Server definition
- Hash
- sha256:4b3ba9b0893145f899c549bf7f5c580977ebc1867d0234254206c92ae389827e
- What it is
- What a remote MCP server returned when asked what it offers: 5 tools
The blob, as servednamed by its sha256
{
"instructions": "Read-only. resolve_compliance(object_id, jurisdiction) returns the current signed RCO or a pre-resolved signed CPG-404 inside the resolved universe; typed errors outside it. Records verify from https://dpuone.ai/.well-known/jwks.json (kid gsc-rco-2026-08), rooted in the signed issuer registry at https://consortium-10060.org/issuers.json.",
"tools": [
{
"description": "Return any RCO by record_id, including superseded records - the audit trail, retained byte-identical.",
"inputSchema": {
"properties": {
"record_id": {
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
}
},
"required": [
"record_id"
],
"type": "object"
},
"name": "get_record",
"outputSchema": {
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).",
"allOf": [
{
"$comment": "The seven legal signal/state pairs.",
"oneOf": [
{
"properties": {
"signal": {
"const": "CPG-000"
},
"state": {
"const": "NOT_APPLICABLE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-200"
},
"state": {
"const": "ALLOW"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-300"
},
"state": {
"const": "CONDITIONAL"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-403"
},
"state": {
"const": "RESTRICT"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-404"
},
"state": {
"const": "NOT_FOUND"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-451"
},
"state": {
"const": "ESCALATE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-500"
},
"state": {
"const": "SYSTEM_ERROR"
}
}
}
]
},
{
"$comment": "conditions: required non-empty for CPG-300, forbidden otherwise.",
"else": {
"not": {
"required": [
"conditions"
]
}
},
"if": {
"properties": {
"signal": {
"const": "CPG-300"
}
}
},
"then": {
"properties": {
"conditions": {
"minItems": 1
}
},
"required": [
"conditions"
]
}
},
{
"$comment": "CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.",
"else": {
"properties": {
"eco_ref": {
"type": "object"
}
}
},
"if": {
"properties": {
"signal": {
"const": "CPG-404"
}
}
},
"then": {
"properties": {
"eco_ref": {
"type": "null"
}
}
}
}
],
"properties": {
"case_study": {
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.",
"default": false,
"type": "boolean"
},
"conditions": {
"items": {
"properties": {
"code": {
"minLength": 1,
"type": "string"
},
"ref": {
"format": "uri",
"type": "string"
}
},
"required": [
"code",
"ref"
],
"type": "object"
},
"type": "array"
},
"eco_ref": {
"anyOf": [
{
"type": "null"
},
{
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"url",
"hash"
],
"type": "object"
}
]
},
"evidence_refs": {
"items": {
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"kind",
"url",
"hash"
],
"type": "object"
},
"type": "array"
},
"issuer": {
"properties": {
"id": {
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
}
},
"required": [
"id",
"rail",
"name"
],
"type": "object"
},
"jurisdiction": {
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.",
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
},
"key_id": {
"minLength": 1,
"type": "string"
},
"object_id": {
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$",
"type": "string"
},
"rco_version": {
"const": "1.0"
},
"record_id": {
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
},
"resolved_at": {
"format": "date-time",
"type": "string"
},
"rule_set": {
"properties": {
"effective_from": {
"format": "date-time",
"type": "string"
},
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"id": {
"type": "string"
},
"version": {
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$",
"type": "string"
}
},
"required": [
"id",
"version",
"hash",
"effective_from"
],
"type": "object"
},
"signal": {
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
]
},
"signature": {
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json.",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"type": "string"
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"supersedes": {
"anyOf": [
{
"type": "null"
},
{
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
}
]
},
"valid_until": {
"format": "date-time",
"type": "string"
},
"verification_url": {
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.",
"format": "uri",
"type": "string"
}
},
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"type": "object"
}
},
{
"description": "Return the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "list_issuers",
"outputSchema": {
"$comment": "Published at consortium-10060.org/issuers.json and returned by list_issuers. This document is the verification root: consumers resolve issuer.id here and take the JWKS URL from this registry; a record's in-record verification_url is a cross-check only. The registry is signed with the consortium key using the same detached-JWS profile as records; the consortium public keyring (the trust anchor) is pinned at consortium-10060.org/.well-known/jwks.json and mirrored in the RCO tree. Amendments append to amendments.json; the registry document is superseded whole, never edited.",
"properties": {
"issuers": {
"items": {
"properties": {
"admitted": {
"format": "date-time",
"type": "string"
},
"id": {
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"jwks_url": {
"format": "uri",
"type": "string"
