generated: '2026-08-12' method: derived source: >- openapi/_original/effect-photonics-wp-rest-openapi.yml, well-known/effect-photonics-well-known.yml, live response headers observed 2026-08-12, and the provider's published FAQ collection at https://effectphotonics.com/wp-json/wp/v2/faq summary: >- Cross-cutting web standards this surface does and does not conform to, each with the evidence it was decided on. The provider makes no API conformance claims — it publishes no developer documentation — so every `conforms: true` below is derived from an observed artifact or response, and every `false` is a probed negative. standards: - id: oauth2 conforms: true evidence: >- OpenAPI securityScheme type oauth2 on the mcp namespace, backed by the live RFC 8414 metadata at /.well-known/oauth-authorization-server (HTTP 200): authorization_code + refresh_token grants. - id: oauth2.1-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"]; token_endpoint_auth_methods_supported = ["none"] (public clients), consistent with the OAuth 2.1 profile MCP requires. - id: rfc8414-authorization-server-metadata conforms: true evidence: 'https://effectphotonics.com/.well-known/oauth-authorization-server returned HTTP 200 with issuer, authorization_endpoint, token_endpoint, revocation_endpoint and scopes_supported.' - id: rfc9728-protected-resource-metadata conforms: true evidence: >- https://effectphotonics.com/.well-known/oauth-protected-resource returned HTTP 200 naming the MCP resource and its authorization server, and the 401 from the MCP endpoint carries a matching WWW-Authenticate Bearer challenge with resource_metadata. - id: mcp conforms: partial evidence: >- Two live MCP JSON-RPC endpoints served by the WordPress MCP adapter, with correct OAuth discovery. Graded partial rather than true because tools/list is 401 anonymously, so no protocol version, capability set or tool schema could be observed. - id: rfc8288-web-linking conforms: true evidence: 'Link header with rel="https://api.w.org/" on every response; rel="next"/"prev" pagination links on collections, exposed via Access-Control-Allow-Origin expose list.' - id: rfc7232-conditional-requests conforms: true evidence: ETag returned on discovery and collection reads (observed "10185-1786543658;;;"). - id: oidc conforms: false evidence: /.well-known/openid-configuration returned HTTP 404. The OAuth server issues access tokens only; there is no ID token, userinfo endpoint or jwks_uri. - id: rfc9457-problem-details conforms: false evidence: Errors use the WordPress envelope {code,message,data.status} with content-type application/json, not application/problem+json. See errors/effect-photonics-problem-types.yml. - id: idempotency conforms: false evidence: No idempotency-key header or parameter on any of the 439 derived operations. - id: pagination conforms: true evidence: page/per_page/offset parameters with X-WP-Total and X-WP-TotalPages response headers. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned HTTP 404. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returned HTTP 404. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both returned HTTP 404. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists on this host; nothing to describe. - id: hsts conforms: false evidence: No Strict-Transport-Security header on https://effectphotonics.com (see security/effect-photonics-domain-security.yml). - id: dnssec conforms: false evidence: No DNSSEC on effectphotonics.com. - id: openapi conforms: not-published evidence: >- The provider publishes no OpenAPI. The specs in openapi/ are API Evangelist derivations of the live WordPress route-discovery document, marked x-apievangelist-method: derived, and must not be read as a provider-published contract. product_compliance: note: >- Recorded separately because it is hardware compliance, not API conformance. It is what the company itself publishes, in the FAQ collection at https://effectphotonics.com/wp-json/wp/v2/faq (HTTP 200, 29 entries, category "Compliance & Certifications"), and it is why a Compliance pointer is emitted in apis.yml. claims: - {id: 'iso-9001', statement: 'ISO 9001 quality management certification, announced in the company newsroom.', source: 'https://effectphotonics.com/newsroom/iso-9001-certification-reaffirms-effect-photonics-commitment-to-quality-across-operations/'} - {id: 'rohs', statement: 'RoHS declarations available for all current production parts.', source: 'https://effectphotonics.com/faq/'} - {id: 'reach', statement: 'REACH declarations available for all current production parts.', source: 'https://effectphotonics.com/faq/'} - {id: 'iec-60825-1', statement: 'Laser safety classification to IEC 60825-1 for Class 1 laser products.', source: 'https://effectphotonics.com/faq/'} - {id: 'conflict-minerals', statement: 'Conflict minerals reporting included in the standard compliance pack.', source: 'https://effectphotonics.com/faq/'} - {id: 'eu-us-nl-export-control', statement: 'Products classified under dual-use export control regimes; shipments subject to EU, US and Dutch export controls.', source: 'https://effectphotonics.com/faq/'} - {id: 'oif-itla-msa-01.3', statement: 'Products declare the OIF Integrable Tunable Laser Assembly MSA 01.3 hardware management interface.', source: 'https://effectphotonics.com/wp-json/wp/v2/management_interface'} not_claimed: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published, and no trust centre exists (trust.effectphotonics.com does not resolve to a served host). No TrustCenter pointer is emitted. x-evidence: fetched: '2026-08-12' probes: - {url: 'https://effectphotonics.com/.well-known/oauth-authorization-server', http_status: 200} - {url: 'https://effectphotonics.com/.well-known/oauth-protected-resource', http_status: 200} - {url: 'https://effectphotonics.com/.well-known/openid-configuration', http_status: 404} - {url: 'https://effectphotonics.com/.well-known/security.txt', http_status: 404} - {url: 'https://effectphotonics.com/.well-known/api-catalog', http_status: 404} - {url: 'https://effectphotonics.com/wp-json/wp/v2/faq?per_page=30', http_status: 200} - {url: 'https://effectphotonics.com/newsroom/iso-9001-certification-reaffirms-effect-photonics-commitment-to-quality-across-operations/', http_status: 200}