ARC · DEVELOPERS · UCP VALIDATOR
Is your UCP profile valid?
Free, instant UCP profile validator. Paste a store URL or your /.well-known/ucp JSON and get errors and warnings against the published Universal Commerce Protocol schema (2026-08-25) and spec rules. Free, no login, no limits on pasted JSON.
What it checks
- UCP schema. The document is validated against
profile.json#/$defs/business_schemafrom the published UCP 2026-08-25 release, with every referenced schema (ucp, service, capability, payment handler, reverse-domain names, signing keys). The JSON Schema files are vendored unchanged from ucp.dev/2026-08-25/schemas, built from Universal-Commerce-Protocol/ucp at tag v2026-08-25 (Apache-2.0). - UCP spec rules the schema cannot express, each linked to its section of the UCP 2026-08-25 specification: authority binding of every
schemaURL, httpsspecandendpointURLs, orphaned extensions,supported_versions, and for a URL the hosting rules (no redirects,Cache-Control: public, max-ageof at least 60, ETag or Last-Modified). - ARC hints, labelled as ours and not UCP requirements: a
dev.ucp.shoppingservice, anmcporrestbinding, and cart or checkout capabilities, which agents need to buy.
Validation is not certification, and a valid profile does not prove the endpoints work. To see whether an agent actually reaches a cart, use the free agent checkout check. The "valid UCP" count in ARC's directory is a lighter check (a dated version and a shopping service), so a store can count there and still have warnings here. Spot a wrong result? The validator source is open in ARC's repo; tell us at contact. For the reference tooling, see ucp-schema.
Use it from code, CI or an agent
curl "https://www.arcreport.ai/api/ucp/validate?url=allbirds.com" curl -X POST https://www.arcreport.ai/api/ucp/validate \ -H "content-type: application/json" \ -d @.well-known/ucp
MCP: call validate_ucp_profile with {"url":"yourstore.com"} or {"profile":{...}} on https://www.arcreport.ai/api/ask (no login). The response has valid, errors, warnings and info, each with a path, rule and spec ref. Limits: 300 URL fetches per network per day; pasted JSON is unlimited. See all developer tools, including the arc-check CLI and GitHub Action.