Draft rubric

Rubric 0.2.0

Each dimension is a ladder of rungs. A dimension's level is its highest rung whose criteria are all met; the headline is the highest level whose requirements are met.

SHA-256
0x191118fe48a7271ef7ed814d7957fbb44701590139f63a1c3ee041ebdd4d453a
Discoverable
R1 ≥ 2
Transactable
R2 ≥ 3, R3 ≥ 2
Agreeable
R4 ≥ 4, R5 ≥ 4
Provable
R6 ≥ 3, R7 ≥ 2, R8 ≥ 2

R1

Discoverable

Can an agent find and read what is sold?

R1.2

Rung 2

Do the site's product pages describe their products in structured data an agent can read without a browser?

A structured product is a schema.org/Product item, in JSON-LD or microdata in the HTML as served (no script executed), that has a `name` and an `offers` whose `price` (or `priceSpecification.price`) and `priceCurrency` an agent can read: the price a non-negative decimal with no currency symbol, thousands separator, sign or trailing unit, as schema.org requires, and the currency a three-letter alphabetic code, ISO 4217's form; case is not required, because sellers write `usd`. An `AggregateOffer` may carry its readable price in `lowPrice`, where schema.org puts the lowest of the offers it aggregates. Zero is a readable price. A field carried as written is structured data only when what is written can be acted on: `call us`, `POA`, `$19.99` and `DOLLARS` are all prose an agent would have to parse.

Pass
The sampled product page (or the home page, when no product page is found) is not a refusal and carries a structured product.
Evidence
the page's response
Probe
product, home (anon)
Standards
schema.org Product and Offer, Google merchant listing structured data
Remedy
Publish JSON-LD Product with an Offer on every product page, in the served HTML.

R1.3

Rung 3

Does the site serve its catalogue from a platform endpoint an agent can call?

A catalogue product has a title and a price in the endpoint's documented shape. The endpoints are the rubric's catalogue-endpoint list.

Pass
At least one endpoint in the catalogue-endpoint list answers 200 with JSON, is not a refusal, and lists at least one catalogue product.
Evidence
the endpoint responses
Probe
catalogue (anon)
Standards
Shopify products.json, WooCommerce Store API
Remedy
Leave the platform's public catalogue enabled; better, serve the catalogue through an agent protocol (R1.4).

R1.4

Rung 4

Can an agent ask the seller's own agent interface what it sells?

A UCP business profile is the document at /.well-known/ucp that answers 200 with JSON whose `ucp.version` is a date and whose `ucp.services` and `ucp.payment_handlers` are objects. It declares catalogue search when its capabilities include dev.ucp.shopping.catalog.search or dev.ucp.shopping.catalog.lookup and a service binding the probe can reach. A paid-resource catalogue is at least one entry for the target's registrable domain, with a description and a price, in a facilitator's public x402 discovery listing, or at least one operation in /openapi.json carrying `x-payment-info`. ACP offers no catalogue a probe can read.

Pass
Either the profile declares catalogue search, the handshake completes in whichever era the server speaks, and the search answer (its structuredContent, or content[0].text) holds at least one product with an id, a title and a price; or a paid-resource catalogue is found.
Evidence
the profile; every JSON-RPC request and response of the handshake; the listing or OpenAPI document
Probe
wellknown, ucp.handshake, payment (anon, ucp)
Standards
UCP 2026-08-25 (Catalog MCP binding, search_catalog), MCP 2026-07-28 (backward compatibility), x402 discovery, MPP
Remedy
Publish a UCP business profile with the catalogue capability (Shopify stores have one by default).

R2

Transactable

Can an agent buy?

R2.2

Rung 2

Can an agent construct a link that puts an item in the site's cart?

The cart-link list names each platform's documented cart link and the catalogue fields that build it: Shopify's cart permalink (/cart/<variant id>:<quantity>) and WooCommerce's ?add-to-cart=<product id>.

Pass
The platform is identified, and the fields its cart link needs are read from at least one catalogue product. The probe does not follow the link.
Evidence
the platform signal; the catalogue response
Probe
home, catalogue (anon)
Standards
Shopify cart permalinks, WooCommerce add-to-cart links
Remedy
An agent commerce protocol (R2.3), which is where cart links lead in any case.

