MCP 服务器

RCO-A2A - Regulatory Compliance Objects

io.github.greencore-solutions/rco-a2a
法律与合规 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Resolves, retrieves, publishes, and audits signed regulatory compliance records and jurisdiction-specific rule sets.

get_record
Get record by id
Return any RCO by record_id, including superseded records - the audit trail, retained byte-identical.
只读 幂等
输入模式
{'type': 'object', 'required': ['record_id'], 'properties': {'record_id': {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}}}
输出模式
{'type': 'object', 'allOf': [{'oneOf': [{'properties': {'state': {'const': 'NOT_APPLICABLE'}, 'signal': {'const': 'CPG-000'}}}, {'properties': {'state': {'const': 'ALLOW'}, 'signal': {'const': 'CPG-200'}}}, {'properties': {'state': {'const': 'CONDITIONAL'}, 'signal': {'const': 'CPG-300'}}}, {'properties': {'state': {'const': 'RESTRICT'}, 'signal': {'const': 'CPG-403'}}}, {'properties': {'state': {'const': 'NOT_FOUND'}, 'signal': {'const': 'CPG-404'}}}, {'properties': {'state': {'const': 'ESCALATE'}, 'signal': {'const': 'CPG-451'}}}, {'properties': {'state': {'const': 'SYSTEM_ERROR'}, 'signal': {'const': 'CPG-500'}}}], '$comment': 'The seven legal signal/state pairs.'}, {'if': {'properties': {'signal': {'const': 'CPG-300'}}}, 'else': {'not': {'required': ['conditions']}}, 'then': {'required': ['conditions'], 'properties': {'conditions': {'minItems': 1}}}, '$comment': 'conditions: required non-empty for CPG-300, forbidden otherwise.'}, {'if': {'properties': {'signal': {'const': 'CPG-404'}}}, 'else': {'properties': {'eco_ref': {'type': 'object'}}}, 'then': {'properties': {'eco_ref': {'type': 'null'}}}, '$comment': 'CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.'}], '$comment': "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).", 'required': ['rco_version', 'record_id', 'object_id', 'jurisdiction', 'signal', 'state', 'resolved_at', 'valid_until', 'supersedes', 'eco_ref', 'rule_set', 'evidence_refs', 'issuer', 'key_id', 'verification_url', 'signature'], 'properties': {'state': {'enum': ['NOT_APPLICABLE', 'ALLOW', 'CONDITIONAL', 'RESTRICT', 'NOT_FOUND', 'ESCALATE', 'SYSTEM_ERROR']}, 'issuer': {'type': 'object', 'required': ['id', 'rail', 'name'], 'properties': {'id': {'type': 'string', 'pattern': '^[a-z0-9-]+$'}, 'name': {'type': 'string', 'minLength': 1}, 'rail': {'enum': ['bpc', 'cpg']}}}, 'key_id': {'type': 'string', 'minLength': 1}, 'signal': {'enum': ['CPG-000', 'CPG-200', 'CPG-300', 'CPG-403', 'CPG-404', 'CPG-451', 'CPG-500']}, 'eco_ref': {'anyOf': [{'type': 'null'}, {'type': 'object', 'required': ['url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}}}]}, 'rule_set': {'type': 'object', 'required': ['id', 'version', 'hash', 'effective_from'], 'properties': {'id': {'type': 'string'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'version': {'type': 'string', 'pattern': '^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$'}, 'effective_from': {'type': 'string', 'format': 'date-time'}}}, 'object_id': {'type': 'string', 'pattern': '^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$'}, 'record_id': {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}, 'signature': {'type': 'string', 'pattern': '^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$', 'description': "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."}, 'case_study': {'type': 'boolean', 'default': False, '$comment': 'v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.'}, 'conditions': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'ref'], 'properties': {'ref': {'type': 'string', 'format': 'uri'}, 'code': {'type': 'string', 'minLength': 1}}}}, 'supersedes': {'anyOf': [{'type': 'null'}, {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}]}, 'rco_version': {'const': '1.0'}, 'resolved_at': {'type': 'string', 'format': 'date-time'}, 'valid_until': {'type': 'string', 'format': 'date-time'}, 'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex'], '$comment': 'The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.'}, 'evidence_refs': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'kind': {'enum': ['esg-credential', 'dpu-proof', 'eco-object', 'other']}}}}, 'verification_url': {'type': 'string', 'format': 'uri', '$comment': 'Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.'}}}
list_issuers
List issuers
Return the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.
