generated: '2026-09-13' method: searched source: >- https://docs.getmembrane.com/docs/managing-membrane/security-and-privacy, https://trust.getmembrane.com/, well-known/integration-app-oauth-authorization-server.json, well-known/integration-app-oauth-protected-resource-mcp-integrate-anything.json, a2a/integration-app-agent-card.json, derived from openapi/integration-app-membrane-api-openapi.json conformance: - id: oauth2 conforms: true evidence: >- https://api.getmembrane.com/.well-known/oauth-authorization-server returns RFC 6749/8414 authorization server metadata with authorization_code + refresh_token grants. This is the end-user-facing half of Membrane's auth; the platform API itself is bearer JWT. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://api.getmembrane.com/.well-known/oauth-authorization-server (HTTP 200, 2026-09-13) - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://api.getmembrane.com/.well-known/oauth-protected-resource/mcp/integrate-anything (HTTP 200, 2026-09-13) names its own authorization server and token_type "tenant". This is what makes the hosted MCP server discoverable and connectable by an unconfigured agent. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: >- registration_endpoint https://api.getmembrane.com/oauth/register declared in the authorization server metadata, with client_id_metadata_document_supported true. - id: rfc7636 name: PKCE conforms: true evidence: code_challenge_methods_supported ["S256"] in the authorization server metadata. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404 on api.getmembrane.com and docs.getmembrane.com. The OAuth server is an authorization server, not an OpenID Provider. - id: openapi conforms: true version: 3.0.0 evidence: >- https://docs.getmembrane.com/api-reference/membrane-api.json and https://api.getmembrane.com/docs-json both serve the same OpenAPI 3.0.0 document, 205 paths / 278 operations, generated by the platform itself rather than hand-written. - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted server at https://api.getmembrane.com/mcp/integrate-anything (401 to anonymous tools/list, which is a live MCP server refusing an unauthenticated call), plus an open-source server at github.com/membranehq/mcp-server implementing Streamable HTTP and deprecated SSE. - id: a2a name: Agent2Agent Protocol conforms: true version: '0.3' evidence: >- https://docs.getmembrane.com/.well-known/agent-card.json (HTTP 200, 2026-09-13). Graded conformant against A2A 1.0.0 hard checks but declares protocolVersion 0.3 - see a2a/integration-app-a2a.yml. - id: agent-skills name: Agent Skills conforms: true evidence: >- Two provider-authored SKILL.md files at github.com/membranehq/agent-skills plus a third served from the docs host at /.well-known/agent-skills/membrane/skill.md, installed with `npx skills add membranehq/agent-skills`. - id: llmstxt name: llms.txt conforms: true evidence: >- https://docs.getmembrane.com/llms.txt (HTTP 200, 47,304 bytes, 163 documentation pages plus an "OpenAPI Specs" section). Note the section lists two specs and one of them (/api-reference/openapi.json) is the Mintlify "OpenAPI Plant Store" sample, not Membrane's. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors are a custom {type, key, message, data, causedByError} JSON envelope served as application/json, documented at https://docs.getmembrane.com/reference/overview/errors. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent anywhere in the 278-operation spec or the REST docs. See conventions/integration-app-conventions.yml. - id: pagination conforms: true style: cursor evidence: >- limit (1-1000) + cursor query parameters on 39/42 operations respectively, with {items[], cursor} response envelopes. Derived from openapi/integration-app-membrane-api-openapi.json. - id: rfc8594 name: Sunset / Deprecation headers conforms: false evidence: >- Versioning is an API-Version request header; no Sunset or Deprecation response header is documented. - id: soc2 name: SOC 2 Type 2 conforms: true evidence: >- "Membrane is SOC 2 Type 2 certified" - https://docs.getmembrane.com/docs/managing-membrane/security-and-privacy. Reports available via https://trust.getmembrane.com/. - id: gdpr conforms: true evidence: >- "Our servers and data are fully located in the European Union and we are GDPR-compliant", plus a stated 14-day maximum retention of user data on S3 after which it is erased by lifecycle rule - https://docs.getmembrane.com/docs/managing-membrane/security-and-privacy - id: pentest name: Third-party penetration testing conforms: true evidence: Penetration test results offered through https://trust.getmembrane.com/ domain_standard: applicable: false note: >- REWARD-ONLY and deliberately left empty. Embedded iPaaS / unified-integration infrastructure has no domain message standard of its own - there is no SCIM/OData/HL7/ISO-20022 equivalent for "connect my product to 100,000 apps". Membrane's domain-relevant standards are the agent protocols it already conforms to above (MCP, A2A, Agent Skills), which are recorded as general conformance rather than claimed as a domain standard. Nothing is invented to fill this slot. not_applicable: - fhir - fapi - scim - odata - psd2 - json:api