R2.3

Rung 3

Does the site offer an agent a protocol path from cart to checkout?

A UCP business profile declares checkout when its capabilities include dev.ucp.shopping.checkout with a service binding the handshake completed against. The checkout tools are create_checkout, get_checkout, update_checkout, complete_checkout and cancel_checkout. An ACP discovery document is /.well-known/acp.json answering 200 with JSON in which `protocol.name` is "acp", `protocol.version` and `supported_versions` are present, `api_base_url` is an absolute https URL, `transports` is a non-empty subset of rest and mcp, and `capabilities.services` includes checkout.

Pass
Either the profile declares checkout and tools/list advertises all five checkout tools, or the site publishes an ACP discovery document. No checkout is created.
Evidence
the profile and the tools/list response; or the ACP document
Probe
wellknown, ucp.handshake (anon, ucp)
Standards
UCP 2026-08-25 (checkout capability), ACP 2026-04-17 (rfc.discovery.md §4)
Remedy
Publish the UCP checkout capability, or ACP's discovery document.

R2.4

Rung 4

Can an agent pay through a protocol built for agents?

A recognised payment challenge is a 402 response carrying an x402 PaymentRequired document, at least one of whose options @integraledger/lcp's pairingOf maps to a pairing; an MPP challenge counts in the same way (pairingsOfPlaced), as does an OpenAPI operation with `x-payment-info` giving intent, method and amount. An AP2 declaration is a UCP profile declaring dev.ucp.common.payment.ap2_mandate with `extends` including dev.ucp.shopping.checkout and at least one EC key (P-256, P-384 or P-521) in keys[], or an A2A agent card declaring the AP2 extension.

Pass
At least one recognised payment challenge or declaration is observed.
Evidence
the 402 responses; the profile
Probe
home, payment, wellknown (anon)
Standards
x402 (v2 PaymentRequired), MPP (draft-ryan-httpauth-payment), AP2 v0.2 (checkout and payment mandates)
Remedy
Accept x402 or MPP, or AP2 mandates through UCP.

R3

Admits agents

Does the site let an identified agent in?

R3.2

Rung 2

Does the site answer an agent that says honestly what it is?

An agent surface is any document or endpoint the wellknown step found present (a UCP profile, a legal context, an ACP document, an agent card, an MCP server card) and the UCP service endpoint the profile names. Admitted is the response class of rubric §1.

Pass
Identity A, or identity S, is admitted at the home page and at every agent surface the site publishes. The report names which identity was admitted.
Evidence
the home-page and agent-surface responses, per identity
Probe
home, wellknown, ucp.handshake, signed (anon, signed)
Standards
RFC 9309, Web Bot Auth
Remedy
Admit declared agents, rate-limited, instead of treating every non-browser client as hostile.

R3.3

Rung 3

Does the site treat an agent that proves who it is differently from one that does not?

Identity S is Lens's signed agent (Web Bot Auth). An edge that cannot yet verify Lens is one on the rubric's list of edges without Lens's verification, identified by its response headers.

Pass
Met when identity A is refused or challenged on a step and identity S is admitted on the same step; or a refusal carries Accept-Signature; or a 402 carries x402's http-message-signatures extension. Not tested when A and S are both admitted and no signature is asked for, when identity S is not configured, or at an edge that cannot yet verify Lens.
Evidence
the paired responses of identities A and S; the challenge or Accept-Signature response
Probe
home, wellknown, signed, payment (anon, signed)
Standards
Web Bot Auth (draft-ietf-webbotauth-httpsig-protocol), RFC 9421, x402 http-message-signatures extension
Remedy
Verify signed agents at the edge (Cloudflare and AWS WAF both can), and let verified agents through.

R4

Terms

Can an agent know what it is agreeing to?

R4.2

Rung 2

Can an agent read the site's terms with an ordinary HTTP request?

The terms candidates are found, in order, from the legal context's `terms`, the UCP policy entries denoting terms of service, a Link header or <link rel="terms-of-service"> on the home page, home-page links matching the terms pattern, and the platform's conventional path; the first three found are captured. Extracted text is the served body with script and style removed.

