vokko.eu / report / roxy.com
roxy.com
Origin-owner checklist from missing spec fields. Not a login. Not a grade letter.
presence 2026-09-01T14:15:23.412Z · callability 2026-09-01T15:06:40.264Z · live re-run is €29/mo
ucp
services dev.ucp.shopping · checkout true
capabilities dev.ucp.shopping.checkout, dev.ucp.shopping.fulfillment, dev.ucp.shopping.discount, dev.ucp.shopping.cart, dev.ucp.shopping.order, dev.ucp.shopping.catalog.search, dev.ucp.shopping.catalog.lookup, dev.shopify.catalog
payment_handlers com.google.pay, dev.shopify.card, dev.shopify.shop_pay
6 items an origin owner can fix without completing checkout.
x402 · x402.missing
No x402 challenge on the homepage or /.well-known/x402.
If you sell machine calls, return HTTP 402 with a PAYMENT-REQUIRED header. Vokko never sends PAYMENT-SIGNATURE to you.
mpp · mpp.missing
No WWW-Authenticate: Payment challenge on the observed GETs.
If you speak MPP, challenge with WWW-Authenticate: Payment. There is no public /.well-known/mpp.
tap · tap.missing
No HTTP Message Signatures directory.
GET /.well-known/http-message-signatures-directory should return JSON 200 if you speak TAP.
mcp · mcp.missing
No MCP manifest JSON.
Publish /.well-known/mcp.json (or /.well-known/mcp) as JSON naming the server endpoint.
a2a · a2a.missing
No A2A agent card.
Publish /.well-known/agent-card.json (preferred) or /.well-known/agent.json with name and skills.
openapi · openapi.missing
No OpenAPI document at the usual paths.
Publish /openapi.json (or /.well-known/openapi.json) if you have an HTTP API.
Protocol matrix · GET /report/roxy.com JSON · GET /api/v1/hosts/roxy.com