MCP App Store
by KeenEthics
Commerce-Shopping

RCO-A2A

by GreenCore Solutions Corp.

Overview

RCO-A2A serves Regulatory Compliance Objects: signed, deterministic, machine-verifiable compliance state per GTIN per jurisdiction, resolved upstream — agents consume the result of the rules, not the rules. Four read tools (resolve_compliance, get_record, list_rule_sets, list_issuers) are session-free, require no account, and return typed responses; one write tool (publish_record) is the controlled issuer path on the partner rail and requires an issuer subscription key. Every record carries its issuer, key id and verification URL; records verify from the public keyring at dpuone.ai and are receipted on Azure Confidential Ledger. Rule sets are versioned and hashed per jurisdiction (49 members + apex under SM-ECO-10060). The protocol layer — record schema, tool contract, signal vocabulary — is MIT at github.com/greencore-solutions/rco-a2a. Operated by GreenCore Solutions Corp., Microsoft AI Cloud Partner, D-U-N-S 24-336-6774, GS1 Canada licensee.

Tools

get_record

Claude
Return any RCO by record_id, including superseded records - the audit trail, retained byte-identical.

list_issuers

Claude
Return the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.

list_rule_sets

Claude
List the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.

publish_record

Claude
Publish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.

resolve_compliance

Claude
Return the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.

App Stats

5

Tools

Claude

Platforms

Works with

Claude

Data refreshed daily