RCO-A2A - Regulatory Compliance Objects
Signed, deterministic compliance state per object per jurisdiction, resolved upstream
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"rco-a2a": {
"url": "https://mcp.rco-a2a.ai/mcp"
}
}
}원격 엔드포인트
https://mcp.rco-a2a.ai/mcpstreamable-http할 수 있는 일
도구 목록
도구 (5)
🟢resolve_compliance(object_id, jurisdiction)
Return the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.
입력 스키마
{
"type": "object",
"properties": {
"object_id": {
"type": "string",
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$"
},
"jurisdiction": {
"type": "string",
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
}
},
"required": [
"object_id",
"jurisdiction"
]
}출력 스키마
{
"type": "object",
"properties": {
"rco_version": {
"const": "1.0"
},
"record_id": {
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
},
"object_id": {
"type": "string",
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$"
},
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
],
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code."
},
"signal": {
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
]
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"conditions": {
"type": "array",
"items": {
"type": "object",
"required": [
"code",
"ref"
],
"properties": {
"code": {
"type": "string",
"minLength": 1
},
"ref": {
"type": "string",
"format": "uri"
}
}
}
},
"resolved_at": {
"type": "string",
"format": "date-time"
},
"valid_until": {
"type": "string",
"format": "date-time"
},
"supersedes": {
"anyOf": [
{
"type": "null"
},
{
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
}
]
},
"eco_ref": {
"anyOf": [
{
"type": "null"
},
{
"type": "object",
"required": [
"url",
"hash"
],
"properties": {
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
}
]
},
"rule_set": {
"type": "object",
"required": [
"id",
"version",
"hash",
"effective_from"
],
"properties": {
"id": {
"type": "string"
},
"version": {
"type": "string",
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"effective_from": {
"type": "string",
"format": "date-time"
}
}
},
"evidence_refs": {
"type": "array",
"items": {
"type": "object",
"required": [
"kind",
"url",
"hash"
],
"properties": {
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
}
},
"issuer": {
"type": "object",
"required": [
"id",
"rail",
"name"
],
"properties": {
"id": {
"type": "string",
"pattern": "^[a-z0-9-]+$"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
},
"name": {
"type": "string",
"minLength": 1
}
}
},
"key_id": {
"type": "string",
"minLength": 1
},
"verification_url": {
"type": "string",
"format": "uri",
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification."
},
"signature": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."
},
"case_study": {
"type": "boolean",
"default": false,
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false."
}
},
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).",
"allOf": [
{
"$comment": "The seven legal signal/state pairs.",
"oneOf": [
{
"properties": {
"signal": {
"const": "CPG-000"
},
"state": {
"const": "NOT_APPLICABLE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-200"
},
"state": {
"const": "ALLOW"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-300"
},
"state": {
"const": "CONDITIONAL"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-403"
},
"state": {
"const": "RESTRICT"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-404"
},
"state": {
"const": "NOT_FOUND"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-451"
},
"state": {
"const": "ESCALATE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-500"
},
"state": {
"const": "SYSTEM_ERROR"
}
}
}
]
},
{
"$comment": "conditions: required non-empty for CPG-300, forbidden otherwise.",
"if": {
"properties": {
"signal": {
"const": "CPG-300"
}
}
},
"then": {
"required": [
"conditions"
],
"properties": {
"conditions": {
"minItems": 1
}
}
},
"else": {
"not": {
"required": [
"conditions"
]
}
}
},
{
"$comment": "CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.",
"if": {
"properties": {
"signal": {
"const": "CPG-404"
}
}
},
"then": {
"properties": {
"eco_ref": {
"type": "null"
}
}
},
"else": {
"properties": {
"eco_ref": {
"type": "object"
}
}
}
}
]
}🟢get_record(record_id)
Return any RCO by record_id, including superseded records - the audit trail, retained byte-identical.
입력 스키마
{
"type": "object",
"properties": {
"record_id": {
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
}
},
"required": [
"record_id"
]
}출력 스키마
{
"type": "object",
"properties": {
"rco_version": {
"const": "1.0"
},
"record_id": {
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
},
"object_id": {
"type": "string",
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$"
},
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
],
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code."
