generated: '2026-09-02' method: probed source: >- https://id.woodmark.com/.well-known/openid-configuration (primary); https://www.truecommerce.com/trading-partner-network/american-woodmark/ (third-party EDI attestation, see note) specification: API Commons Conformance specificationVersion: '0.1' provider: American Woodmark providerId: american-woodmark description: >- Standards conformance for American Woodmark. Everything asserted true below is read from the live OpenID Connect discovery document at id.woodmark.com — the only machine-readable contract the company publishes. American Woodmark ships no OpenAPI, AsyncAPI, GraphQL SDL, WSDL or Protobuf, so no contract-derived conformance beyond the identity layer is assertable. conformance: - id: oidc name: OpenID Connect Core 1.0 conforms: true evidence: - >- https://id.woodmark.com/.well-known/openid-configuration returns HTTP 200 application/json with issuer, jwks_uri, authorization_endpoint, token_endpoint and userinfo_endpoint. - 'id_token_signing_alg_values_supported: ["RS256"]' - 'subject_types_supported: ["public"]' - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: - Discovery document served at the RFC-mandated /.well-known/openid-configuration path. - id: oidc-session-management name: OpenID Connect Session Management / RP-Initiated Logout conforms: true evidence: - 'end_session_endpoint: https://id.woodmark.com/connect/endsession' - 'check_session_iframe: https://id.woodmark.com/connect/checksession' - 'frontchannel_logout_supported: true; backchannel_logout_supported: true' - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: - >- authorization_endpoint + token_endpoint advertised; grant_types_supported lists authorization_code, client_credentials, refresh_token, implicit, password. - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: - 'code_challenge_methods_supported: ["plain", "S256"]' note: >- Conformant but weakened — advertising `plain` alongside S256 permits a downgrade that RFC 7636 §7.2 warns against. - id: rfc7517-jwks name: JSON Web Key Set (RFC 7517) conforms: true evidence: - >- https://id.woodmark.com/.well-known/openid-configuration/jwks returns HTTP 200 with an RSA signing key (kty RSA, use sig, RS256). - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: - 'revocation_endpoint: https://id.woodmark.com/connect/revocation' - id: rfc7662-token-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: - 'introspection_endpoint: https://id.woodmark.com/connect/introspect' - id: rfc8628-device-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: - 'device_authorization_endpoint: https://id.woodmark.com/connect/deviceauthorization' - 'grant_types_supported includes urn:ietf:params:oauth:grant-type:device_code' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: false evidence: - No registration_endpoint is present in the discovery document. - id: rfc9728-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: false evidence: - https://id.woodmark.com/.well-known/oauth-protected-resource returns HTTP 404. - id: rfc8414-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: - >- https://id.woodmark.com/.well-known/oauth-authorization-server returns HTTP 404. Only the OIDC discovery path is served. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: - https://www.americanwoodmark.com/.well-known/security.txt returns HTTP 404. - https://id.woodmark.com/.well-known/security.txt returns HTTP 404. - id: openapi name: OpenAPI Specification conforms: false evidence: - >- /openapi.json, /swagger.json, /swagger/v1/swagger.json and /api-docs return 404 on www.americanwoodmark.com, go.woodmark.com, api.woodmark.com and id.woodmark.com. - >- The hosts declared in a prior round of this profile — api.americanwoodmark.com and developer.americanwoodmark.com — do not resolve (NXDOMAIN). - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: - No published contract or error reference exists to assert this against. - id: asyncapi name: AsyncAPI conforms: false evidence: - No event, streaming or webhook surface is published. domain_standards: - id: ansi-asc-x12-edi name: ANSI ASC X12 EDI conforms: true provider_published: false scored: false evidence: - >- https://www.truecommerce.com/trading-partner-network/american-woodmark/ lists American Woodmark as a trading partner supporting transaction sets 850 (Purchase Order), 856 (Ship Notice/Manifest) and 860 (Purchase Order Change Request - Buyer Initiated), and states the codes are part of the ANSI ASC X12 standard with UN/EDIFACT and XML syntax also supported. Fetched 2026-09-02, HTTP 200 via browser user-agent (HTTP 403 to a default user-agent). note: >- This is the real integration surface for American Woodmark's trade — it is how home centers and homebuilders transact with them. It is recorded here as an honest finding, but it is deliberately NOT claimed for domain_standard_conformance: the assertion comes from a third-party VAN's trading-partner directory, not from a contract American Woodmark publishes. American Woodmark itself publishes no EDI implementation guide, no transaction-set list, and no partner onboarding page. domain_standard_conformance reads the contract, and there is no contract. maintainers: - FN: Kin Lane email: kin@apievangelist.com