# Vendor facets — FusionAuth. Self-hostable (or FusionAuth-cloud) CIAM that serves a ROOT discovery # document with issuer and authorization_code (fetched live from login.fusionauth.io), so on the provider's # own login host it reads as served auth and served delegated identity. It does NOT support Dynamic Client # Registration (its own MCP guide says so), and the MCP server serves its own protected-resource metadata. vendor: fusionauth name: FusionAuth website: https://fusionauth.io areas: - identity registry_keys: [] rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Run on a host the provider owns, FusionAuth's root discovery document reads as served auth (0.9) and served delegated identity. That is the whole agent-readiness lift: there is no dynamic client registration, so MCP clients must be pre-registered, and protected-resource metadata comes from the provider's MCP server, not from FusionAuth. DPoP is an Enterprise feature and is not one of the mechanisms the FAPI check names. Not detectable from the registry today, so capability-only. features: - id: root-discovery-document name: Root OIDC discovery description: >- /.well-known/openid-configuration at the host root with issuer, authorization_code, client_credentials, device_code (and implicit/password); no registration_endpoint. source: https://login.fusionauth.io/.well-known/openid-configuration tier: all - id: oauth-endpoints name: OAuth 2.0 / OIDC endpoints description: >- Authorization, token and device endpoints; authorization codes can be DPoP-bound, with DPoP an Enterprise feature. source: https://fusionauth.io/docs/lifecycle/authenticate-users/oauth/endpoints tier: all - id: mcp-access-control name: Protecting an MCP server with FusionAuth description: >- Guide for FusionAuth as the MCP authorization server with pre-registered clients; states FusionAuth does not support DCR; the MCP server advertises its own protected-resource metadata. source: https://fusionauth.io/docs/extend/examples/controlling-access-mcp-server tier: all maps: - feature: root-discovery-document check: auth_clarity layer: agent_readiness grade: served provider_must: >- Serve FusionAuth on a host of its own (self-hosted, or a custom domain on FusionAuth Cloud) and get that host onto its record. The multi-tenant variant of discovery is tenant-scoped; the root document reflects the default tenant. points: 10 baseline_pass_rate: 0.474 - feature: root-discovery-document check: delegated_identity layer: agent_readiness grade: served provider_must: Same host on record; authorization_code is in grant_types_supported. points: 6 baseline_pass_rate: 0.209 - feature: oauth-endpoints check: oauth_scopes_enumerated layer: composite conditional: true condition: Only if the provider's own OpenAPI declares oauth2 and enumerates its scopes. catalog_pass_rate: 0.866 facet: contract_quality points: 4 baseline_pass_rate: 0.902 saturated: true saturated_note: >- 90% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. earns_nothing: - feature: mcp-access-control check: dynamic_client_registration why: >- FusionAuth does not implement RFC 7591, so no registration_endpoint can appear; MCP clients are pre-registered by script or admin UI. - feature: oauth-endpoints check: reg_fapi_profile why: >- DPoP-bound codes are not among what that check names (FAPI conformance, PAR, private_key_jwt, mTLS-bound tokens). - feature: root-discovery-document check: well_known_published why: openid-configuration is not one of the documents that check reads. out_of_reach: checks: - dynamic_client_registration - protected_resource_metadata - security_schemes_defined - oauth_flows_current - consent_identity note: >- No RFC 7591 support; RFC 9728 is served by the provider's MCP server (the guide uses the MCP framework's provider, not a FusionAuth library). unscored_practice: - feature: root-discovery-document why: >- The served document advertises implicit and password grants; oauth_flows_current reads only OpenAPI securitySchemes. surface: contract_quality: reachable: 4.0 total: 211 agent_readiness: reachable: 15.0 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://fusionauth.io/docs/extend/examples/controlling-access-mcp-server - https://fusionauth.io/docs/lifecycle/authenticate-users/oauth/endpoints - https://login.fusionauth.io/.well-known/openid-configuration measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 7710 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 0.0 p75: 0.0 p90: 0.0 max: 0.0 mean_among_movers: 0.0 agent_readiness_lift: median: 8.3 p75: 8.3 p90: 9.6 max: 12.6 mean_among_movers: 8.2 facet_lift_median_among_movers: {} composite_band_moves: {} agent_readiness_band_moves: agent-aware -> agent-ready: 3302 agent-ready -> agent-native: 269 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written