SEO capability claim matrix
| Field | Value |
|---|---|
| As of | 2026-10-07 (Casablanca / UTC+1) |
| Goal | T0-AGENTIC-CLAIM-AUDIT in .agents/seo/goals.json |
| Audit checkout | clean SEO sources on main at 0f89682 (fix(seo): lead keywords and featureList with schema-backed positioning) |
| origin/main at audit | 0f89682 (in sync for SEO claim sources) |
| Method | Read-only public HTTP + OpenAPI/docs/code inspection on main; plus local loopback credentialed papi smoke (2026-10-07). Production admin credentials were not used. |
| Status vocabulary | live | in_progress | unsupported |
| Promotion rule | Only live claims may stay in public marketing / discovery copy. in_progress may appear in internal docs with explicit gating language. unsupported must not be sold as shipped. |
Worktree boundary: dirty / untracked non-SEO files on the machine were not treated as shipped evidence. Stale local VitePress agent-auth-mcp dist HTML is not live; the public docs URL returns 404.
Local smoke (2026-10-07 ~11:13 Casablanca): loopback-only against http://127.0.0.1:3000 with the existing e2e user. PASS (~3.2s): sign-in → create form → human publish → create agent → scoped grant → agent token → validate invalid (valid=false) → validate valid (valid=true) → submit → revoke agent. Evidence dir on pop-os: /tmp/kinoforms-papi-smoke-evidence. Elevates operator-provisioned identity + agent validate/submit from “interface only” to local execution verified; does not prove production parity.
Executive summary
Safe for public copy today (live):
- Schema-backed forms (native
schema.fields, not “full JSON Schema”). - Human create / edit in the visual builder.
- Scoped API create + diff-edit (
forms:write) as a documented, auth-enforced interface. - Structured response validation (
POST /papi/v1/submitter/form/validation). - Human publishing (editor / session API). Not on
/papimanagement routes. - Operator-provisioned agent identity + form-scoped grants (API); local smoke verified register → grant → token → validate → submit → revoke.
- Scoped API keys for embed / management.
- Public respondent runtime for published forms.
- Pricing honesty: free during early access (paid checkout not live).
Keep gated / omit from marketing:
- RFC 9421 agent signing —
in_progress(FEATURE_AGENT_SIGNINGdefault off; prod flag unknown). - Hosted / product MCP form-building —
unsupported(experiment only; live docs 404). - Agent or API publishing —
unsupported. - Agents settings UI — not found under settings; operator path is session/curl / documented identity API.
Claim matrix
| # | Claim | Code (main) | Docs | Live / runtime | Status | Public wording |
|---|---|---|---|---|---|---|
| 1 | Schema-backed forms | papi/builder.rs create accepts schema; validator + form adapter; OpenAPI Form model | Builder Guide schema.fields; llms.txt; agentic page; homepage SEO | Homepage / features / agentic / OpenAPI advertise schema-backed forms | live | “Schema-backed forms — fields and constraints live in the form schema.” Avoid “full JSON Schema.” |
| 2 | Human create / edit in visual builder | apps/web/src/pages/forms/new.tsx, editor.tsx; session form controllers | User guide form builder; marketing “visual editor” | Marketing pages 200 | live | “People create and edit forms in the visual builder.” |
| 3 | Scoped API create + diff-edit | POST/PATCH /papi/v1/management/forms; ops setMeta / field ops; API keys UI forms:write | Builder Guide; OpenAPI; llms.txt | Live OpenAPI; unauth → 401; local smoke created a form via session (API-key write path remains interface-verified) | live | “With a scoped API key (forms:write), create drafts and apply ordered PATCH ops.” Avoid “agents publish via API.” |
| 4 | Form PATCH expectedVersion | Shared patch compares version; publish advances currentVersion | Builder Guide Expected Version Check (PATCH does not bump version) | OpenAPI advertises expectedVersion / currentVersion | live (limited) | Optional expectedVersion must match; publishing advances version. Draft PATCH is not full optimistic concurrency. |
| 5 | Structured response validation | papi_validate / papi_submit → validate_submission | Validation Reference; Agent Quickstart; /form-submission-validation | Live OpenAPI path; local smoke invalid→valid=false, valid→valid=true | live | “Validate payloads against the form’s fields and rules.” Avoid “validates arbitrary JSON Schema.” |
| 6 | Human publishing | publish_form / unpublish_form; editor Publish UI | Public forms guide; overview | No /papi/.../publish in OpenAPI; local smoke human-published throwaway form | live (human product) | “Publish from the form editor for a public respondent link.” Do not claim agent/API publish. |
