generated: '2026-08-11' method: probed source: https://auth.darrow.ai/.well-known/openid-configuration note: >- Darrow publishes no OpenAPI, AsyncAPI, GraphQL SDL or API reference, so every assertion below is grounded in what was actually fetched: the Auth0 tenant's discovery document and the /.well-known/ probe sweep recorded in well-known/darrow-well-known.yml. A `conforms: false` here means "no public evidence of it", not "the provider fails it" — the contract needed to check most of these is not published. standards: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://auth.darrow.ai/.well-known/openid-configuration returned 200 with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri and id_token_signing_alg_values_supported. - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- Authorization, token, revocation and device-authorization endpoints are advertised; grant_types_supported includes authorization_code, client_credentials, refresh_token and the device-code grant. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returned 200 (application/json). - id: rfc7636 name: PKCE conforms: true evidence: code_challenge_methods_supported = [S256, plain]. - id: rfc9449 name: OAuth 2.0 Demonstrating Proof of Possession (DPoP) conforms: true evidence: dpop_signing_alg_values_supported = [ES256]. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint = https://auth.darrow.ai/oidc/register. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: false evidence: /.well-known/oauth-protected-resource returned 404 on every probed host. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returned 404 (auth) / 404 (www) / 307 (portal, platform). - id: openapi name: OpenAPI conforms: false evidence: >- No spec at any probed location on www.darrow.ai, portal.darrow.ai or platform.darrow.ai; platform.darrow.ai/api/openapi.json returns 401 Unauthorized. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface is documented publicly. - id: mcp name: Model Context Protocol conforms: false evidence: No /mcp endpoint or hosted MCP server found; /mcp 307s into the login flow. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json returned 404 or 307 on every host. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Not verifiable — the only public error body observed is {"error":"Unauthorized"} from platform.darrow.ai/api/* (application/json, not application/problem+json). - id: fapi name: FAPI conforms: false evidence: >- The tenant still advertises the implicit and resource-owner-password grants and HS256 ID-token signing, which FAPI profiles disallow. compliance_programs: published: false note: >- www.darrow.ai/compliance describes Darrow's compliance-scanning PRODUCT (23+ privacy regulations, 275+ US state and federal regulations), not Darrow's own certifications. No SOC 2, ISO 27001, HIPAA, PCI or FedRAMP claim, and no trust center, was found on any probed host — so no Compliance pointer is emitted. x-evidence: fetched: '2026-08-11' urls: - url: https://auth.darrow.ai/.well-known/openid-configuration status: 200 - url: https://auth.darrow.ai/.well-known/oauth-authorization-server status: 200 - url: https://auth.darrow.ai/.well-known/oauth-protected-resource status: 404 - url: https://platform.darrow.ai/api/openapi.json status: 401 - url: https://www.darrow.ai/.well-known/agent-card.json status: 404