Agentic Commerce Surface
197 providers hold a real, parsing `/.well-known/ucp.json` and every one scored zero before this: `well_known_catalog` credits only api-catalog, security.txt and protected-resource, and NONE of the 197 holds any of those. A provider standing up a conformant agentic-commerce document was indistinguishable from one serving no `.well-known` at all. OPERATOR ATTRIBUTION IS SETTLED BEFORE THE AWARD. 193 of the 197 point at `<store>.myshopify.com` — that is not 193 merchants shipping an agentic-commerce surface, it is one platform shipping one 193 times under its merchants' names, the same failure that ranked universities for Figshare's contract. The grade is decided from the document's own service endpoints: on the provider's registrable domain it is theirs; on a vendor's it is real, visible, and the vendor's. `platform` is graded down rather than zeroed because the capability genuinely exists — a buyer's agent can transact there. A PARSING DOCUMENT IS NOT ENOUGH: a version and at least one declared service are required, or it is a stub at the right path. NO AP2 CHECK AND NO x402 CHECK. AP2 defines no well-known path and no pointer — its artifacts are SD-JWT mandate chains presented in-band at transaction time, under authentication, so nothing anonymous is ever fetchable; 0 of the 197 UCP documents reference it. x402 is a 402 plus a response header and needs a live request to a paid endpoint. Scoring either would claim a measurement the surface does not permit — the rule the rubric already applies to draft-klrc-aiagent-auth. APPENDED AT SLOT 19.
How it is scored
One signal, read from what the provider publishes, worth 5 points of the 139 in the agent-readiness score.
| Signal the scorer reads | Points |
|---|---|
a parsing /.well-known/ucp.json or acp.json declaring a version and at least one service — `self` when its endpoints are on the provider's own domain, `platform` when they are on a vendor's | 5 |
Grades and what each earns
This dimension is graded rather than pass/fail: how the signal was evidenced decides what fraction of the points it earns.
| Grade | Credit | Points | Providers |
|---|---|---|---|
| self | 1.0× | 5.0 | 4 |
| platform | 0.25× | 1.2 | 211 |
Top providers
All 215 providers publishing this signal, ranked by credit earned, ties broken by composite.
The other 18 dimensions
github.com/api-evangelist/<provider>, and each check above names the exact artifact it
reads. Publish the artifact, open a pull request, and the next scoring run picks it up — no gatekeeping
and no fee. The full rubric is at apis.io/rating/, and
prioritized profiling
is the fast lane if you would rather have it done for you.
Scored on rubric v0.17.2 across 27,504 providers · lists rebuilt 2026-09-01 · capped at the top 500 per page.