只读 幂等
输入模式
{'type': 'object', 'properties': {}}
输出模式
{'type': 'object', '$comment': "Published at consortium-10060.org/issuers.json and returned by list_issuers. This document is the verification root: consumers resolve issuer.id here and take the JWKS URL from this registry; a record's in-record verification_url is a cross-check only. The registry is signed with the consortium key using the same detached-JWS profile as records; the consortium public keyring (the trust anchor) is pinned at consortium-10060.org/.well-known/jwks.json and mirrored in the RCO tree. Amendments append to amendments.json; the registry document is superseded whole, never edited.", 'required': ['registry_version', 'updated', 'issuers', 'key_id', 'verification_url', 'signature'], 'properties': {'key_id': {'type': 'string', 'minLength': 1}, 'issuers': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'rail', 'name', 'jwks_url', 'status', 'admitted'], 'properties': {'id': {'type': 'string', 'pattern': '^[a-z0-9-]+$'}, 'keys': {'type': 'array', 'items': {'type': 'object', 'required': ['kid', 'valid_from'], 'properties': {'kid': {'type': 'string'}, 'revoked': {'type': 'boolean'}, 'valid_to': {'anyOf': [{'type': 'null'}, {'type': 'string', 'format': 'date-time'}]}, 'valid_from': {'type': 'string', 'format': 'date-time'}}}, '$comment': 'Key lifecycle of record. Retired kids stay on the issuer JWKS indefinitely so historical records remain verifiable; this array dates each kid.'}, 'name': {'type': 'string', 'minLength': 1}, 'rail': {'enum': ['bpc', 'cpg']}, 'status': {'enum': ['active', 'suspended', 'revoked']}, 'admitted': {'type': 'string', 'format': 'date-time'}, 'jwks_url': {'type': 'string', 'format': 'uri'}, 'status_changed': {'type': 'string', 'format': 'date-time', '$comment': 'Required when status is not active — the effective time of the suspension or revocation. Records signed before this instant by then-valid keys still verify; consumers reject records whose resolved_at is at or after it.'}}}, 'minItems': 1}, 'updated': {'type': 'string', 'format': 'date-time'}, 'signature': {'type': 'string', 'pattern': '^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$'}, 'trust_anchor': {'type': 'object', '$comment': "v1.3: the consortium key's out-of-band pin - the fingerprint is published on the dpuone.ai keyring page and as a DNS TXT record on this zone; verify either before trusting this document's own JWKS.", 'required': ['kid', 'sha256_fingerprint', 'method', 'published'], 'properties': {'kid': {'type': 'string'}, 'method': {'type': 'string'}, 'published': {'type': 'array', 'items': {'type': 'string'}, 'minItems': 2}, 'sha256_fingerprint': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}}}, 'registry_version': {'type': 'string', 'pattern': '^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$'}, 'verification_url': {'type': 'string', 'format': 'uri'}}}
list_rule_sets
List rule sets
List the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.
只读 幂等
输入模式
{'type': 'object', 'required': ['jurisdiction'], 'properties': {'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex'], 'type': 'string'}}}
输出模式
{'type': 'object', 'required': ['jurisdiction', 'rule_sets'], 'properties': {'rule_sets': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'version', 'hash', 'effective_from', 'effective_to', 'url'], 'properties': {'id': {'type': 'string'}, 'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'version': {'type': 'string', 'pattern': '^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$'}, 'effective_to': {'anyOf': [{'type': 'null'}, {'type': 'string', 'format': 'date-time'}]}, 'effective_from': {'type': 'string', 'format': 'date-time'}}}}, 'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex']}}}
publish_record
Publish record (issuer)
Publish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.