},
"signal": {
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
]
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"conditions": {
"type": "array",
"items": {
"type": "object",
"required": [
"code",
"ref"
],
"properties": {
"code": {
"type": "string",
"minLength": 1
},
"ref": {
"type": "string",
"format": "uri"
}
}
}
},
"resolved_at": {
"type": "string",
"format": "date-time"
},
"valid_until": {
"type": "string",
"format": "date-time"
},
"supersedes": {
"anyOf": [
{
"type": "null"
},
{
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
}
]
},
"eco_ref": {
"anyOf": [
{
"type": "null"
},
{
"type": "object",
"required": [
"url",
"hash"
],
"properties": {
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
}
]
},
"rule_set": {
"type": "object",
"required": [
"id",
"version",
"hash",
"effective_from"
],
"properties": {
"id": {
"type": "string"
},
"version": {
"type": "string",
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"effective_from": {
"type": "string",
"format": "date-time"
}
}
},
"evidence_refs": {
"type": "array",
"items": {
"type": "object",
"required": [
"kind",
"url",
"hash"
],
"properties": {
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
}
},
"issuer": {
"type": "object",
"required": [
"id",
"rail",
"name"
],
"properties": {
"id": {
"type": "string",
"pattern": "^[a-z0-9-]+$"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
},
"name": {
"type": "string",
"minLength": 1
}
}
},
"key_id": {
"type": "string",
"minLength": 1
},
"verification_url": {
"type": "string",
"format": "uri",
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification."
},
"signature": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."
},
"case_study": {
"type": "boolean",
"default": false,
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false."
}
},
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).",
"allOf": [
{
"$comment": "The seven legal signal/state pairs.",
"oneOf": [
{
"properties": {
"signal": {
"const": "CPG-000"
},
"state": {
"const": "NOT_APPLICABLE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-200"
},
"state": {
"const": "ALLOW"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-300"
},
"state": {
"const": "CONDITIONAL"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-403"
},
"state": {
"const": "RESTRICT"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-404"
},
"state": {
"const": "NOT_FOUND"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-451"
},
"state": {
"const": "ESCALATE"
}
}
},
{
"properties": {
"signal": {
"const": "CPG-500"
},
"state": {
"const": "SYSTEM_ERROR"
}
}
}
]
},
{
"$comment": "conditions: required non-empty for CPG-300, forbidden otherwise.",
"if": {
"properties": {
"signal": {
"const": "CPG-300"
}
}
},
"then": {
"required": [
"conditions"
],
"properties": {
"conditions": {
"minItems": 1
}
}
},
"else": {
"not": {
"required": [
"conditions"
]
}
}
},
{
"$comment": "CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.",
"if": {
"properties": {
"signal": {
"const": "CPG-404"
}
}
},
"then": {
"properties": {
"eco_ref": {
"type": "null"
}
}
},
"else": {
"properties": {
"eco_ref": {
"type": "object"
}
}
}
}
]
}🟢list_rule_sets(jurisdiction)
List the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.
입력 스키마
{
"type": "object",
"properties": {
"jurisdiction": {
"type": "string",
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
}
},
"required": [
"jurisdiction"
]
}출력 스키마
{
"type": "object",
"properties": {
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
]
},
"rule_sets": {
"type": "array",
"items": {
"type": "object",
"required": [
"id",
"version",
"hash",
"effective_from",
"effective_to",
"url"
],
"properties": {
"id": {
"type": "string"
},
"version": {
"type": "string",
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"effective_from": {
"type": "string",
"format": "date-time"
},
"effective_to": {
"anyOf": [
{
"type": "null"
},
{
"type": "string",
"format": "date-time"
}
]
},
"url": {
"type": "string",
"format": "uri"
}
}
}
}
},
"required": [
"jurisdiction",
"rule_sets"
]
}🟢list_issuers
Return the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.
