# api.qa report — sitemap.xml

> **Grade F** · AX score **0/10** · remote mode · attested

- verified: 2026-07-28T22:34:22.695Z
- verifier: api.qa v0.1.0 · seed 1209358241 (replayable)
- evidence digest: `ab425c0555c2c478972a64093aa90643fb607e02fe65b0e81bed84c87ae88fb4`
- report digest: `185596564ecf38fed0846e2daff8873515049dd839eb69f9e244a1f14a47b469` (Ed25519-signed)

## AX score (the 10-point checklist)

| # | check | verdict |
| --- | --- | --- |
| 1 | llms.txt is served and agent-actionable | FAIL |
| 2 | /.well-known/agents.json capability card parses | FAIL |
| 3 | /icp.json self-classification surface | FAIL |
| 4 | root content-negotiates (curl → markdown, browser → HTML) | FAIL |
| 5 | machine-readable API contract (OpenAPI) is published | FAIL |
| 6 | MCP interface declared with transport + tools | FAIL |
| 7 | at least one declared endpoint answers 2xx with no key | FAIL |
| 8 | payment boundaries answer as structured 402 offers | FAIL |
| 9 | surfaces cross-reference each other (linkset) | FAIL |
| 10 | attestation/identity ladder is declared | FAIL |

## Check details

### FAIL — llms.txt is served and agent-actionable (`llms-txt`)

expected 200 markdown (H1 + substantive content) at /llms.txt — got: status 530

### FAIL — /.well-known/agents.json capability card parses (`agents-json`)

expected valid JSON with a name and interfaces at /.well-known/agents.json — got: status 530

### FAIL — /icp.json self-classification surface (`icp-json`)

expected valid JSON with agent_classes at /icp.json — got: status 530

### FAIL — root content-negotiates (curl → markdown, browser → HTML) (`content-negotiation`)

agent Accept received HTML (or nothing) — curl gets a wall of markup — got: status 530

### skip — API home answers machine-legible (JSON/markdown) to every client, browsers included (`machine-legible-home`)

no probe manifest declared — target does not claim the agent-first API contract; page surfaces may serve HTML

### FAIL — machine-readable API contract (OpenAPI) is published (`openapi`)

no parseable OpenAPI document found (declared URL or /openapi.json) — got: status 530

### FAIL — MCP interface declared with transport + tools (`mcp-declared`)

agents.json interfaces.mcp with a transport/url and a non-empty tools list — got: status 530

### skip — MCP endpoint publishes RFC 9728 protected-resource metadata (`mcp-oauth-protected-resource`)

no MCP interface declared — nothing to verify

### skip — authorization server publishes RFC 8414 metadata (openid-configuration fallback) (`mcp-oauth-as-metadata`)

no MCP interface declared — nothing to verify

### skip — authorization server advertises PKCE S256 (RFC 7636) (`mcp-pkce`)

no MCP interface declared — nothing to verify

### skip — authorization server supports Dynamic Client Registration (RFC 7591) (`mcp-oauth-dcr`)

no MCP interface declared — nothing to verify

### skip — protected-resource declares an RFC 8707 audience bound to the MCP origin (`mcp-oauth-resource-indicators`)

no MCP interface declared — nothing to verify

### skip — unauthenticated MCP request returns 401 with WWW-Authenticate → protected-resource metadata (`mcp-www-authenticate`)

no MCP interface declared — nothing to verify

### skip — AAP discovery advertises Ed25519 + approval methods + register/status/revoke + jwks_uri (`aap-discovery`)

no /.well-known/agent-configuration document (2xx) — target does not claim the Agent Auth Protocol

### skip — auth.md agent-identity advertised (agent_auth identity/claim/events + ID-JAG + SET revocation) (`authmd-agent-identity`)

no authorization-server metadata resolved (no MCP/OAuth AS declared) — nothing advertises an agent_auth block

### FAIL — at least one declared endpoint answers 2xx with no key (`keyless-flow`)

no keyless GET candidates discoverable from agents.json/OpenAPI — nothing an agent can try without an account

### FAIL — payment boundaries answer as structured 402 offers (`offers-402`)

no monetization.offers declared — payment boundaries are dead ends, not offers — got: status 530

### FAIL — surfaces cross-reference each other (linkset) (`linkset`)

llms.txt references fewer than 2 sibling surfaces and root sends no Link header — surfaces are islands — got: status 530

### FAIL — attestation/identity ladder is declared (`attestation`)

no attestation or identity ladder declared on agents.json or icp.json — got: status 530

### skip — sampled responses conform to their published schemas (`schema-conformance`)

no sampled endpoint had both a 2xx response and a published response schema

### skip — claimed endpoints actually exist (no ghost surface) (`claims-honesty`)

no claimed endpoints to probe

### skip — live responses match the published OpenAPI contract (full diff) (`contract-diff`)

no valid OpenAPI contract to diff against the live surface

### skip — card-declared probe manifest is valid (`probe-manifest`)

no probe manifest declared (agents.json top-level `probes`) — nothing to validate

### skip — capability card names its interfaces and cross-links its sibling surfaces (`card-interfaces-linked`)

no probe manifest — target does not claim the agent-first API contract

## Replay this verdict

The full evidence bundle is embedded in the JSON report. Judging is a pure
function of the bundle — re-run the checks over it and you MUST get this
same grade, or the report is forged / the verifier version changed:

```sh
curl -H 'accept: application/json' https://api.qa/sitemap.xml | npx autonomous-qa rejudge
```
