generated: '2026-09-10' method: probed source: https://portal.firstsolar.com/.well-known/openid-configuration note: 'Derived only from documents actually fetched from First Solar hosts. First Solar publishes no OpenAPI, AsyncAPI, GraphQL SDL or WSDL, so every standard below is asserted from the OIDC discovery document its Developer Portal tenant serves, or recorded as not-conforming/not-applicable. No domain standard applies: the provider''s market (thin-film PV module manufacturing) has no API-level domain standard, and none is invented to fill the slot.' standards: - id: oauth2 conforms: true evidence: https://portal.firstsolar.com/.well-known/openid-configuration advertises authorization_endpoint, token_endpoint, introspection_endpoint and revocation_endpoint; unauthenticated POST to the token endpoint returns an RFC 6749 error object - id: oidc-discovery conforms: true evidence: https://portal.firstsolar.com/.well-known/openid-configuration returns application/json carrying issuer, jwks_uri, authorization_endpoint, token_endpoint, userinfo_endpoint and 36 scopes_supported - id: rfc7517-jwks conforms: true evidence: https://portal.firstsolar.com/developer/id/keys returns HTTP 200 with a keys[] array of RSA signing keys - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256] in the discovery document' - id: rfc9449-dpop conforms: true evidence: 'dpop_signing_alg_values_supported: [RS256, RS384, RS512, ES256, ES384, ES512, EdDSA] in the discovery document' - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://portal.firstsolar.com/developer/services/oauth2/register advertised in the discovery document' - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns the Developer Portal login HTML on every First Solar host, not RFC 8414 metadata - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on firstsolar.com and www.firstsolar.com - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog is a soft-404 on the corporate site and a login shell on the portal - id: openapi conforms: false evidence: no OpenAPI or Swagger document found on any First Solar host; the API hosts named in Certificate Transparency (api., ecatproapi., pmmapi., geo., capacity.) do not resolve publicly - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published - id: rfc9457-problem-details conforms: false evidence: no published error contract