generated: '2026-09-05' method: probed source: >- https://www.8b.africa/.well-known/oauth-authorization-server , https://www.8b.africa/.well-known/oauth-protected-resource , a live 401 challenge from https://www.8b.africa/wp-json/mcp/mcp-oauth-server , https://www.8b.africa/llms.txt and https://my.8b.africa/robots.txt note: >- Every entry below is asserted from a document that was actually fetched, or from a header actually returned. Nothing is inferred from marketing prose, because 8B publishes no developer or compliance prose to infer from. conformance: - id: oauth2 name: OAuth 2.0 / 2.1 authorization code with PKCE conforms: true evidence: https://www.8b.africa/.well-known/oauth-authorization-server detail: >- response_types_supported [code], grant_types_supported [authorization_code, refresh_token], code_challenge_methods_supported [S256], token_endpoint_auth_methods_supported [none]. Public-client authorization code with mandatory PKCE is the OAuth 2.1 baseline shape. - id: rfc8414 name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://www.8b.africa/.well-known/oauth-authorization-server detail: >- Served anonymously at the registered well-known path with issuer, authorization_endpoint, token_endpoint and revocation_endpoint present. - id: rfc9728 name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: https://www.8b.africa/.well-known/oauth-protected-resource detail: >- Served anonymously, names the protected resource and its authorization_servers, and the 401 from the resource carries a WWW-Authenticate Bearer challenge with a resource_metadata parameter pointing back at this document — the full discovery loop. - id: rfc7636 name: RFC 7636 PKCE conforms: true evidence: https://www.8b.africa/.well-known/oauth-authorization-server detail: code_challenge_methods_supported is [S256]; plain is not offered. - id: rfc6750 name: RFC 6750 Bearer Token Usage conforms: true evidence: https://www.8b.africa/.well-known/oauth-protected-resource detail: bearer_methods_supported is [header]; the 401 returns a conformant WWW-Authenticate. - id: rfc7009 name: RFC 7009 OAuth 2.0 Token Revocation conforms: true evidence: https://www.8b.africa/.well-known/oauth-authorization-server detail: A revocation_endpoint is advertised at https://www.8b.africa/oauth/revoke. - id: mcp name: Model Context Protocol conforms: true evidence: https://www.8b.africa/wp-json/mcp/mcp-oauth-server detail: >- A JSON-RPC 2.0 endpoint accepting POST with Accept application/json, text/event-stream, authorized per the MCP authorization spec via RFC 9728 discovery. The tool surface itself is auth-gated and was not enumerated, so this asserts transport and authorization conformance only, not tool-schema quality. - id: llmstxt name: llms.txt conforms: true evidence: https://www.8b.africa/llms.txt detail: >- A well-formed llms.txt is served at the site root — H1 title, blockquote summary and linked sections. Generated by Yoast SEO v28.4 rather than hand-authored. - id: content-signals name: Cloudflare Content Signals Policy (AI preference in robots.txt) conforms: true evidence: https://my.8b.africa/robots.txt detail: >- "Content-Signal: search=yes,ai-train=no,use=reference" for User-agent *, plus explicit Disallow / for seven AI crawlers. Published on the community host only; the marketing host serves a zero-byte robots.txt with no signal at all. - id: openid-connect name: OpenID Connect Discovery conforms: false evidence: https://www.8b.africa/.well-known/openid-configuration detail: 404 on every host probed. OAuth is offered for API authorization, not identity. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: https://www.8b.africa/wp-json/mcp/mcp-oauth-server detail: >- Errors use the WordPress REST envelope ({"code","message","data":{"status"}}) with content-type application/json, not application/problem+json. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: https://www.8b.africa/.well-known/security.txt detail: 404 on every host probed. - id: rfc8594 name: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: https://www.8b.africa/wp-json/mcp/mcp-oauth-server detail: No Sunset or Deprecation headers observed; no versioning or deprecation policy published. domain_standards: note: >- REWARD-ONLY and honestly empty. 8B sits at the intersection of two markets that do have domain standards — consumer/education lending, and higher-education administration — and its contract declares neither, because it publishes no domain contract at all. The standards below were the shortlist worth probing for a company of this shape; none of them appears anywhere in the served surface. No penalty is implied by their absence. checked: - id: lti name: IMS Global / 1EdTech Learning Tools Interoperability declared: false - id: oneroster name: 1EdTech OneRoster declared: false - id: ed-fi name: Ed-Fi Data Standard declared: false - id: caliper name: 1EdTech Caliper Analytics declared: false - id: fdx name: Financial Data Exchange API declared: false - id: iso20022 name: ISO 20022 financial messaging declared: false - id: oai-pmh name: OAI-PMH declared: false compliance_certifications: published: false note: >- No trust center, no SOC 2 / ISO 27001 / PCI / GDPR certification page and no compliance statement were found on any host. probe-security-programs.py returned vdp=none trust=none. No Compliance or TrustCenter pointer is emitted, because there is nothing to point at.