Skip to content

SEO capability claim matrix ​

FieldValue
As of2026-10-07 (Casablanca / UTC+1)
GoalT0-AGENTIC-CLAIM-AUDIT in .agents/seo/goals.json
Audit checkoutclean SEO sources on main at 0f89682 (fix(seo): lead keywords and featureList with schema-backed positioning)
origin/main at audit0f89682 (in sync for SEO claim sources)
MethodRead-only public HTTP + OpenAPI/docs/code inspection on main; plus local loopback credentialed papi smoke (2026-10-07). Production admin credentials were not used.
Status vocabularylive | in_progress | unsupported
Promotion ruleOnly live claims may stay in public marketing / discovery copy. in_progress may appear in internal docs with explicit gating language. unsupported must not be sold as shipped.

Worktree boundary: dirty / untracked non-SEO files on the machine were not treated as shipped evidence. Stale local VitePress agent-auth-mcp dist HTML is not live; the public docs URL returns 404.

Local smoke (2026-10-07 ~11:13 Casablanca): loopback-only against http://127.0.0.1:3000 with the existing e2e user. PASS (~3.2s): sign-in → create form → human publish → create agent → scoped grant → agent token → validate invalid (valid=false) → validate valid (valid=true) → submit → revoke agent. Evidence dir on pop-os: /tmp/kinoforms-papi-smoke-evidence. Elevates operator-provisioned identity + agent validate/submit from “interface only” to local execution verified; does not prove production parity.


Executive summary ​

Safe for public copy today (live):

  1. Schema-backed forms (native schema.fields, not “full JSON Schema”).
  2. Human create / edit in the visual builder.
  3. Scoped API create + diff-edit (forms:write) as a documented, auth-enforced interface.
  4. Structured response validation (POST /papi/v1/submitter/form/validation).
  5. Human publishing (editor / session API). Not on /papi management routes.
  6. Operator-provisioned agent identity + form-scoped grants (API); local smoke verified register → grant → token → validate → submit → revoke.
  7. Scoped API keys for embed / management.
  8. Public respondent runtime for published forms.
  9. Pricing honesty: free during early access (paid checkout not live).

Keep gated / omit from marketing:

  • RFC 9421 agent signing — in_progress (FEATURE_AGENT_SIGNING default off; prod flag unknown).
  • Hosted / product MCP form-building — unsupported (experiment only; live docs 404).
  • Agent or API publishing — unsupported.
  • Agents settings UI — not found under settings; operator path is session/curl / documented identity API.

Claim matrix ​

#ClaimCode (main)DocsLive / runtimeStatusPublic wording
1Schema-backed formspapi/builder.rs create accepts schema; validator + form adapter; OpenAPI Form modelBuilder Guide schema.fields; llms.txt; agentic page; homepage SEOHomepage / features / agentic / OpenAPI advertise schema-backed formslive“Schema-backed forms — fields and constraints live in the form schema.” Avoid “full JSON Schema.”
2Human create / edit in visual builderapps/web/src/pages/forms/new.tsx, editor.tsx; session form controllersUser guide form builder; marketing “visual editor”Marketing pages 200live“People create and edit forms in the visual builder.”
3Scoped API create + diff-editPOST/PATCH /papi/v1/management/forms; ops setMeta / field ops; API keys UI forms:writeBuilder Guide; OpenAPI; llms.txtLive OpenAPI; unauth → 401; local smoke created a form via session (API-key write path remains interface-verified)live“With a scoped API key (forms:write), create drafts and apply ordered PATCH ops.” Avoid “agents publish via API.”
4Form PATCH expectedVersionShared patch compares version; publish advances currentVersionBuilder Guide Expected Version Check (PATCH does not bump version)OpenAPI advertises expectedVersion / currentVersionlive (limited)Optional expectedVersion must match; publishing advances version. Draft PATCH is not full optimistic concurrency.
5Structured response validationpapi_validate / papi_submit → validate_submissionValidation Reference; Agent Quickstart; /form-submission-validationLive OpenAPI path; local smoke invalid→valid=false, valid→valid=truelive“Validate payloads against the form’s fields and rules.” Avoid “validates arbitrary JSON Schema.”
6Human publishingpublish_form / unpublish_form; editor Publish UIPublic forms guide; overviewNo /papi/.../publish in OpenAPI; local smoke human-published throwaway formlive (human product)“Publish from the form editor for a public respondent link.” Do not claim agent/API publish.
7Agent / API publishingNo publish op in papi / OpenAPICorrectly absent from Builder Guide management verbsOpenAPI path set has zero publish routesunsupportedOmit from public copy.
8Operator-provisioned agent identity + grantspapi/identity.rs — agents, grants, scopes agent:read|validate|submitAgent Quickstart; OpenAPI identity tag; agent-discoveryLive OpenAPI; unauth → 401; local smoke create agent + grant + revokelive (API)“An operator registers an agent and grants form-specific scopes. Agents cannot self-activate.” No dedicated Agents settings page found.
9Agent validate + submit under grantssession.rs scope checks; submitter routesAgent Quickstart steps 4–5; Submitter guideOpenAPI paths live; local smoke token → validate → submitlive (local execution verified; prod parity open)“With operator grants and a session token (or signed request when enabled), agents can validate and submit to granted forms.” Frame as operator-provisioned / API.
10Scoped API keysAPI key validation; settings API Keys pageUser guide API keys; Builder Guide authSettings page in app; OpenAPI ApiKeyAuthlive“Scoped API keys (forms:read, forms:write, submission scopes).”
11RFC 9421 signed agent requestspapi/signing.rs; key register under identityAgent Quickstart: gated by FEATURE_AGENT_SIGNING (off by default)Key paths in OpenAPI; prod flag unknownin_progressDocs/internal only until flag-on confirmed in prod + smoke.
12Hosted MCP / product MCP form-buildingNo MCP route in API; experiments/agent-credential-mcp/ onlyQuickstart points at experiment; no source guide pageLive …/developer/agent-auth-mcp 404; not in docs sitemap / OpenAPIunsupported (public product)Omit from marketing, llms.txt, agent-discovery. Optional footnote: experimental local helper in repo.
13AI form assistant in builderForm-builder AI chat componentsUser guide AI form assistantSeparate from agent-identity APIlive (distinct claim)“AI form assistant” — do not conflate with agent identity / MCP.
14Public respondent runtimePublic form by access key; /f/<accessKey>agent-discovery; public forms guide/f/* SPA 200; public API 404 for unknown keylive“Published forms are available at public respondent URLs.”
15Pricing: paid plans live checkoutPrior SEO fix removed paid-plan title overclaimPricing early-access copyLive title “Free During Early Access”unsupported as paid-live; live as free early accessKeep early-access honesty. No paid checkout claims.