},
"keys": {
"$comment": "Key lifecycle of record. Retired kids stay on the issuer JWKS indefinitely so historical records remain verifiable; this array dates each kid.",
"items": {
"properties": {
"kid": {
"type": "string"
},
"revoked": {
"type": "boolean"
},
"valid_from": {
"format": "date-time",
"type": "string"
},
"valid_to": {
"anyOf": [
{
"type": "null"
},
{
"format": "date-time",
"type": "string"
}
]
}
},
"required": [
"kid",
"valid_from"
],
"type": "object"
},
"type": "array"
},
"name": {
"minLength": 1,
"type": "string"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
},
"status": {
"enum": [
"active",
"suspended",
"revoked"
]
},
"status_changed": {
"$comment": "Required when status is not active — the effective time of the suspension or revocation. Records signed before this instant by then-valid keys still verify; consumers reject records whose resolved_at is at or after it.",
"format": "date-time",
"type": "string"
}
},
"required": [
"id",
"rail",
"name",
"jwks_url",
"status",
"admitted"
],
"type": "object"
},
"minItems": 1,
"type": "array"
},
"key_id": {
"minLength": 1,
"type": "string"
},
"registry_version": {
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$",
"type": "string"
},
"signature": {
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"type": "string"
},
"trust_anchor": {
"$comment": "v1.3: the consortium key's out-of-band pin - the fingerprint is published on the dpuone.ai keyring page and as a DNS TXT record on this zone; verify either before trusting this document's own JWKS.",
"properties": {
"kid": {
"type": "string"
},
"method": {
"type": "string"
},
"published": {
"items": {
"type": "string"
},
"minItems": 2,
"type": "array"
},
"sha256_fingerprint": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
}
},
"required": [
"kid",
"sha256_fingerprint",
"method",
"published"
],
"type": "object"
},
"updated": {
"format": "date-time",
"type": "string"
},
"verification_url": {
"format": "uri",
"type": "string"
}
},
"required": [
"registry_version",
"updated",
"issuers",
"key_id",
"verification_url",
"signature"
],
"type": "object"
}
},
{
"description": "List the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.",
"inputSchema": {
"properties": {
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
],
"type": "string"
}
},
"required": [
"jurisdiction"
],
"type": "object"
},
"name": "list_rule_sets",
"outputSchema": {
"properties": {
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
},
"rule_sets": {
"items": {
"properties": {
"effective_from": {
"format": "date-time",
"type": "string"
},
"effective_to": {
"anyOf": [
{
"type": "null"
},
{
"format": "date-time",
"type": "string"
}
]
},
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"id": {
"type": "string"
},
"url": {
"format": "uri",
"type": "string"
},
"version": {
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$",
"type": "string"
}
},
"required": [
"id",
"version",
"hash",
"effective_from",
"effective_to",
"url"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"jurisdiction",
"rule_sets"
],
"type": "object"
}
},
{
"description": "Publish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.",
"inputSchema": {
"properties": {
"record": {
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k). Served flat since 1.0.2 (no alternation constructs; the signal discriminator binds the state); the full contract schema is https://rco-a2a.ai/schema/v1.4/resolve_compliance.tool.json and is what the validator enforces.",
"properties": {
"case_study": {
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.",
"default": false,
"type": "boolean"
},
"conditions": {
"items": {
"properties": {
"code": {
"minLength": 1,
"type": "string"
},
"ref": {
"format": "uri",
"type": "string"
}
},
"required": [
"code",
"ref"
],
"type": "object"
},
"type": "array"
},
"eco_ref": {
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"url",
"hash"
],
"type": [
"object",
"null"
]
},
"evidence_refs": {
"items": {
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"kind",
"url",
"hash"
],
"type": "object"
},
"type": "array"
},
"issuer": {
"properties": {
"id": {
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
}
},
"required": [
"id",
"rail",
"name"
],
"type": "object"
},
"jurisdiction": {
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.",
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
},
"key_id": {
"minLength": 1,
"type": "string"
},
"object_id": {
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$",
"type": "string"
},
"rco_version": {
"const": "1.0"
},
"record_id": {
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
},
"resolved_at": {
"format": "date-time",
"type": "string"
},
"rule_set": {
"properties": {
"effective_from": {
"format": "date-time",
"type": "string"
},
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"id": {
"type": "string"
},
"version": {
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$",
"type": "string"
}
},
"required": [
"id",
"version",
"hash",
"effective_from"
],
"type": "object"
},
"signal": {
"$comment": "Discriminator. Each signal binds exactly one state: CPG-000=NOT_APPLICABLE, CPG-200=ALLOW, CPG-300=CONDITIONAL, CPG-403=RESTRICT, CPG-404=NOT_FOUND, CPG-451=ESCALATE, CPG-500=SYSTEM_ERROR. conditions: required non-empty for CPG-300, forbidden otherwise. Enforced by the validator.",
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
