generated: '2026-09-12' method: probed source: well-known/gracenote-well-known.yml + openapi/_sources.yml provider: Gracenote providerId: gracenote description: >- Cross-cutting standards Gracenote's published contracts and discovery documents actually conform to. Every `conforms: true` below points at a document that was fetched, not at a marketing claim. conformance: - id: openapi-3.1 name: OpenAPI Specification 3.1.1 conforms: true evidence: >- All ten first-party definitions declare openapi 3.1.1 — on-api, gvd, gmd v2, gmd v3, gn-ids, nexus, global-sports lookup, global-sports update, onconnect lookup, online video and social. - id: swagger-2.0-origin name: OpenAPI 2.0 (converted) conforms: partial evidence: >- openapi/gracenote-gn-ids-api-openapi.json carries x-original-swagger-version 2.0 — it is a converted Swagger 2.0 document, now served as 3.1.1. - id: oauth2 name: OAuth 2.0 conforms: true evidence: https://video.mcp.gracenote.com/.well-known/oauth-authorization-server (HTTP 200) - id: rfc8414 name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- Served on three hosts — video.mcp.gracenote.com, sports.mcp.gracenote.com and gracenote.com — each returning issuer, authorization_endpoint, token_endpoint, revocation_endpoint, response_types_supported, grant_types_supported and code_challenge_methods_supported. - id: rfc9728 name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://video.mcp.gracenote.com/.well-known/oauth-protected-resource/mcp and the sports equivalent both return resource, authorization_servers, scopes_supported and bearer_methods_supported (HTTP 200), and the 401 challenge on /mcp names the document in its WWW-Authenticate resource_metadata parameter. - id: rfc7591 name: RFC 7591 OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://video.mcp.gracenote.com/register declared in the authorization-server metadata. - id: rfc7636 name: RFC 7636 PKCE conforms: true evidence: code_challenge_methods_supported ["S256"] on all three authorization-server documents. - id: mcp name: Model Context Protocol conforms: true evidence: >- Two production servers speaking JSON-RPC 2.0 over streamable HTTP — https://video.mcp.gracenote.com/mcp and https://sports.mcp.gracenote.com/mcp. Both answered a tools/list probe with a protocol-correct 401 OAuth challenge on 2026-09-12. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json anywhere in the ten specs. Gracenote uses a flat {status, error, description} JSON envelope instead. - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on gracenote.com and on auth.mcp.gracenote.com. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: 404 on gracenote.com and www.gracenote.com; 403 on developer.tmsapi.com and devportal.gracenote.com. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation response header declared in any published spec. - id: rfc9421 name: HTTP Message Signatures conforms: false evidence: Not referenced in any published contract or discovery document. - id: idempotency-key name: Idempotency-Key header conforms: false evidence: >- No Idempotency-Key parameter in any of the ten specs. The only write surface (GN IDS API) exposes no replay-protection header. - id: pagination name: Documented pagination conforms: true evidence: >- offset/limit query parameters across the OnConnect, On API, GVD and Global Sports Data lookup surfaces; GVD and On API both state "Gracenote recommends a maximum limit of 1000 across all endpoints". - id: json-api name: JSON:API conforms: false evidence: Responses are vendor-shaped JSON; no JSON:API media type or document structure. - id: odata name: OData conforms: false evidence: No $metadata surface and no OData query conventions in any spec. domain_standards: - id: tms-id name: TMS ID / Gracenote IDs (de facto video content identifier) conforms: true evidence: >- tmsId is a first-class path and query identifier across the OnConnect Lookup APIs (GET /v1.1/programs/{tmsId}) and the On API, and the GN IDS API exists specifically to submit and publish programs against Gracenote-licensed datasets using these IDs. Gracenote's own portal calls them "the industry's most widely adopted video IDs". This is a proprietary identifier scheme that functions as a market standard, not an open specification — recorded as such. note: >- Reward-only check. The video-metadata market has no open, body-published content-identifier standard equivalent to SCIM or FHIR; Gracenote's IDs are the closest thing, and they are Gracenote's own. - id: iso-639-1 name: ISO 639-1 / IETF BCP 47 language tags conforms: true evidence: >- The Video MCP Server's gnv_resolve_entities and gnv_get_root tools take language as "ISO 639-1 or IETF tag (e.g. en, en-US)"; the video specs use the same convention. - id: iso-3166 name: ISO 3166 country codes conforms: true evidence: >- gnv_resolve_entities and gnv_get_availability take countryCode as ISO 3166-1 alpha-3 ("USA", "GBR"); gnv_web_search takes ISO 3166-1 alpha-2. The OnConnect Online Video and Social API enumerates AU, BR, CA, DE, ES, FR, IT, MX, SE, UK, US. compliance_certifications: published: false note: >- No trust center and no named certifications (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) are published on gracenote.com or the developer portal. Probed https://gracenote.com/trust/ (404), https://gracenote.com/security/ (404) and https://trust.gracenote.com/ (DNS does not resolve) on 2026-09-12. No Compliance pointer is emitted, because nothing was found to point at.