generated: '2026-09-07' method: probed source: >- https://fmsso.fanniemae.com/.well-known/openid-configuration and https://fmsso.fanniemae.com/.well-known/oauth-authorization-server (both HTTP 200, fetched 2026-09-07, saved verbatim under well-known/) note: >- Every `conforms: true` entry below is asserted from a machine-readable document Fannie Mae serves on its own host, not from a marketing claim. Because Fannie Mae publishes no public API contract, no REST-convention or domain-standard conformance could be verified from a spec; those entries are recorded as unverified with the reason, rather than guessed. conformance: - id: oauth2 title: OAuth 2.0 (RFC 6749) conforms: true evidence: https://fmsso.fanniemae.com/.well-known/oauth-authorization-server detail: Full authorization server metadata with authorization, token, revocation and introspection endpoints. - id: oidc title: OpenID Connect Core 1.0 conforms: true evidence: https://fmsso.fanniemae.com/.well-known/openid-configuration detail: issuer, userinfo_endpoint, jwks_uri, id_token_signing_alg_values_supported and openid scope all present. - id: oidc-discovery title: OpenID Connect Discovery 1.0 conforms: true evidence: https://fmsso.fanniemae.com/.well-known/openid-configuration - id: rfc8414 title: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: https://fmsso.fanniemae.com/.well-known/oauth-authorization-server - id: rfc7636 title: PKCE (RFC 7636) conforms: true evidence: https://fmsso.fanniemae.com/.well-known/openid-configuration detail: 'code_challenge_methods_supported: [plain, S256]' - id: rfc9126 title: Pushed Authorization Requests (RFC 9126) conforms: true evidence: https://fmsso.fanniemae.com/as/par.oauth2 detail: pushed_authorization_request_endpoint advertised; require_pushed_authorization_requests is false. - id: rfc8628 title: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: https://fmsso.fanniemae.com/as/device_authz.oauth2 - id: rfc8693 title: OAuth 2.0 Token Exchange (RFC 8693) conforms: true evidence: 'grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange' - id: rfc8705 title: OAuth 2.0 Mutual-TLS Client Authentication (RFC 8705) conforms: true evidence: 'token_endpoint_auth_methods_supported includes tls_client_auth' - id: rfc7009 title: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: https://fmsso.fanniemae.com/as/revoke_token.oauth2 - id: rfc7662 title: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: https://fmsso.fanniemae.com/as/introspect.oauth2 - id: rfc7591 title: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: 'registration_endpoint https://fmsso.fanniemae.com/as/clients.oauth2 advertised in the discovery document' detail: >- Advertised, not exercised. An anonymous GET on the endpoint returns 404; registration would require an initial access token. We did not attempt a write. - id: ciba title: OpenID Connect Client-Initiated Backchannel Authentication (CIBA) conforms: true evidence: https://fmsso.fanniemae.com/as/bc-auth.ciba - id: dpop title: OAuth 2.0 Demonstrating Proof of Possession (RFC 9449) conforms: true evidence: 'dpop_signing_alg_values_supported present in the discovery document' - id: rfc9116 title: security.txt (RFC 9116) conforms: false evidence: >- /.well-known/security.txt returns 404 on www.fanniemae.com, fanniemae.com and fmsso.fanniemae.com (probed 2026-09-07). Fannie Mae does run a vulnerability disclosure program, but does not advertise it at the well-known path. - id: openapi title: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document was found on any Fannie Mae host. The Developer Portal API catalog and its specs sit behind portal registration; see x-coverage in apis.yml. - id: rfc9457 title: Problem Details for HTTP APIs (RFC 9457) conforms: unverified evidence: >- No public contract or error reference to read. The Developer Portal's own internal API returns a proprietary JSON envelope (correlationId/status/message/timestamp/errors), observed on https://developer.fanniemae.com/fv7ui-public/web/fv7/api/noauth (HTTP 404) — that is the portal's own UI backend, not a published Fannie Mae API, so it is recorded as observation only. domain_standards: - id: mismo title: MISMO (Mortgage Industry Standards Maintenance Organization) conforms: unverified evidence: >- MISMO is the domain standard for this market and Fannie Mae's delivery datasets (ULDD, UCDP, UAD) are MISMO-derived, but that could not be confirmed from a contract: no Fannie Mae API contract, XSD or message schema is published at a public URL. REWARD-ONLY check — recorded as unverified, never as a failure. probe: >- No MISMO namespace, schema or message type was observable because no machine-readable contract is public.