幂等
输入模式
{'type': 'object', 'required': ['record'], 'properties': {'record': {'type': 'object', '$comment': "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k). Served flat since 1.0.2 (no alternation constructs; the signal discriminator binds the state); the full contract schema is https://rco-a2a.ai/schema/v1.4/resolve_compliance.tool.json and is what the validator enforces.", 'required': ['rco_version', 'record_id', 'object_id', 'jurisdiction', 'signal', 'state', 'resolved_at', 'valid_until', 'supersedes', 'eco_ref', 'rule_set', 'evidence_refs', 'issuer', 'key_id', 'verification_url', 'signature'], 'properties': {'state': {'enum': ['NOT_APPLICABLE', 'ALLOW', 'CONDITIONAL', 'RESTRICT', 'NOT_FOUND', 'ESCALATE', 'SYSTEM_ERROR']}, 'issuer': {'type': 'object', 'required': ['id', 'rail', 'name'], 'properties': {'id': {'type': 'string', 'pattern': '^[a-z0-9-]+$'}, 'name': {'type': 'string', 'minLength': 1}, 'rail': {'enum': ['bpc', 'cpg']}}}, 'key_id': {'type': 'string', 'minLength': 1}, 'signal': {'enum': ['CPG-000', 'CPG-200', 'CPG-300', 'CPG-403', 'CPG-404', 'CPG-451', 'CPG-500'], '$comment': 'Discriminator. Each signal binds exactly one state: CPG-000=NOT_APPLICABLE, CPG-200=ALLOW, CPG-300=CONDITIONAL, CPG-403=RESTRICT, CPG-404=NOT_FOUND, CPG-451=ESCALATE, CPG-500=SYSTEM_ERROR. conditions: required non-empty for CPG-300, forbidden otherwise. Enforced by the validator.'}, 'eco_ref': {'type': ['object', 'null'], 'required': ['url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}}}, 'rule_set': {'type': 'object', 'required': ['id', 'version', 'hash', 'effective_from'], 'properties': {'id': {'type': 'string'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'version': {'type': 'string', 'pattern': '^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$'}, 'effective_from': {'type': 'string', 'format': 'date-time'}}}, 'object_id': {'type': 'string', 'pattern': '^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$'}, 'record_id': {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}, 'signature': {'type': 'string', 'pattern': '^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$', 'description': "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."}, 'case_study': {'type': 'boolean', 'default': False, '$comment': 'v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.'}, 'conditions': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'ref'], 'properties': {'ref': {'type': 'string', 'format': 'uri'}, 'code': {'type': 'string', 'minLength': 1}}}}, 'supersedes': {'type': ['string', 'null'], 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}, 'rco_version': {'const': '1.0'}, 'resolved_at': {'type': 'string', 'format': 'date-time'}, 'valid_until': {'type': 'string', 'format': 'date-time'}, 'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex'], '$comment': 'The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.'}, 'evidence_refs': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'kind': {'enum': ['esg-credential', 'dpu-proof', 'eco-object', 'other']}}}}, 'verification_url': {'type': 'string', 'format': 'uri', '$comment': 'Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.'}}}}}
输出模式
{'type': 'object', 'required': ['published', 'record_id', 'slot', 'record_url', 'ledger'], 'properties': {'note': {'type': 'string'}, 'slot': {'type': 'string', 'pattern': '^cpg-[0-9]{4}$'}, 'ledger': {'type': 'object', 'properties': {'hash': {'type': 'string'}, 'receipt_url': {'type': 'string', 'format': 'uri'}, 'transaction_id': {'type': 'string'}}}, 'card_url': {'type': 'string', 'format': 'uri'}, 'published': {'type': 'boolean'}, 'record_id': {'type': 'string'}, 'idempotent': {'type': 'boolean'}, 'record_url': {'type': 'string', 'format': 'uri'}}, 'additionalProperties': True}
resolve_compliance
Resolve compliance state
Return the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.