입력 스키마
{
"type": "object",
"properties": {}
}출력 스키마
{
"type": "object",
"properties": {
"registry_version": {
"type": "string",
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$"
},
"updated": {
"type": "string",
"format": "date-time"
},
"issuers": {
"type": "array",
"minItems": 1,
"items": {
"type": "object",
"required": [
"id",
"rail",
"name",
"jwks_url",
"status",
"admitted"
],
"properties": {
"id": {
"type": "string",
"pattern": "^[a-z0-9-]+$"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
},
"name": {
"type": "string",
"minLength": 1
},
"jwks_url": {
"type": "string",
"format": "uri"
},
"status": {
"enum": [
"active",
"suspended",
"revoked"
]
},
"admitted": {
"type": "string",
"format": "date-time"
},
"status_changed": {
"type": "string",
"format": "date-time",
"$comment": "Required when status is not active — the effective time of the suspension or revocation. Records signed before this instant by then-valid keys still verify; consumers reject records whose resolved_at is at or after it."
},
"keys": {
"type": "array",
"$comment": "Key lifecycle of record. Retired kids stay on the issuer JWKS indefinitely so historical records remain verifiable; this array dates each kid.",
"items": {
"type": "object",
"required": [
"kid",
"valid_from"
],
"properties": {
"kid": {
"type": "string"
},
"valid_from": {
"type": "string",
"format": "date-time"
},
"valid_to": {
"anyOf": [
{
"type": "null"
},
{
"type": "string",
"format": "date-time"
}
]
},
"revoked": {
"type": "boolean"
}
}
}
}
}
}
},
"key_id": {
"type": "string",
"minLength": 1
},
"verification_url": {
"type": "string",
"format": "uri"
},
"signature": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$"
},
"trust_anchor": {
"type": "object",
"required": [
"kid",
"sha256_fingerprint",
"method",
"published"
],
"properties": {
"kid": {
"type": "string"
},
"sha256_fingerprint": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"method": {
"type": "string"
},
"published": {
"type": "array",
"minItems": 2,
"items": {
"type": "string"
}
}
},
"$comment": "v1.3: the consortium key's out-of-band pin - the fingerprint is published on the dpuone.ai keyring page and as a DNS TXT record on this zone; verify either before trusting this document's own JWKS."
}
},
"required": [
"registry_version",
"updated",
"issuers",
"key_id",
"verification_url",
"signature"
],
"$comment": "Published at consortium-10060.org/issuers.json and returned by list_issuers. This document is the verification root: consumers resolve issuer.id here and take the JWKS URL from this registry; a record's in-record verification_url is a cross-check only. The registry is signed with the consortium key using the same detached-JWS profile as records; the consortium public keyring (the trust anchor) is pinned at consortium-10060.org/.well-known/jwks.json and mirrored in the RCO tree. Amendments append to amendments.json; the registry document is superseded whole, never edited."
}🟡publish_record(record)
Publish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.
입력 스키마
{
"type": "object",
"properties": {
"record": {
"$comment": "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k). Served flat since 1.0.2 (no alternation constructs; the signal discriminator binds the state); the full contract schema is https://rco-a2a.ai/schema/v1.4/resolve_compliance.tool.json and is what the validator enforces.",
"type": "object",
"required": [
"rco_version",
"record_id",
"object_id",
"jurisdiction",
"signal",
"state",
"resolved_at",
"valid_until",
"supersedes",
"eco_ref",
"rule_set",
"evidence_refs",
"issuer",
"key_id",
"verification_url",
"signature"
],
"properties": {
"rco_version": {
"const": "1.0"
},
"record_id": {
"type": "string",
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
},
"object_id": {
"type": "string",
"pattern": "^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$"
},
"jurisdiction": {
"enum": [
"EU-ECO-10060",
"FR-ECO-10060",
"DE-ECO-10060",
"ES-ECO-10060",
"IT-ECO-10060",
"NL-ECO-10060",
"PL-ECO-10060",
"CH-ECO-10060",
"UK-ECO-10060",
"BE-ECO-10060",
"PT-ECO-10060",
"AT-ECO-10060",
"IE-ECO-10060",
"CZ-ECO-10060",
"DK-ECO-10060",
"SE-ECO-10060",
"FI-ECO-10060",
"NO-ECO-10060",
"GR-ECO-10060",
"US-ECO-10060",
"CA-ECO-10060",
"MX-ECO-10060",
"BR-ECO-10060",
"AR-ECO-10060",
"CL-ECO-10060",
"CO-ECO-10060",
"CR-ECO-10060",
"DO-ECO-10060",
"EC-ECO-10060",
"GT-ECO-10060",
"PA-ECO-10060",
"PE-ECO-10060",
"UY-ECO-10060",
"AU-ECO-10060",
"JP-ECO-10060",
"KR-ECO-10060",
"SG-ECO-10060",
"IN-ECO-10060",
"ID-ECO-10060",
"MY-ECO-10060",
"PH-ECO-10060",
"TH-ECO-10060",
"VN-ECO-10060",
"AE-ECO-10060",
"SA-ECO-10060",
"IL-ECO-10060",
"TR-ECO-10060",
"MA-ECO-10060",
"ZA-ECO-10060",
"apex"
],
"$comment": "The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code."
