generated: '2026-09-05' method: probed source: >- https://help.cbs.com/.well-known/openid-configuration and live probes of https://api.cbssports.com/fantasy, 2026-09-05 standards: - id: openid-connect-discovery conforms: true evidence: >- https://help.cbs.com/.well-known/openid-configuration returns HTTP 200 with a valid OIDC discovery document (issuer, authorization_endpoint, token_endpoint, jwks_uri, userinfo_endpoint, id_token_signing_alg_values_supported) - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns 401 on help.cbs.com and 404 on every other CBS/Paramount host probed - id: oauth2 conforms: true evidence: >- the help.cbs.com discovery document advertises authorization, token, revocation and introspection endpoints and the authorizationCode and implicit response types - id: rfc9728-oauth-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource 401 on help.cbs.com, 404 elsewhere - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on every CBS and Paramount host probed - id: rfc9457-problem-details conforms: false evidence: >- api.cbssports.com returns plain-text bodies for 4xx ("Missing league_id", "Invalid Sport zone", "sport not found") and a bespoke {statusCode,statusMessage,uri,uriAlias,body} JSON envelope for 5xx; no application/problem+json anywhere - id: openapi conforms: false evidence: >- no OpenAPI/Swagger document found at any of /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc on api.cbssports.com, www.cbsnews.com, api.paramount.com or www.cbs.com - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published - id: rss-2.0 conforms: true evidence: >- https://www.cbsnews.com/latest/rss/main returns HTTP 200 with a well-formed document carrying the content, dc, atom, sy, slash and media namespaces; the feed index is published at https://www.cbsnews.com/rss/ - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json 404 on all nine hosts probed domain_standards: - note: >- Reward-only and deliberately empty. Paramount's advertising stack (EyeQ, and the Conduit programmatic integration layer) is the one place a domain standard — OpenRTB, VAST, ads.txt/app-ads.txt — would plausibly be declared, but no Paramount contract or reference is public, so there is no spec location to point evidence at. An invented conformance here would be worth nothing; an honest absence costs the provider nothing under the reward-only rule.