Pass
A candidate answers 200, is not a refusal, and its extracted text has at least `termsMinWords` words and contains the terms pattern in its first `termsPatternWithin` characters.
Evidence
the candidate's response
Probe
terms (anon)
Standards
LCP §2.3
Remedy
Serve the terms in the page as delivered, not assembled by script.

R4.3

Rung 3

Does the document say when it took effect or was last changed?

The date pattern is a label (last updated, last modified, last revised, effective, effective as of, effective date) followed within `dateWindow` characters by a date in one of the pattern list's forms.

Pass
A candidate that meets R4.2 has extracted text matching the date pattern.
Evidence
the candidate's response
Probe
terms (anon)
Remedy
State the effective date in the document.

R4.4

Rung 4

Can an agent tell which version of the terms it saw?

A version identifier is `version` followed by a number, or `v` followed by a dotted number. A version segment of a URL path is /v<n>/ or an ISO date.

Pass
For a candidate that meets R4.2: its extracted text carries a version identifier, or its URL path carries a version segment, or it is the legal context's terms document and R5.5 is met.
Evidence
the candidate's response and URL
Probe
terms, terms.refetch, wellknown (anon)
Standards
LCP §12.3
Remedy
Give each version of the terms an identifier and a stable URL.

R4.5

Rung 5

Could an agent pin the terms by their hash?

The stability interval is the rubric's `stabilityIntervalMs` between the end of the first fetch and the start of the second.

Pass
For a candidate that meets R4.2, two fetches at the stability interval return byte-identical bodies.
Evidence
both responses and their SHA-256
Probe
terms, terms.refetch (anon)
Standards
LCP §2.8, LCP §3 Level 2
Remedy
Serve the terms as a static file, with no per-request content.

R4.6

Rung 6

Are the terms in a format an agent can extract reliably?

Machine-readable types are text/markdown, text/plain, application/json and any +json type.

Pass
A candidate that meets R4.2 is served as a machine-readable type; or the legal context declares termsFormat markdown, json or plain for it and the served type is not text/html.
Evidence
the candidate's response headers; the legal context
Probe
terms, wellknown (anon)
Standards
LCP §2.5 (termsFormat), LCP §2.8
Remedy
Publish a Markdown, JSON or plain-text edition of the terms for agents.

R5

Legal context

Does the seller publish an LCP legal context?

R5.2

Rung 2

Does the site publish a legal context?

The legal context is https://{target}/.well-known/legal-context.json, read by @integraledger/lcp/discovery's parse.

Pass
The document answers 200, is not a refusal, and parse accepts its bytes. When it does not, its refusal code is recorded.
Evidence
the response; the parse result, including ignored members
Probe
wellknown (anon)
Standards
LCP §2.1–§2.5, LCP §3 Level 1
Remedy
Publish the document; @integraledger/lcp/discovery's emit writes one.

R5.3

Rung 3

Does the document's terms URL serve a standalone terms document?

The terms URL is the legal context's `terms` member.

Pass
The terms URL answers 200 over HTTPS, is not a refusal, and has a non-empty body.
Evidence
the response
Probe
wellknown, terms (anon)
Standards
LCP §2.3, LCP §2.4
Remedy
Serve the terms at the URL the legal context names.

R5.4

Rung 4Judgement

Are the terms the legal context names the terms the site presents everywhere else?

The other candidates are the terms candidates of R4, other than the legal context's terms document, that meet R4.2.

Pass
For every other candidate: it resolves to the same URL after redirects, or its bytes are identical, or, where they differ, an AI-derived judgement over both documents' extracted text finds that they state the same terms, listing any differences it found. With no other candidate, met, and the report says there was nothing to compare.
Evidence
the candidates' responses; the stored judgement, which records the model, the prompt version and both evidence items
Probe
wellknown, terms (anon)
Standards
LCP §2.5
Remedy
Make the agent edition and the page carry the same terms, or point both at one document.

R5.5

Rung 5

Does the legal context pin its terms by hash, and do the served bytes match?

`atrHash` is the legal context's digest of the document at `terms`, compared as decoded bytes with hashEquals.

