generated: '2026-08-11' method: searched source: live probes of https://admakeai.com/.well-known/* and https://admakeai.com/llms.txt (2026-08-11); https://github.com/mesmerlord/admakeai-mcp; mcp/admakeai-mcp-tools.json note: >- Conformance is asserted only where a document was actually fetched and read. AdMakeAI's standards posture is entirely in the agent/authorization layer — it implements the MCP authorization stack properly — and entirely absent in the API-contract layer, where it publishes no OpenAPI, no AsyncAPI, no JSON Schema bundle and no RFC 9457 errors. No compliance program, certification or trust center was found, so no Compliance pointer is emitted. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted streamable-http server at https://admakeai.com/api/mcp, an MCP server card at /.well-known/mcp.json declaring $schema https://modelcontextprotocol.io/schema/mcp-server-card.json, and an active listing in the official MCP registry as com.admakeai/admakeai (published 2026-08-11). - id: oauth2 name: OAuth 2.0 / 2.1 authorization code conforms: true evidence: /.well-known/oauth-authorization-server advertises authorization_code + refresh_token grants, code flow only. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://admakeai.com/.well-known/oauth-authorization-server returned 200 with a full metadata document. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://admakeai.com/.well-known/oauth-protected-resource and the per-resource path /.well-known/oauth-protected-resource/api/mcp both returned 200 naming the MCP endpoint as the resource. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://admakeai.com/api/oauth/register; client_id_metadata_document_supported true. - id: rfc7636 name: PKCE conforms: true evidence: code_challenge_methods_supported ["S256"]. - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: true evidence: revocation_endpoint https://admakeai.com/api/oauth/revoke. - id: llms-txt name: llms.txt conforms: true evidence: https://admakeai.com/llms.txt returned 200 with a conforming H1 + blockquote + sectioned link-list document. - id: agent-skills name: agentskills.io index v1 conforms: true evidence: /.well-known/agent-skills.json declares $schema https://agentskills.io/schema/v1/index.json with 13 skills. - id: agent-skill-md name: Agent Skill (SKILL.md) conforms: true evidence: Published SKILL.md with name/description/allowed-tools frontmatter at github.com/mesmerlord/admakeai-agent-skills. - id: openapi name: OpenAPI conforms: false evidence: No OpenAPI document found at any probed path on the API host, the docs host or /.well-known/. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, webhook or streaming surface exists — generation completion is poll-only. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both returned application 404. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: Errors are tRPC uppercase code strings; no application/problem+json is documented. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returned 404. - id: rfc9727 name: api-catalog conforms: false evidence: /.well-known/api-catalog returned 404. - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returned 404 (OAuth only, no OIDC). - id: rfc8594 name: Sunset header conforms: false evidence: No deprecation or sunset policy is published. - id: idempotency name: Idempotent request keys conforms: false evidence: No idempotency key or de-duplication semantics documented on credit-spending or Meta-writing operations. - id: hsts name: HTTP Strict Transport Security conforms: false evidence: security/admakeai-domain-security.yml — hsts false on admakeai.com. third_party_platforms: - name: Meta Marketing API role: >- All publishing runs through Meta's official Marketing API rather than browser automation; the provider makes this an explicit selling point and publishes posts about the ban risk of the alternative. source: https://admakeai.com/llms.txt - name: Meta Ad Library role: Competitor ad research corpus. compliance_program: published: false certifications: [] trust_center: null note: No SOC 2, ISO 27001, GDPR/DPA or trust page was found; security/ probes returned no vulnerability-disclosure or trust surface.