},
"signal": {
"enum": [
"CPG-000",
"CPG-200",
"CPG-300",
"CPG-403",
"CPG-404",
"CPG-451",
"CPG-500"
],
"$comment": "Discriminator. Each signal binds exactly one state: CPG-000=NOT_APPLICABLE, CPG-200=ALLOW, CPG-300=CONDITIONAL, CPG-403=RESTRICT, CPG-404=NOT_FOUND, CPG-451=ESCALATE, CPG-500=SYSTEM_ERROR. conditions: required non-empty for CPG-300, forbidden otherwise. Enforced by the validator."
},
"state": {
"enum": [
"NOT_APPLICABLE",
"ALLOW",
"CONDITIONAL",
"RESTRICT",
"NOT_FOUND",
"ESCALATE",
"SYSTEM_ERROR"
]
},
"conditions": {
"type": "array",
"items": {
"type": "object",
"required": [
"code",
"ref"
],
"properties": {
"code": {
"type": "string",
"minLength": 1
},
"ref": {
"type": "string",
"format": "uri"
}
}
}
},
"resolved_at": {
"type": "string",
"format": "date-time"
},
"valid_until": {
"type": "string",
"format": "date-time"
},
"supersedes": {
"type": [
"string",
"null"
],
"pattern": "^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$"
},
"eco_ref": {
"type": [
"object",
"null"
],
"required": [
"url",
"hash"
],
"properties": {
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
},
"rule_set": {
"type": "object",
"required": [
"id",
"version",
"hash",
"effective_from"
],
"properties": {
"id": {
"type": "string"
},
"version": {
"type": "string",
"pattern": "^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
},
"effective_from": {
"type": "string",
"format": "date-time"
}
}
},
"evidence_refs": {
"type": "array",
"items": {
"type": "object",
"required": [
"kind",
"url",
"hash"
],
"properties": {
"kind": {
"enum": [
"esg-credential",
"dpu-proof",
"eco-object",
"other"
]
},
"url": {
"type": "string",
"format": "uri"
},
"hash": {
"type": "string",
"pattern": "^sha256:[a-f0-9]{64}$"
}
}
}
},
"issuer": {
"type": "object",
"required": [
"id",
"rail",
"name"
],
"properties": {
"id": {
"type": "string",
"pattern": "^[a-z0-9-]+$"
},
"rail": {
"enum": [
"bpc",
"cpg"
]
},
"name": {
"type": "string",
"minLength": 1
}
}
},
"key_id": {
"type": "string",
"minLength": 1
},
"verification_url": {
"type": "string",
"format": "uri",
"$comment": "Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification."
},
"signature": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$",
"description": "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."
},
"case_study": {
"type": "boolean",
"default": false,
"$comment": "v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false."
}
}
}
},
"required": [
"record"
]
}출력 스키마
{
"type": "object",
"properties": {
"published": {
"type": "boolean"
},
"idempotent": {
"type": "boolean"
},
"record_id": {
"type": "string"
},
"slot": {
"type": "string",
"pattern": "^cpg-[0-9]{4}$"
},
"record_url": {
"type": "string",
"format": "uri"
},
"card_url": {
"type": "string",
"format": "uri"
},
"ledger": {
"type": "object",
"properties": {
"transaction_id": {
"type": "string"
},
"hash": {
"type": "string"
},
"receipt_url": {
"type": "string",
"format": "uri"
}
}
},
"note": {
"type": "string"
}
},
"required": [
"published",
"record_id",
"slot",
"record_url",
"ledger"
],
"additionalProperties": true
}커뮤니티
증거