Public copy vs matrix (spot check, 2026-10-07) ​

SurfaceAlignment
Homepage / features / agenticAligned with live claims 1–3, 5 after keywords/featureList tidy (0f89682).
PricingAligned with claim 15 after 6b85fd5.
agent-discovery.mdAligned if read as operator-granted API, not polished Agents UI.
llms.txtAligned (create/PATCH + validation; no MCP/publish).
Agent QuickstartCorrectly documents grants, validate/submit, gates signing; MCP as experiment only.
OpenAPI “identity fully live”Acceptable for API contract; local smoke backs execution on loopback; prod smoke still open.

Open follow-ups ​

  1. Production credentialed papi smoke (disposable workspace) for claims 3/8/9 parity.
  2. Confirm whether FEATURE_AGENT_SIGNING is on in production.
  3. Product intent: Settings → Agents UI vs session/curl as the supported operator path.
  4. When MCP or signing becomes GA: flip the dated row here, then marketing.

Appendix — live OpenAPI paths (2026-10-07) ​

/papi/v1/auth/anonymous
/papi/v1/auth/token
/papi/v1/docs
/papi/v1/identity/agents
/papi/v1/identity/agents/{agent_id}
/papi/v1/identity/agents/{agent_id}/grants
/papi/v1/identity/agents/{agent_id}/grants/{grant_id}
/papi/v1/identity/agents/{agent_id}/keys
/papi/v1/identity/agents/{agent_id}/keys/{key_id}
/papi/v1/identity/agents/{agent_id}/rotate-secret
/papi/v1/management/forms
/papi/v1/management/forms/{form_id}
/papi/v1/management/forms/{form_id}/submissions
/papi/v1/management/forms/{form_id}/submissions/{submission_id}
/papi/v1/openapi.json
/papi/v1/submitter/challenges/{challenge_id}/responses
/papi/v1/submitter/form/challenges
/papi/v1/submitter/form/submissions
/papi/v1/submitter/form/validation

No publish route. Identity + management + submitter + challenge only.

Prior art ​

  • artifacts/seo-agent/2026-09-29T06-30-29-918Z/claim-matrix.md
  • artifacts/seo-agent/2026-10-01T04-48-01-153Z/executor-evidence/claim-matrix.md
  • artifacts/seo-agent/2026-10-03T04-25-16-134Z/executor-evidence/category-claim-audit.json
  • Agent-box drafts: /workspace/seo-drafts/2026-10-07-T0-AGENTIC-CLAIM-AUDIT.md, /workspace/seo-drafts/2026-10-07-papi-smoke-evidence-summary.md

KinoForms documentation