Pass
atrHash is present, and the SHA-256 of the bytes served at terms, on both fetches at the stability interval, equals it.
Evidence
both responses; the hashes
Probe
wellknown, terms, terms.refetch (anon)
Standards
LCP §2.5, LCP §3 Level 2, LCP §5.3
Remedy
Publish atrHash, and serve the terms byte-for-byte identically.

R6

Provable agreement

Is each transaction bound to a record a stranger can check?

R6.2

Rung 2

Is the buyer's authorisation of the payment signed and verifiable by a third party?

A pairing states in its `pattern` whether the buyer signs; AP2 mandates are signed.

Pass
R2.4 is met through a path whose authorisation is signed: an x402 or MPP pairing whose pattern states a signed authorisation, or AP2 mandates.
Evidence
as R2.4
Probe
home, payment, wellknown (anon)
Standards
AP2 v0.2 checkout and payment mandates (SD-JWT), x402, MPP
Remedy
As R2.4.

R6.3

Rung 3

Does the seller put the hash of the agreement's record where the buyer's payment will carry it, and serve bytes that match?

A challenge carries an ATR hash H and a link L as a pairing places them when the pairing's read returns both.

Pass
A challenge captured by home or payment carries H and L; L is HTTPS; and the hash of the bytes served at L equals H on both fetches of the atr step: the buyer gate passes. Where the ATR would appear only inside a checkout the probe would have to create (UCP, ACP, AP2), not tested unless the seller has consented.
Evidence
the challenge; both ATR responses; the hashes; the pairing and its pattern
Probe
home, payment, atr (anon)
Standards
LCP §5.3, LCP §8.1, LCP §8.3
Remedy
Assemble an ATR per transaction and advertise its hash (@integraledger/lcp, or the Integra appliance).

R6.4

Rung 4

Does a settled payment carry the agreement's hash on a public ledger?

A settled payment is a nominal transaction the probe makes with the seller's consent, or a settlement reference the seller supplies.

Pass
For a settled payment, the pairing's settlement read returns H, and H equals the hash of the ATR bytes served at L. Without a settled payment, not tested, never not met.
Evidence
the settlement read; the ATR bytes; the hashes
Probe
settle (anon, lens)
Standards
LCP §8.3
Remedy
Settle on a rail where the hash rides on chain.

R7

Seller identity

Can a buyer's agent verify who the seller is?

R7.2

Rung 2

Does the seller publish keys, bound to its domain, that its agent-facing messages can be checked against?

A key set is a keys[] JWK Set in the UCP profile, a did:web document at /.well-known/did.json, or a DID configuration at /.well-known/did-configuration.json, fetched over HTTPS from the target origin.

Pass
At least one key set parses and holds at least one key with a kid (or a DID verification method with an id).
Evidence
the documents
Probe
wellknown (anon)
Standards
UCP 2026-08-25 (keys[]), did:web, DIF DID Configuration
Remedy
Publish the signing keys in the UCP profile (Shopify stores often have them already), or a did:web document.

R7.3

Rung 3

Does the seller name the legal entity behind it, and does a public register confirm it?

A register identifier is a leiCode, vatID, taxID, duns or iso6523Code, together with a legalName, on schema.org/Organization (or a subtype a site uses for itself) in the home page's structured data, or the same properties on an object in the UCP profile or the DID document. The registers step looks each identifier up where a free public register API exists: an LEI (leiCode, or an iso6523Code under ICD 0199) in GLEIF's API; an EU or Northern Ireland VAT number in the European Commission's VIES. Legal names are compared under deterministic normalisation: Unicode compatibility form with diacritics removed, case, & as and, full stops and apostrophes removed, every other run of punctuation and whitespace as one space, and each legal form in lists.legalForms written as its abbreviation.

Pass
At least one published identifier is confirmed by its register: for an LEI, GLEIF's record with registration status ISSUED; for a VAT number, VIES reports it valid. And the register's legal name (for GLEIF, the legal name or a legal name in another language or transliteration; for VIES, the registered name) equals the published legalName under the normalisation. No looser match is made. An identifier with no free public register lookup in this version (taxID, duns, an iso6523Code under another ICD, a VAT number outside VIES), or whose register discloses no name, is not tested; a register that cannot be reached is inconclusive. The best result over the published identifiers counts: met, then inconclusive, then not tested, then not met.
Evidence
the home page or agent document naming the organisation; the register's response
Probe
home, wellknown, registers (anon, lens)
Standards
ISO 17442 (LEI), schema.org Organization, EU VIES (VAT)
Remedy
Publish legalName and an LEI (or an EU VAT number) in schema.org/Organization on the home page, writing the name as the register does.

