generated: '2026-08-06' method: derived source: well-known/allwork-openid-configuration.json note: >- Derived entirely from AllWork's live discovery documents. AllWork publishes no OpenAPI, no API reference, and makes no public compliance claims on allworknow.com, so every non-identity standard below is recorded as not conforming for lack of any published evidence — that is an absence of a published artifact, not an assertion about AllWork's internal practice. standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization/token endpoints advertised in the AWN1 realm discovery document. - id: oidc-discovery conforms: true evidence: >- OpenID Connect Discovery 1.0 document served at /realms/AWN1/.well-known/openid-configuration (HTTP 200). - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: discovery document carries issuer, jwks_uri and endpoint metadata. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256. - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint advertised. - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint advertised. - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint and urn:ietf:params:oauth:grant-type:device_code advertised. - id: rfc9126-pushed-authorization-requests conforms: true evidence: pushed_authorization_request_endpoint advertised (not required). - id: rfc8705-mtls-client-auth conforms: true evidence: tls_client_certificate_bound_access_tokens true; tls_client_auth supported; mtls_endpoint_aliases present. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint advertised (Keycloak clients-registrations). - id: ciba conforms: true evidence: backchannel_authentication_endpoint and urn:openid:params:grant-type:ciba advertised. - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported. - id: uma2 conforms: true evidence: /realms/AWN1/.well-known/uma2-configuration returns 200. - id: rfc9116-security-txt conforms: true evidence: /.well-known/security.txt returns 200 with Contact and Expires fields. - id: fapi conforms: false evidence: >- implicit and password grants remain enabled and PAR is not required; no FAPI profile is claimed. - id: openapi conforms: false evidence: no OpenAPI or Swagger document found on any AllWork host. - id: rfc9457-problem-details conforms: false evidence: no public API surface or error contract published. - id: rfc8594-sunset-header conforms: false evidence: no versioning or deprecation policy published. - id: rfc9457-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. compliance_program: published: false note: >- No trust center, no SOC 2 / ISO 27001 / PCI DSS / HIPAA statement, and no compliance page found on allworknow.com. AllWork markets employment-law and worker-classification compliance (a service offering) rather than an information-security certification posture. x-evidence: fetched: '2026-08-06' urls: - url: https://auth.allworknow.com/realms/AWN1/.well-known/openid-configuration status: 200 - url: https://auth.allworknow.com/realms/AWN1/.well-known/uma2-configuration status: 200 - url: https://allworknow.com/.well-known/api-catalog status: 404