generated: '2026-08-12' method: probed source: live probes of coolerx.com on 2026-08-12 name: CoolerX standards conformance description: >- Cross-cutting standards assertions for the only machine-readable surface CoolerX serves: the OAuth-protected MCP endpoint on coolerx.com. Every entry below is graded against a document or response header we actually fetched. CoolerX publishes no compliance or certification claims of any kind, so no Compliance pointer is emitted. standards: - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- https://coolerx.com/.well-known/oauth-authorization-server returned 200 application/json with issuer, authorization_endpoint, token_endpoint, response_types_supported and grant_types_supported present. Saved verbatim to well-known/cooler-screens-oauth-authorization-server.json. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://coolerx.com/.well-known/oauth-protected-resource returned 200 with resource, authorization_servers, bearer_methods_supported and scopes_supported. The 401 from the MCP endpoint carries the matching WWW-Authenticate challenge with resource_metadata pointing back at that document. - id: rfc6749 name: OAuth 2.0 Authorization Framework conforms: true evidence: >- authorization_code and refresh_token grants advertised; response_types_supported ["code"]; bearer token in the Authorization header (RFC 6750). - id: rfc7636 name: PKCE conforms: true evidence: >- code_challenge_methods_supported ["S256"] with token_endpoint_auth_methods_supported ["none"] — public clients with S256 proof key, the OAuth 2.1 baseline. - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: true evidence: revocation_endpoint https://coolerx.com/oauth/revoke advertised in AS metadata. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: false evidence: >- No registration_endpoint in the AS metadata. The server instead sets client_id_metadata_document_supported: true, using the Client ID Metadata Document pattern in place of DCR. - id: mcp-authorization name: MCP Authorization (2025-06-18) conforms: true evidence: >- Anonymous POST to https://coolerx.com/wp-json/mcp/mcp-oauth-server returned 401 with WWW-Authenticate: Bearer realm="https://coolerx.com", resource_metadata="https://coolerx.com/.well-known/oauth-protected-resource" — the exact discovery chain the MCP authorization specification requires. - id: oidc name: OpenID Connect Discovery conforms: false evidence: https://coolerx.com/.well-known/openid-configuration returned 404. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Error bodies use the WordPress REST envelope {"code","message","data":{"status"}} served as application/json, not application/problem+json. See errors/cooler-screens-problem-types.yml. - id: rfc8615 name: Well-Known URIs conforms: true evidence: Two documents served from /.well-known/; see well-known/cooler-screens-well-known.yml. - id: rfc6797 name: HTTP Strict Transport Security conforms: true evidence: >- strict-transport-security: max-age=31536000; includeSubDomains; preload on origin responses. Undercut in practice by the expired certificate on coolerx.com. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both returned 404 on coolerx.com and www.coolerx.com. The legacy host coolerscreens.com returns 200 for both paths, but that is a soft-200 catch-all — a control probe of /totally-made-up-path-xyz123 also returned 200 with the same HTML body — so it is recorded as a miss, not a hit. No agent card exists. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document found. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc on coolerx.com — all 404. api.coolerx.com and portal.coolerx.com refuse TCP connections. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface published on any CoolerX host. compliance_claims: published: false note: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim, and no security page anywhere on coolerx.com (/security/ and /trust/ both 404 on 2026-08-12). Notable for a company that operates in-store camera and sensor hardware across national retail chains — the only public assurance document is the consumer privacy policy.