R7.4

Rung 4

Has a third party that verifies organisations issued a credential naming this domain?

Any of: a Verified Mark Certificate or Common Mark Certificate for the domain, named by the a= tag of its BIMI record (default._bimi.<registrable domain>, read through DNS-over-HTTPS); a UNTP Digital Identity Anchor for a DID the origin links (its did:web document, or a did:web its DID configuration links by a Domain Linkage Credential that verifies), found through the DID document's untp:dia service and secured with JOSE; or a vLEI linked to the domain through a KERI-based DID (did:webs). Trust roots are versioned lists in this rubric: lists.markVerifyingAuthorities (root certificates, by SHA-256) and lists.identityAnchorIssuers (register DIDs).

Pass
One such credential verifies and, where R7.3 found an organisation, names the same one (under R7.3's normalisation, or a DIA by its registered identifier). A mark certificate: BIMI's extended key usage, a VMC or CMC mark type, the domain among its subject alternative names, a path to a listed root with every certificate valid at the probe's time, and the certificate not on its issuer's current CRL (a CRL that cannot be read, or none named, is inconclusive; OCSP is not queried; embedded SCTs are recorded, not verified). A DIA: its signature verifies with a key its issuer's DID document lists for assertion (ES256 or EdDSA), type DigitalIdentityAnchor, its subject the linked DID, current, its issuer on the list, and no status list (one it names is not read, so inconclusive). A vLEI is not tested: no maintained TypeScript verifier runs in a Worker. The best result over the credentials counts; a site with none of them is not met.
Evidence
the BIMI record, the mark certificate chain and its CRLs; the DID documents, the anchor and its issuer's DID document
Probe
wellknown, registers (anon, lens)
Standards
BIMI (draft-brand-indicators-for-message-identification), VMC and CMC (BIMI Group), RFC 5280 (X.509, CRLs), UNTP Digital Identity Anchor (v0.7.0), W3C VC 2.0 and VC-JOSE-COSE, ISO 17442-3 (vLEI)
Remedy
Obtain a Verified Mark or Common Mark Certificate for the domain and publish it in its BIMI record, or a Digital Identity Anchor from your business register linked from your DID document.

R8

Product identity

Can the agreement name exactly the product?

R8.2

Rung 2

Does each product carry an identifier an agreement could name?

The product sample is every product the probe read (the catalogue page, the UCP search answer and the product page). An identifier is a valid GTIN (gtin, gtin8, gtin12, gtin13, gtin14, a Shopify variant barcode, or UCP variants[].barcodes[]; digits only, length 8, 12, 13 or 14, correct check digit) or a non-empty sku, mpn or productID. GTINs with prefixes 020–029, 040–049 and 200–299 are merchant-scoped. An identifier is consistent when every surface that states one for the same product states the same.

Pass
At least `identifierSharePercent`% of the sampled products, and at least one, carry an identifier that is valid and consistent. The report says whether it is global (a GTIN outside the restricted ranges, or brand plus MPN) or merchant-scoped (a SKU, or a restricted GTIN).
Evidence
the catalogue, product and search responses
Probe
catalogue, product, ucp.handshake (anon, ucp)
Standards
GS1 General Specifications (GTIN), schema.org Product, UCP catalogue
Remedy
Publish GTINs in the catalogue and in schema.org/Product.

R8.3

Rung 3Judgement

Does the identifier lead, through a standard resolver, to the product's own record?