]
},
"signature": {
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json.",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"type": "string"
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"supersedes": {
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": [
"string",
"null"
]
},
"valid_until": {
"format": "date-time",
"type": "string"
},
"verification_url": {
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.",
"format": "uri",
"type": "string"
}
},
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"type": "object"
}
},
"required": [
"record"
],
"type": "object"
},
"name": "publish_record",
"outputSchema": {
"additionalProperties": true,
"properties": {
"card_url": {
"format": "uri",
"type": "string"
},
"idempotent": {
"type": "boolean"
},
"ledger": {
"properties": {
"hash": {
"type": "string"
},
"receipt_url": {
"format": "uri",
"type": "string"
},
"transaction_id": {
"type": "string"
}
},
"type": "object"
},
"note": {
"type": "string"
},
"published": {
"type": "boolean"
},
"record_id": {
"type": "string"
},
"record_url": {
"format": "uri",
"type": "string"
},
"slot": {
"pattern": "^cpg-[0-9]{4}$",
"type": "string"
}
},
"required": [
"published",
"record_id",
"slot",
"record_url",
"ledger"
],
"type": "object"
}
},
{
"description": "Return the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.",
"inputSchema": {
"properties": {
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
],
"type": "string"
},
"object_id": {
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$",
"type": "string"
}
},
"required": [
"object_id",
"jurisdiction"
],
"type": "object"
},
"name": "resolve_compliance",
"outputSchema": {
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).",
"allOf": [
{
"$comment": "The seven legal signal/state pairs.",
"oneOf": [
{
"properties": {
"signal": {
"const": "CPG-000"
},
"state": {
"const": "NOT_APPLICABLE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-200"
},
"state": {
"const": "ALLOW"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-300"
},
"state": {
"const": "CONDITIONAL"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-403"
},
"state": {
"const": "RESTRICT"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-404"
},
"state": {
"const": "NOT_FOUND"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-451"
},
"state": {
"const": "ESCALATE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-500"
},
"state": {
"const": "SYSTEM_ERROR"
}
}
}
]
},
{
"$comment": "conditions: required non-empty for CPG-300, forbidden otherwise.",
"else": {
"not": {
"required": [
"conditions"
]
}
},
"if": {
"properties": {
"signal": {
"const": "CPG-300"
}
}
},
"then": {
"properties": {
"conditions": {
"minItems": 1
}
},
"required": [
"conditions"
]
}
},
{
"$comment": "CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.",
"else": {
"properties": {
"eco_ref": {
"type": "object"
}
}
},
"if": {
"properties": {
"signal": {
"const": "CPG-404"
}
}
},
"then": {
"properties": {
"eco_ref": {
"type": "null"
}
}
}
}
],
"properties": {
"case_study": {
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.",
"default": false,
"type": "boolean"
},
"conditions": {
"items": {
"properties": {
"code": {
"minLength": 1,
"type": "string"
},
"ref": {
"format": "uri",
"type": "string"
}
},
"required": [
"code",
"ref"
],
"type": "object"
},
"type": "array"
},
"eco_ref": {
"anyOf": [
{
"type": "null"
},
{
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"url",
"hash"
],
"type": "object"
}
]
},
"evidence_refs": {
"items": {
"properties": {
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"format": "uri",
"type": "string"
}
},
"required": [
"kind",
"url",
"hash"
],
"type": "object"
},
"type": "array"
},
"issuer": {
"properties": {
"id": {
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
}
},
"required": [
"id",
"rail",
"name"
],
"type": "object"
},
"jurisdiction": {
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.",
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
},
"key_id": {
"minLength": 1,
"type": "string"
},
"object_id": {
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$",
"type": "string"
},
"rco_version": {
"const": "1.0"
},
"record_id": {
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
},
"resolved_at": {
"format": "date-time",
"type": "string"
},
"rule_set": {
"properties": {
"effective_from": {
"format": "date-time",
"type": "string"
},
"hash": {
"pattern": "^sha256:[a-f0-9]{64}$",
"type": "string"
},
"id": {
"type": "string"
},
"version": {
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$",
"type": "string"
}
},
"required": [
"id",
"version",
"hash",
"effective_from"
],
"type": "object"
},
"signal": {
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
]
},
"signature": {
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json.",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"type": "string"
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"supersedes": {
"anyOf": [
{
"type": "null"
},
{
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$",
"type": "string"
}
]
},
"valid_until": {
"format": "date-time",
"type": "string"
},
"verification_url": {
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.",
"format": "uri",
"type": "string"
}
},
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:4b3ba9b0893145f899c549bf7f5c580977ebc1867d0234254206c92ae389827e | sha256sum