| 7 | Agent / API publishing | No publish op in papi / OpenAPI | Correctly absent from Builder Guide management verbs | OpenAPI path set has zero publish routes | unsupported | Omit from public copy. |
| 8 | Operator-provisioned agent identity + grants | papi/identity.rs — agents, grants, scopes agent:read|validate|submit | Agent Quickstart; OpenAPI identity tag; agent-discovery | Live OpenAPI; unauth → 401; local smoke create agent + grant + revoke | live (API) | “An operator registers an agent and grants form-specific scopes. Agents cannot self-activate.” No dedicated Agents settings page found. |
| 9 | Agent validate + submit under grants | session.rs scope checks; submitter routes | Agent Quickstart steps 4–5; Submitter guide | OpenAPI paths live; local smoke token → validate → submit | live (local execution verified; prod parity open) | “With operator grants and a session token (or signed request when enabled), agents can validate and submit to granted forms.” Frame as operator-provisioned / API. |
| 10 | Scoped API keys | API key validation; settings API Keys page | User guide API keys; Builder Guide auth | Settings page in app; OpenAPI ApiKeyAuth | live | “Scoped API keys (forms:read, forms:write, submission scopes).” |
| 11 | RFC 9421 signed agent requests | papi/signing.rs; key register under identity | Agent Quickstart: gated by FEATURE_AGENT_SIGNING (off by default) | Key paths in OpenAPI; prod flag unknown | in_progress | Docs/internal only until flag-on confirmed in prod + smoke. |
| 12 | Hosted MCP / product MCP form-building | No MCP route in API; experiments/agent-credential-mcp/ only | Quickstart points at experiment; no source guide page | Live …/developer/agent-auth-mcp 404; not in docs sitemap / OpenAPI | unsupported (public product) | Omit from marketing, llms.txt, agent-discovery. Optional footnote: experimental local helper in repo. |
| 13 | AI form assistant in builder | Form-builder AI chat components | User guide AI form assistant | Separate from agent-identity API | live (distinct claim) | “AI form assistant” — do not conflate with agent identity / MCP. |
| 14 | Public respondent runtime | Public form by access key; /f/<accessKey> | agent-discovery; public forms guide | /f/* SPA 200; public API 404 for unknown key | live | “Published forms are available at public respondent URLs.” |
| 15 | Pricing: paid plans live checkout | Prior SEO fix removed paid-plan title overclaim | Pricing early-access copy | Live title “Free During Early Access” | unsupported as paid-live; live as free early access | Keep early-access honesty. No paid checkout claims. |
Public copy vs matrix (spot check, 2026-10-07)
| Surface | Alignment |
|---|---|
| Homepage / features / agentic | Aligned with live claims 1–3, 5 after keywords/featureList tidy (0f89682). |
| Pricing | Aligned with claim 15 after 6b85fd5. |
agent-discovery.md | Aligned if read as operator-granted API, not polished Agents UI. |
llms.txt | Aligned (create/PATCH + validation; no MCP/publish). |
| Agent Quickstart | Correctly documents grants, validate/submit, gates signing; MCP as experiment only. |
| OpenAPI “identity fully live” | Acceptable for API contract; local smoke backs execution on loopback; prod smoke still open. |
Open follow-ups
- Production credentialed papi smoke (disposable workspace) for claims 3/8/9 parity.
- Confirm whether
FEATURE_AGENT_SIGNINGis on in production. - Product intent: Settings → Agents UI vs session/curl as the supported operator path.
- When MCP or signing becomes GA: flip the dated row here, then marketing.
Appendix — live OpenAPI paths (2026-10-07)
/papi/v1/auth/anonymous
/papi/v1/auth/token
/papi/v1/docs
/papi/v1/identity/agents
/papi/v1/identity/agents/{agent_id}
/papi/v1/identity/agents/{agent_id}/grants
/papi/v1/identity/agents/{agent_id}/grants/{grant_id}
/papi/v1/identity/agents/{agent_id}/keys
/papi/v1/identity/agents/{agent_id}/keys/{key_id}
/papi/v1/identity/agents/{agent_id}/rotate-secret
/papi/v1/management/forms
/papi/v1/management/forms/{form_id}
/papi/v1/management/forms/{form_id}/submissions
/papi/v1/management/forms/{form_id}/submissions/{submission_id}
/papi/v1/openapi.json
/papi/v1/submitter/challenges/{challenge_id}/responses
/papi/v1/submitter/form/challenges
/papi/v1/submitter/form/submissions
/papi/v1/submitter/form/validationNo publish route. Identity + management + submitter + challenge only.
Prior art
artifacts/seo-agent/2026-09-29T06-30-29-918Z/claim-matrix.mdartifacts/seo-agent/2026-10-01T04-48-01-153Z/executor-evidence/claim-matrix.mdartifacts/seo-agent/2026-10-03T04-25-16-134Z/executor-evidence/category-claim-audit.json- Agent-box drafts:
/workspace/seo-drafts/2026-10-07-T0-AGENTIC-CLAIM-AUDIT.md,/workspace/seo-drafts/2026-10-07-papi-smoke-evidence-summary.md