The resolution sample is up to three distinct products of the R8 sample: the product page's product first, then the catalogue's, then the UCP answer's. A product with a GTIN outside the restricted ranges resolves through its GS1 Digital Link URI: one the site publishes (a gtin value written as a Digital Link URI, or a link on the product page on the seller's registrable domain), else https://id.gs1.org/01/<gtin14>. A conforming resolver answers /.well-known/gs1resolver with a description file, and answers Accept: application/linkset+json with an RFC 9264 linkset (context objects with absolute anchors, relations holding target objects with absolute hrefs) whose context object anchored at the URI carries exactly one gs1:defaultLink; GS1's own linkset schema is not bundled in this version. A product without such a GTIN resolves through an https identifier on the seller's registrable domain: the first https value of its schema.org identifier, productID or @id there, else its URL there (the catalogue item's, or the product page's).

Pass
A product meets the rung when, for a GTIN, the resolver conforms and its default link (or, where that does not answer 2xx, its first pip link) answers 2xx on the seller's registrable domain or, through GS1's resolver, whose links only the GTIN's licensee registers, on the brand owner's; and that page describes the same product: deterministically when it is the product's own page or its schema.org Product states the same GTIN, otherwise by an AI-derived judgement over both, marked so. For a product without such a GTIN, it meets the rung when its identifier answers 2xx, is not a refusal, and serves the product's page (a schema.org Product whose name equals the product's after normalisation, or with the same SKU, MPN or productID) or its product record (a signed statement whose subject is the identifier). At least identifierSharePercent% of the resolution sample, and at least one, meet it.
Evidence
the product sample's responses; the resolver's description file and linkset; the pages the links and identifiers lead to; for an AI-derived finding, the stored judgement
Probe
catalogue, product, ucp.handshake, gs1 (anon, lens)
Standards
GS1 Digital Link URI syntax 1.7.0, GS1-Conformant Resolver Standard 1.2.1, ISO/IEC 18975, RFC 9264
Remedy
Register the products' GTINs with a GS1 resolver pointing at the product pages; for products without a GTIN, give each an https identifier on your own domain that serves its page or its record.

R8.4

Rung 4

Is there a signed record of what the product is, by a party bound to the seller or the brand?

A product record is a W3C VC 2.0 Digital Product Passport secured with COSE (VC-JOSE-COSE: cty application/vc), found through a dpp link (the IANA link relation) on the product page the probe reads, as an HTML link element or an HTTP Link header. Its issuer's key is resolved from a did:web document or a did:key. The sample for this rung is the product whose page the probe read, because a catalogue item carries no standard link to its passport and the probe reads one product page. A record found through a GS1 linkset or an EU Digital Product Passport data carrier counts once the gs1 step exists.

Pass
The record's signature verifies with its issuer's key, which its DID document lists for assertion; the issuer is bound to the seller's origin (a did:web on its host or registrable domain, or a DID the origin's DID configuration links); the record is current and names no status list this version does not read; its subject is the sampled product (the same GTIN, the same identifier path on the seller's host, or the same SKU); its name equals the product's after normalisation; and the image served at its image link hashes to its digest. At least `identifierSharePercent`% of the products the probe looked up a record for, and at least one, meet it.
Evidence
the product page; the record; the issuer's DID document; the DID configuration; the image
Probe
product, wellknown (anon)
Standards
UNTP Digital Product Passport, W3C VC 2.0 and VC-JOSE-COSE, did:web; DIF Well Known DID Configuration, IANA link relation dpp, EU ESPR Digital Product Passport (EN 18219, EN 18246)
Remedy
Publish product passports signed by the seller or the brand owner.

R8.5

Rung 5

Is the version of the product the buyer was shown registered in a public append-only log, and does the agreement's record bind it by hash?

Any public append-only log whose history a stranger can check qualifies: a transparency service whose receipt (RFC 9942, an RFC 9162 inclusion proof) verifies with a key it publishes at /.well-known/scitt-keys. A product exhibit is a JSON object in the ATR with the role product, the product identifier (id), the version (the SHA-256 of the signed record as logged) and the URL at which the log serves the entry (entry).

Pass
The ATR from a consented nominal transaction carries at least one product exhibit, and for every one, the entry served at its URL is that version of that product, is a product record, and carries a receipt that verifies with a key its log publishes.
Evidence
the ATR; the entry served at each exhibit's URL; the log's key set
Probe
settle (anon, lens)
Standards
LCP §7, IETF SCITT (RFC 9943, RFC 9942)
Remedy
Register each product version, and reference it from the ATR.