generated: '2026-09-19' method: searched source: >- Live /.well-known probes on dokki.one (2026-09-19), the MCP endpoint 401 challenge, and the public docs (https://dokki.one/pub/api, https://dokki.one/pub/docs/clients, https://dokki.one/privacy). Dokki publishes no compliance / trust page: /security, /accessibility, /legal/* all 307 to the login page, probe-security-programs.py found no VDP or trust center, and no certification (SOC 2, ISO 27001, etc.) is named anywhere public. No Compliance pointer is therefore emitted. standards: - id: rfc8414 name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- https://dokki.one/.well-known/oauth-authorization-server returned 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri, registration_endpoint, scopes_supported, response_types_supported, grant_types_supported, code_challenge_methods_supported and token_endpoint_auth_methods_supported. Saved as well-known/dokki-one-oauth-authorization-server.json. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://dokki.one/.well-known/openid-configuration returned 200 (byte-identical to the RFC 8414 document) with issuer https://dokki.one, jwks_uri, userinfo_endpoint, subject_types_supported [public], id_token_signing_alg_values_supported [RS256, HS256, ES256] and claims_supported. - id: rfc9728 name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://dokki.one/.well-known/oauth-protected-resource returned 200 naming resource https://dokki.one/api/mcp, authorization_servers [https://dokki.one], bearer_methods_supported [header], scopes_supported and resource_documentation; both MCP endpoints answer 401 with WWW-Authenticate Bearer resource_metadata="...oauth-protected-resource?resource=https%3A%2F%2Fdokki.one%2Fapi%2Fmcp". - id: rfc7591 name: RFC 7591 OAuth 2.0 Dynamic Client Registration conforms: true evidence: >- registration_endpoint https://schcrwqbgkcmhdltwgcz.supabase.co/auth/v1/oauth/clients/register is advertised in the discovery documents; an anonymous GET returns 405 (POST-only), consistent with a live registration endpoint. Registration itself was not attempted. - id: oauth2 name: OAuth 2.0 (authorization_code + refresh_token) conforms: true evidence: >- grant_types_supported [authorization_code, refresh_token]; token_endpoint_auth_methods_supported includes none (public clients). - id: pkce name: RFC 7636 PKCE conforms: true evidence: >- code_challenge_methods_supported [S256, plain]. caveat: >- plain is still advertised alongside S256. - id: mcp-streamable-http name: Model Context Protocol — Streamable HTTP transport conforms: true evidence: >- The AI Clients doc states "Transport: stateless Streamable HTTP" for https://dokki.one/mcp/v2; the endpoint answers JSON-RPC 2.0 ({"jsonrpc":"2.0","error":{"code":-32001,...}}) to POST tools/list and initialize. caveat: >- Protocol revision not observable anonymously (401 before initialize completes). - id: mcp-authorization name: MCP Authorization (OAuth 2.1 discovery via RFC 9728 -> RFC 8414) conforms: true evidence: >- The 401 challenge -> protected-resource metadata -> authorization-server metadata -> dynamic registration chain the MCP authorization spec prescribes is fully served; the plugin READMEs state "Dokki's .well-known discovery endpoints drive the browser sign-in." - id: mcp-apps name: MCP Apps (UI resources) conforms: true evidence: >- preview_resource "opens a rendered inline preview ... in MCP hosts that support MCP Apps UI resources" (https://dokki.one/pub/docs/clients). - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document is published; /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json all 307 to the login page and the reference offers only HTML pages. openapi/dokki-one-openapi.yml in this repo is GENERATED from that reference by API Evangelist. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors use a proprietary envelope {"error":{"code","message","request_id"}} with media type application/json (https://dokki.one/pub/api/pagination-errors-and-rate-limits). - id: pagination name: Pagination (offset) conforms: true evidence: '"Most list endpoints accept limit and offset; responses include a page object when the endpoint supports pagination."' - id: idempotency name: Idempotency-Key / replay protection conforms: false evidence: '"use your own idempotency key in the integration layer ... Do not assume a timed-out POST was not applied." No server-side mechanism.' - id: rfc8594 name: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: >- No deprecation policy, Sunset or Deprecation header is documented; the API changelog has one entry. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: >- https://dokki.one/.well-known/security.txt returned 404. - id: rfc9727 name: RFC 9727 api-catalog conforms: false evidence: >- https://dokki.one/.well-known/api-catalog returned 404. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on dokki.one and every subdomain. A "Dokki" agent is listed on the third-party registry openagora.cc with a registry-hosted card, which does not count as the provider serving one. - id: llms-txt name: llms.txt conforms: true evidence: >- https://dokki.one/llms.txt returned 200 text/plain (saved to llms/dokki-one-llms.txt); /llms-full.txt is behind login. - id: scim name: SCIM 2.0 (RFC 7643/7644) conforms: false evidence: >- The org-pricing page says an Enterprise contract "can include SAML SSO, SCIM, and audit capabilities"; no SCIM base URL, schema URN or documentation is published, so no conformance is recorded (reward-only; capability mention is not a contract). domain_standard: null domain_standard_note: >- Collaboration / knowledge-workspace software has no sector interchange standard in the Kin Score regime list; nothing is claimed. compliance_published: false certifications: []