is the rubric's `stabilityIntervalMs` between the end of the first fetch and the start of the second.

Pass
For a candidate that meets R4.2, two fetches at the stability interval return byte-identical bodies.
Evidence
both responses and their SHA-256
Probe
terms, terms.refetch (anon)
Standards
LCP §2.8, LCP §3 Level 2
Remedy
Serve the terms as a static file, with no per-request content.

R4.6

Rung 6

Are the terms in a format an agent can extract reliably?

Machine-readable types are text/markdown, text/plain, application/json and any +json type.

Pass
A candidate that meets R4.2 is served as a machine-readable type; or the legal context declares termsFormat markdown, json or plain for it and the served type is not text/html.
Evidence
the candidate's response headers; the legal context
Probe
terms, wellknown (anon)
Standards
LCP §2.5 (termsFormat), LCP §2.8
Remedy
Publish a Markdown, JSON or plain-text edition of the terms for agents.

R5

Legal context

Does the seller publish an LCP legal context?

R5.2

Rung 2

Does the site publish a legal context?

The legal context is https://{target}/.well-known/legal-context.json, read by @integraledger/lcp/discovery's parse.

Pass
The document answers 200, is not a refusal, and parse accepts its bytes. When it does not, its refusal code is recorded.
Evidence
the response; the parse result, including ignored members
Probe
wellknown (anon)
Standards
LCP §2.1–§2.5, LCP §3 Level 1
Remedy
Publish the document; @integraledger/lcp/discovery's emit writes one.

R5.3

Rung 3

Does the document's terms URL serve a standalone terms document?

The terms URL is the legal context's `terms` member.

Pass
The terms URL answers 200 over HTTPS, is not a refusal, and has a non-empty body.
Evidence
the response
Probe
wellknown, terms (anon)
Standards
LCP §2.3, LCP §2.4
Remedy
Serve the terms at the URL the legal context names.

R5.4

Rung 4Judgement

Are the terms the legal context names the terms the site presents everywhere else?

The other candidates are the terms candidates of R4, other than the legal context's terms document, that meet R4.2.

Pass
For every other candidate: it resolves to the same URL after redirects, or its bytes are identical, or, where they differ, an AI-derived judgement over both documents' extracted text finds that they state the same terms, listing any differences it found. With no other candidate, met, and the report says there was nothing to compare.
Evidence
the candidates' responses; the stored judgement, which records the model, the prompt version and both evidence items
Probe
wellknown, terms (anon)
Standards
LCP §2.5
Remedy
Make the agent edition and the page carry the same terms, or point both at one document.

R5.5

Rung 5

Does the legal context pin its terms by hash, and do the served bytes match?

`atrHash` is the legal context's digest of the document at `terms`, compared as decoded bytes with hashEquals.

Pass
atrHash is present, and the SHA-256 of the bytes served at terms, on both fetches at the stability interval, equals it.
Evidence
both responses; the hashes
Probe
wellknown, terms, terms.refetch (anon)
Standards
LCP §2.5, LCP §3 Level 2, LCP §5.3
Remedy
Publish atrHash, and serve the terms byte-for-byte identically.

R6

Provable agreement

Is each transaction bound to a record a stranger can check?

R6.2

Rung 2

Is the buyer's authorisation of the payment signed and verifiable by a third party?

A pairing states in its `pattern` whether the buyer signs; AP2 mandates are signed.

Pass
R2.4 is met through a path whose authorisation is signed: an x402 or MPP pairing whose pattern states a signed authorisation, or AP2 mandates.
Evidence
as R2.4
Probe
home, payment, wellknown (anon)
Standards
AP2 v0.2 checkout and payment mandates (SD-JWT), x402, MPP
Remedy
As R2.4.

R6.3

Rung 3

Does the seller put the hash of the agreement's record where the buyer's payment will carry it, and serve bytes that match?

A challenge carries an ATR hash H and a link L as a pairing places them when the pairing's read returns both.

Pass
A challenge captured by home or payment carries H and L; L is HTTPS; and the hash of the bytes served at L equals H on both fetches of the atr step: the buyer gate passes. Where the ATR would appear only inside a checkout the probe would have to create (UCP, ACP, AP2), not tested unless the seller has consented.
Evidence
the challenge; both ATR responses; the hashes; the pairing and its pattern
Probe
home, payment, atr (anon)
Standards
LCP §5.3, LCP §8.1, LCP §8.3
Remedy
Assemble an ATR per transaction and advertise its hash (@integraledger/lcp, or the Integra appliance).

R6.4

Rung 4

Does a settled payment carry the agreement's hash on a public ledger?

A settled payment is a nominal transaction the probe makes with the seller's consent, or a settlement reference the seller supplies.

Pass
For a settled payment, the pairing's settlement read returns H, and H equals the hash of the ATR bytes served at L. Without a settled payment, not tested, never not met.
Evidence
the settlement read; the ATR bytes; the hashes
Probe
settle (anon, lens)
Standards
LCP §8.3
Remedy
Settle on a rail where the hash rides on chain.

