generated: '2026-09-17' method: searched source: >- https://developer.clickup.com/docs/authentication, https://security.clickup.com/, well-known/clickup-mcp-oauth-authorization-server.json, well-known/clickup-mcp-oauth-protected-resource.json, well-known/clickup-api-catalog.json, well-known/clickup-security.txt, openapi/clickup-api-v2-reference-openapi.json standards: - id: oauth2 conforms: true evidence: >- Authorization Code grant documented at https://developer.clickup.com/docs/authentication (authorize https://app.clickup.com/api, token https://api.clickup.com/api/v2/oauth/token); GetAccessToken is a published operation in the v2 spec. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://mcp.clickup.com/.well-known/oauth-authorization-server returned 200 (saved verbatim) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://mcp.clickup.com/.well-known/oauth-protected-resource returned 200 (saved verbatim) - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://mcp.clickup.com/oauth/register advertised in the authorization-server metadata - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] in the MCP authorization-server metadata - id: rfc8707-resource-indicators conforms: true evidence: resource_indicators_supported true in both MCP discovery documents - id: mcp-authorization conforms: true version: '2026-07-28' evidence: mcp_authorization_spec_version "2026-07-28" in https://mcp.clickup.com/.well-known/oauth-authorization-server - id: rfc9727-api-catalog conforms: true evidence: >- https://developer.clickup.com/.well-known/api-catalog returned a 200 linkset with service-desc entries of type application/vnd.oai.openapi+json for both published OpenAPI documents - id: rfc9116-security-txt conforms: true evidence: https://clickup.com/.well-known/security.txt returned 200 with Contact, Policy, Expires and Canonical fields - id: openapi-3.1 conforms: true evidence: openapi/clickup-api-v2-reference-openapi.json declares openapi 3.1.0 - id: openapi-3.0 conforms: true evidence: openapi/clickup-public-api-v3-openapi.json declares openapi 3.0.0 - id: openidconnect conforms: false evidence: no /.well-known/openid-configuration on any ClickUp host (404/403 on all six probed) - id: rfc9457-problem-details conforms: false evidence: >- Errors are returned as a ClickUp-specific JSON envelope ({"err": "...", "ECODE": "..."} in the public API, {"err","status","message"} on mcp.clickup.com); no application/problem+json media type appears in either spec. - id: rfc8594-sunset-header conforms: false evidence: no deprecation or sunset policy published in the developer documentation index (llms.txt) - id: scim conforms: false evidence: >- No SCIM schema URN or /scim/v2 surface in either spec. SAML/SCIM provisioning is sold on the Enterprise plan but is not exposed as a public contract. - id: rfc6750-bearer-token conforms: true evidence: >- MCP resource metadata advertises bearer_methods_supported ["header"]; the OAuth path of the public API sends "Authorization: Bearer {access_token}". - id: webhook-hmac-signature conforms: true evidence: >- HMAC-SHA256 X-Signature over the payload with a per-webhook shared secret, https://developer.clickup.com/docs/webhooksignature domain_standard: applicable: false note: >- Work management / project management has no cross-vendor wire standard for an API to declare (there is no SCIM, FHIR, OpenRTB or ISO 20022 equivalent for tasks and Lists). REWARD-ONLY dimension, so nothing is invented to fill it. The nearest adjacent standards ClickUp DOES speak are the OAuth and MCP authorization documents recorded above. compliance_program: url: https://security.clickup.com/ certifications: [SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, GDPR] source: security/clickup-trust-center.yml