只读 幂等
输入模式
{'type': 'object', 'required': ['object_id', 'jurisdiction'], 'properties': {'object_id': {'type': 'string', 'pattern': '^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$'}, 'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex'], 'type': 'string'}}}
输出模式
{'type': 'object', 'allOf': [{'oneOf': [{'properties': {'state': {'const': 'NOT_APPLICABLE'}, 'signal': {'const': 'CPG-000'}}}, {'properties': {'state': {'const': 'ALLOW'}, 'signal': {'const': 'CPG-200'}}}, {'properties': {'state': {'const': 'CONDITIONAL'}, 'signal': {'const': 'CPG-300'}}}, {'properties': {'state': {'const': 'RESTRICT'}, 'signal': {'const': 'CPG-403'}}}, {'properties': {'state': {'const': 'NOT_FOUND'}, 'signal': {'const': 'CPG-404'}}}, {'properties': {'state': {'const': 'ESCALATE'}, 'signal': {'const': 'CPG-451'}}}, {'properties': {'state': {'const': 'SYSTEM_ERROR'}, 'signal': {'const': 'CPG-500'}}}], '$comment': 'The seven legal signal/state pairs.'}, {'if': {'properties': {'signal': {'const': 'CPG-300'}}}, 'else': {'not': {'required': ['conditions']}}, 'then': {'required': ['conditions'], 'properties': {'conditions': {'minItems': 1}}}, '$comment': 'conditions: required non-empty for CPG-300, forbidden otherwise.'}, {'if': {'properties': {'signal': {'const': 'CPG-404'}}}, 'else': {'properties': {'eco_ref': {'type': 'object'}}}, 'then': {'properties': {'eco_ref': {'type': 'null'}}}, '$comment': 'CPG-404 carries eco_ref null; every other signal carries a non-null eco_ref.'}], '$comment': "Record wire version stays 1.0. Cross-field checks a JSON Schema cannot express are normative in the specification and enforced by the published validator: (a) resolved_at < valid_until; (b) record_id's issuer/object/jurisdiction segments equal issuer.id, object_id and jurisdiction; (c) supersedes, when present, differs from record_id only in its trailing sequence number, which is exactly one lower; (d) GTINs are zero-padded GTIN-14 with a valid GS1 check digit; (e) host object_ids are lowercase, punycode-encoded, no trailing dot. record_id keeps its colons on the wire; a filesystem mirror replaces each colon with an underscore (CEO ruling 2026-08-29). GB is rejected as invalid_jurisdiction naming the valid set — UK is the member code (permanent GB=UK rule). Verification VERIFIES every byte of the canonical signing payload; nothing claims to reproduce signature bytes (ECDSA is randomized). v1.3 adds the optional case_study boolean and the unit rule: record-holders are keyed GTIN x jurisdiction only (NG-11 s2k).", 'required': ['rco_version', 'record_id', 'object_id', 'jurisdiction', 'signal', 'state', 'resolved_at', 'valid_until', 'supersedes', 'eco_ref', 'rule_set', 'evidence_refs', 'issuer', 'key_id', 'verification_url', 'signature'], 'properties': {'state': {'enum': ['NOT_APPLICABLE', 'ALLOW', 'CONDITIONAL', 'RESTRICT', 'NOT_FOUND', 'ESCALATE', 'SYSTEM_ERROR']}, 'issuer': {'type': 'object', 'required': ['id', 'rail', 'name'], 'properties': {'id': {'type': 'string', 'pattern': '^[a-z0-9-]+$'}, 'name': {'type': 'string', 'minLength': 1}, 'rail': {'enum': ['bpc', 'cpg']}}}, 'key_id': {'type': 'string', 'minLength': 1}, 'signal': {'enum': ['CPG-000', 'CPG-200', 'CPG-300', 'CPG-403', 'CPG-404', 'CPG-451', 'CPG-500']}, 'eco_ref': {'anyOf': [{'type': 'null'}, {'type': 'object', 'required': ['url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}}}]}, 'rule_set': {'type': 'object', 'required': ['id', 'version', 'hash', 'effective_from'], 'properties': {'id': {'type': 'string'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'version': {'type': 'string', 'pattern': '^20[0-9]{2}\\.