R7

Seller identity

Can a buyer's agent verify who the seller is?

R7.2

Rung 2

Does the seller publish keys, bound to its domain, that its agent-facing messages can be checked against?

A key set is a keys[] JWK Set in the UCP profile, a did:web document at /.well-known/did.json, or a DID configuration at /.well-known/did-configuration.json, fetched over HTTPS from the target origin.

Pass
At least one key set parses and holds at least one key with a kid (or a DID verification method with an id).
Evidence
the documents
Probe
wellknown (anon)
Standards
UCP 2026-08-25 (keys[]), did:web, DIF DID Configuration
Remedy
Publish the signing keys in the UCP profile (Shopify stores often have them already), or a did:web document.

R7.3

Rung 3

Does the seller name the legal entity behind it, and does a public register confirm it?

A register identifier is a leiCode, vatID, taxID, duns or iso6523Code from schema.org/Organization on the home page, together with a legalName.

Pass
The identifier exists in its register with active status, and the register's legal name equals the published legalName under deterministic normalisation. In the first engine build, a published identifier with no registers step is not tested.
Evidence
the page or document; the register's response
Probe
home, wellknown, registers (anon, lens)
Standards
ISO 17442 (LEI), schema.org Organization
Remedy
Publish legalName and an LEI (or another register identifier) in schema.org/Organization.

R7.4

Rung 4

Has a third party that verifies organisations issued a credential naming this domain?

A vLEI linked to the domain, a UNTP Digital Identity Anchor for a DID the origin links to, or a Verified Mark or Common Mark Certificate for the domain through its BIMI record, each verifying to a trust root on the rubric's list.

Pass
One such credential verifies and, where R7.3 found an organisation, names the same one.
Evidence
the credential and its verification
Probe
wellknown (anon)
Standards
ISO 17442-3 (vLEI), UNTP Digital Identity Anchor, BIMI, W3C VC 2.0
Remedy
Obtain a vLEI or a Verified Mark Certificate and link it to the domain.

R8

Product identity

Can the agreement name exactly the product?

R8.2

Rung 2

Does each product carry an identifier an agreement could name?

The product sample is every product the probe read (the catalogue page, the UCP search answer and the product page). An identifier is a valid GTIN (gtin, gtin8, gtin12, gtin13, gtin14, a Shopify variant barcode, or UCP variants[].barcodes[]; digits only, length 8, 12, 13 or 14, correct check digit) or a non-empty sku, mpn or productID. GTINs with prefixes 020–029, 040–049 and 200–299 are merchant-scoped. An identifier is consistent when every surface that states one for the same product states the same.

Pass
At least `identifierSharePercent`% of the sampled products, and at least one, carry an identifier that is valid and consistent. The report says whether it is global (a GTIN outside the restricted ranges, or brand plus MPN) or merchant-scoped (a SKU, or a restricted GTIN).
Evidence
the catalogue, product and search responses
Probe
catalogue, product, ucp.handshake (anon, ucp)
Standards
GS1 General Specifications (GTIN), schema.org Product, UCP catalogue
Remedy
Publish GTINs in the catalogue and in schema.org/Product.

R8.3

Rung 3

Does the identifier lead, through a standard resolver, to the product's own record?

The product's Digital Link URI is one the site publishes, or https://id.gs1.org/01/<gtin14>; a conforming resolver answers /.well-known/gs1resolver and a linkset per RFC 9264.

Pass
For the sampled GTINs, the resolver conforms and the default or pip link answers 2xx on the seller's or the brand owner's domain.
Evidence
the resolver's responses
Probe
gs1 (lens)
Standards
GS1 Digital Link URI syntax 1.7.0, ISO/IEC 18975, RFC 9264
Remedy
Register the products' GTINs with a GS1 resolver pointing at the product pages.

R8.4

Rung 4

Is there a signed record of what the product is, by a party bound to the seller or the brand?

A product record is found through the linkset, an EU Digital Product Passport data carrier, or a credential link in the catalogue, and parses as a W3C VC 2.0, a JWS, or an EN 18246 signed construct.

Pass
The record's signature verifies, its issuer is bound to the seller's origin or the brand owner, it is current, and its subject is the sampled product.
Evidence
the record and its verification
Probe
gs1, catalogue (lens, anon)
Standards
UNTP Digital Product Passport, EU ESPR Digital Product Passport (EN 18219, EN 18246), W3C VC 2.0
Remedy
Publish product passports signed by the seller or the brand owner.

R8.5

Rung 5

Is the version of the product the buyer was shown registered in a public append-only log, and does the agreement's record bind it by hash?

Any public append-only registry whose history a stranger can check qualifies.

Pass
An ATR from a consented nominal transaction references, by hash, a product record that appears in such a log.
Evidence
the ATR; the log's inclusion proof
Probe
settle (anon, lens)
Standards
LCP §7, IETF SCITT
Remedy
Register each product version, and reference it from the ATR.