generated: '2026-09-13' method: probed source: https://myingredion.com/.well-known/openid-configuration note: >- Ingredion publishes no API contract, so there is no spec to read conformance out of. The only standards assertions that can be made with evidence come from the OpenID Connect discovery document served on the MyIngredion customer portal. Everything not evidenced is recorded as conforms: false with the reason — an honest absence, not a penalty. conformance: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: https://myingredion.com/.well-known/openid-configuration detail: >- 200 application/json, issuer https://myingredion.com, with authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri and id_token_signing_alg_values_supported (RS256) all present — the required discovery metadata set. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: https://myingredion.com/.well-known/openid-configuration detail: grant_types_supported = [authorization_code, refresh_token]; revocation and introspection endpoints both declared. - id: pkce name: PKCE (RFC 7636) conforms: true evidence: https://myingredion.com/.well-known/openid-configuration detail: code_challenge_methods_supported = [S256]. - id: dpop name: OAuth 2.0 DPoP (RFC 9449) conforms: true evidence: https://myingredion.com/.well-known/openid-configuration detail: dpop_signing_alg_values_supported declares RS256/384/512, ES256/384/512 and EdDSA. - id: dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: https://myingredion.com/.well-known/openid-configuration detail: registration_endpoint https://myingredion.com/services/oauth2/register is declared. - id: oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: https://myingredion.com/.well-known/oauth-authorization-server detail: Returns HTTP 200 but the body is the 152KB portal HTML shell, not metadata. Only the OIDC path serves a real document. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: https://www.ingredion.com/.well-known/security.txt detail: 404 on the corporate domain; soft-404 HTML shell on the portal domain. - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: https://www.ingredion.com/openapi.json detail: No published contract exists (404), so no error format can be asserted either way. - id: openapi name: OpenAPI conforms: false evidence: https://www.ingredion.com/openapi.json detail: 404 on every corporate and portal host probed; no OpenAPI, Swagger, GraphQL, AsyncAPI, WSDL or gRPC contract is published. domain_standards: note: >- REWARD-ONLY and correctly empty. Ingredion is a food-ingredient manufacturer; the machine exchange standards of that market (GS1 GDSN / GTIN product data, EDI X12 850/855/856 purchase orders and ASNs, SPINS or TraceGains supplier document exchange) are all plausible for a company of this size, but NONE is declared in any contract or document Ingredion publishes anonymously, and a standard asserted without a contract to point at would be fabrication. Nothing here is scored against the company. candidates_checked: - id: gs1-gdsn declared: false detail: No GS1/GTIN product-data endpoint or declaration found on any Ingredion host. - id: edi-x12 declared: false detail: >- No public EDI onboarding, trading-partner or 850/855/856 documentation is published. The MyIngredion portal describes human order entry and order tracking only.