(0[1-9]|1[0-2])(\\.[0-9]+)?$'}, 'effective_from': {'type': 'string', 'format': 'date-time'}}}, 'object_id': {'type': 'string', 'pattern': '^(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63})$'}, 'record_id': {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}, 'signature': {'type': 'string', 'pattern': '^[A-Za-z0-9_-]+\\.\\.[A-Za-z0-9_-]+$', 'description': "Detached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json."}, 'case_study': {'type': 'boolean', 'default': False, '$comment': 'v1.3 (CEO close-out ruling): true marks a labelled case-study record (e.g. the elyssah worked chain); never counted in the real-maker number. Absent = false.'}, 'conditions': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'ref'], 'properties': {'ref': {'type': 'string', 'format': 'uri'}, 'code': {'type': 'string', 'minLength': 1}}}}, 'supersedes': {'anyOf': [{'type': 'null'}, {'type': 'string', 'pattern': '^rco:[a-z0-9-]+:(gtin:[0-9]{14}|host:([a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?\\.)+[a-z]{2,63}):([A-Z]{2}-ECO-10060|apex):[1-9][0-9]*$'}]}, 'rco_version': {'const': '1.0'}, 'resolved_at': {'type': 'string', 'format': 'date-time'}, 'valid_until': {'type': 'string', 'format': 'date-time'}, 'jurisdiction': {'enum': ['EU-ECO-10060', 'FR-ECO-10060', 'DE-ECO-10060', 'ES-ECO-10060', 'IT-ECO-10060', 'NL-ECO-10060', 'PL-ECO-10060', 'CH-ECO-10060', 'UK-ECO-10060', 'BE-ECO-10060', 'PT-ECO-10060', 'AT-ECO-10060', 'IE-ECO-10060', 'CZ-ECO-10060', 'DK-ECO-10060', 'SE-ECO-10060', 'FI-ECO-10060', 'NO-ECO-10060', 'GR-ECO-10060', 'US-ECO-10060', 'CA-ECO-10060', 'MX-ECO-10060', 'BR-ECO-10060', 'AR-ECO-10060', 'CL-ECO-10060', 'CO-ECO-10060', 'CR-ECO-10060', 'DO-ECO-10060', 'EC-ECO-10060', 'GT-ECO-10060', 'PA-ECO-10060', 'PE-ECO-10060', 'UY-ECO-10060', 'AU-ECO-10060', 'JP-ECO-10060', 'KR-ECO-10060', 'SG-ECO-10060', 'IN-ECO-10060', 'ID-ECO-10060', 'MY-ECO-10060', 'PH-ECO-10060', 'TH-ECO-10060', 'VN-ECO-10060', 'AE-ECO-10060', 'SA-ECO-10060', 'IL-ECO-10060', 'TR-ECO-10060', 'MA-ECO-10060', 'ZA-ECO-10060', 'apex'], '$comment': 'The 49 SM-ECO-10060 member jurisdictions + EU bloc + apex, generated from the signed member registry. GB is rejected; UK is the code.'}, 'evidence_refs': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'url', 'hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'kind': {'enum': ['esg-credential', 'dpu-proof', 'eco-object', 'other']}}}}, 'verification_url': {'type': 'string', 'format': 'uri', '$comment': 'Cross-check only. The verification root is the signed consortium issuer registry: consumers resolve issuer.id there and take the JWKS URL from the registry; mismatch with this field fails verification.'}}}
已更改
publish_record
2026年9月19日 02:42
已更改
list_issuers
2026年9月19日 02:42
已更改
list_rule_sets
2026年9月19日 02:42
已更改
get_record
2026年9月19日 02:42
已更改
resolve_compliance
2026年9月19日 02:42
已添加
publish_record
2026年9月17日 12:42
已添加
list_issuers
2026年9月17日 12:42
已添加
list_rule_sets
2026年9月17日 12:42
已添加
get_record
2026年9月17日 12:42
已添加
resolve_compliance
2026年9月17日 12:42