Attach one URL. Resolve the state.
RCO-A2A publishes signed, deterministic compliance state per product × jurisdiction, resolved before an agent asks. A buyer's agent consumes the result of the rules, not the rules themselves (SRI — coined by Matthew Keddy, CEO, GSC).
https://mcp.rco-a2a.ai/mcp
No account. No authentication on reads. Typed responses. Signed records. Listed on the public MCP Registry as io.github.greencore-solutions/rco-a2a.
Resolve the current state. Retrieve the historical record. Read the jurisdiction rule set. Verify the issuer.
Public — open read access for agents. Governed — the same records behind identity, policy and logging (the governed door, portal.rco-a2a.ai/mcp). Issuer — the controlled write path for parties signing records with their own keys.
The records do not change between doors. Only the access policy does.
Every RCO identifies its issuer and verification key. Every issued record carries an independent Azure Confidential Ledger receipt. Partner records verify against the partner's key.
GSC serves the record. The issuer owns the statement.
Measured availability: status.rco-a2a.ai.