generated: '2026-09-05' method: probed source: >- https://api.4screen.com/auth/realms/fourscreen/.well-known/openid-configuration (HTTP 200, saved verbatim to well-known/4screen-openid-configuration.json), https://4screen.com/.well-known/security.txt (HTTP 200), https://4screen.com/privacy-policy/ (HTTP 200), https://4screen.com/advertising-conditions-europe/ (HTTP 200). name: 4.screen standards conformance description: >- What 4.screen's own published documents demonstrably conform to. Every entry below is asserted from a document that was fetched, not from a marketing claim. The two-item summary: 4.screen's AUTHENTICATION layer is standards-rich and machine-verifiable, while its API layer publishes no contract at all, so every REST/HTTP convention below is unknown rather than absent. conformance: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://api.4screen.com/auth/realms/fourscreen/.well-known/openid-configuration returns HTTP 200 application/json with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri, response_types_supported, subject_types_supported and id_token_signing_alg_values_supported — the full required set. Verified 2026-09-05. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- The same discovery document advertises authorization_code, client_credentials and refresh_token grants against /protocol/openid-connect/auth and /protocol/openid-connect/token. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- https://api.4screen.com/auth/realms/fourscreen/.well-known/oauth-authorization-server returns HTTP 200 with the identical metadata document. Saved verbatim to well-known/4screen-oauth-authorization-server.json. - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: ["plain","S256"] in the discovery document.' - id: rfc8705 name: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (RFC 8705) conforms: true evidence: >- tls_client_auth is listed in token_endpoint_auth_methods_supported and tls_client_certificate_bound_access_tokens is true; mtls_endpoint_aliases is present with eight aliased endpoints. - id: rfc9126 name: OAuth 2.0 Pushed Authorization Requests (RFC 9126) conforms: true evidence: >- pushed_authorization_request_endpoint is published at /protocol/openid-connect/ext/par/request. Note require_pushed_authorization_requests is false — PAR is offered, not enforced. - id: rfc8628 name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: >- device_authorization_endpoint published and urn:ietf:params:oauth:grant-type:device_code listed in grant_types_supported. Relevant surface for a company whose clients are head units. - id: ciba name: OpenID Connect Client-Initiated Backchannel Authentication (CIBA) conforms: true evidence: >- backchannel_authentication_endpoint published; backchannel_token_delivery_modes_supported ["poll","ping"]. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: >- registration_endpoint published at /auth/realms/fourscreen/clients-registrations/openid-connect. - id: rfc7517 name: JSON Web Key Set (RFC 7517) conforms: true evidence: >- jwks_uri /protocol/openid-connect/certs returns HTTP 200 with a keys[] array of RSA signing keys (RS256). Verified 2026-09-05. - id: rfc9116 name: security.txt (RFC 9116) conforms: true evidence: >- https://4screen.com/.well-known/security.txt HTTP 200, with Contact, Expires, Preferred-Languages and Canonical fields and an explicit reference to the RFC in a comment. Also served on api.4screen.com and portal.4screen.com. No Policy or Encryption field, so it is a valid but minimal implementation. - id: rfc9700 name: OAuth 2.0 Security Best Current Practice (RFC 9700) conforms: false evidence: >- The realm still advertises the `implicit` and `password` (ROPC) grant types in grant_types_supported, both of which RFC 9700 says MUST NOT be used. PKCE and mTLS support are present, so the failure is the legacy grants being left on rather than a missing control. - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: >- https://4screen.com/privacy-policy/ (HTTP 200) is a GDPR-form privacy notice for 4.screen GmbH, a German controller; https://4screen.com/legal-notice/ (HTTP 200) carries the German Impressum (Amtsgericht München HRB 259171, VAT DE334377104) required by §5 TMG / DDG. Jurisdictional, not a certification. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- The one error envelope observable without credentials is {"httpStatus":401,"domain":"SYSTEM","errorCode":"AUTHENTICATION_FAILED","message":"..."} served as content-type text/plain from api.4screen.com. It is a first-party envelope, not application/problem+json, and it carries none of the RFC 9457 members (type/title/status/detail/instance). - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI is published. /openapi.json, /openapi.yaml, /swagger.json, /v3/api-docs, /v3/api-docs.yaml, /v2/api-docs, /api-docs, /swagger-ui.html, /swagger-ui/index.html, /docs and /redoc on api.4screen.com all return HTTP 401; the same paths on 4screen.com return HTTP 404. Probed 2026-09-05. - id: graphql name: GraphQL conforms: unknown evidence: >- A /graphql surface exists — the portal application bundle at https://portal.4screen.com/assets/index-DOaWU9vK.js contains the literal path `/graphql` against window.FOURSCREEN_API_DOMAIN. A POST introspection query to https://api.4screen.com/graphql returns HTTP 401, so the schema cannot be read anonymously and is NOT recorded here. Conformance is unknown, not false. domain_standard: market: in-car advertising / programmatic digital out-of-home standards_probed: - id: iab-sellers-json name: IAB Tech Lab sellers.json conforms: false evidence: >- https://4screen.com/sellers.json HTTP 404 and https://api.4screen.com/sellers.json HTTP 401. Probed 2026-09-05. - id: iab-ads-txt name: IAB Tech Lab ads.txt / app-ads.txt conforms: false evidence: >- https://4screen.com/ads.txt and https://4screen.com/app-ads.txt both HTTP 404. Probed 2026-09-05. - id: openrtb name: IAB Tech Lab OpenRTB conforms: unknown evidence: >- No OpenRTB bid endpoint is discoverable and no 4.screen public document names OpenRTB. 4.screen sells its four formats (Branded Pins, Sponsored Search, Recommendations, Detail Screen) directly rather than describing a programmatic exchange, so the standard may simply not apply. Recorded as unknown rather than false — reward-only, no penalty implied. note: >- 4.screen operates as a direct-sold in-car placement platform, not an exchange. The absence of sellers.json/ads.txt is consistent with that posture and is recorded as measurement, not as a deficiency. certifications: [] certifications_note: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim was found. trust.4screen.com and security.4screen.com do not resolve; 4screen.com/trust, /security and /compliance are not in the site's sitemap. summary: conforms_true: 12 conforms_false: 4 conforms_unknown: 2 strongest_signal: >- A complete, anonymous, standards-conformant OAuth 2.0 / OIDC discovery surface including mTLS-bound tokens, PAR, CIBA and the device grant. weakest_signal: >- Zero published API contract of any kind, and a non-RFC-9457 error envelope.