generated: '2026-09-02' method: searched source: well-known/ironfang-oauth-authorization-server.json, well-known/ironfang-oauth-protected-resource.json, openapi/ironfang-openapi.yaml, https://ironfang.uk/docs/mcp note: 'Renderwolf''s conformance story is concentrated in one place: the agent-authorization stack. The identity host implements the modern OAuth discovery and delegation RFCs properly, and the MCP server implements a current protocol revision. Outside that, the REST API is a plain bearer-key JSON API with a vendor error envelope and no adopted API-design standard.' entries: - id: openapi-3.1 name: OpenAPI 3.1.0 conforms: true evidence: - 'openapi/ironfang-openapi.yaml - openapi: 3.1.0, 25 paths, 33 operations, 17 schemas' - https://api.ironfang.uk/openapi.yaml (HTTP 200, application/yaml) note: Every operation carries a unique operationId, a summary, tags and enumerated 2xx/4xx responses; securitySchemes are defined and applied globally. Ironfang states the spec is authoritative and the reference page is generated from it, not the reverse. - id: oauth2 name: OAuth 2.1 authorization code with PKCE conforms: true scope: MCP surface only evidence: - 'well-known/ironfang-oauth-authorization-server.json - code_challenge_methods_supported: [S256], response_types_supported: [code]' - https://ironfang.uk/docs/mcp - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: - https://id.ironfang.uk/.well-known/oauth-authorization-server (HTTP 200) - issuer, jwks_uri, authorization_endpoint, token_endpoint, registration_endpoint - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: - https://mcp.ironfang.uk/.well-known/oauth-protected-resource (HTTP 200) - resource, authorization_servers, bearer_methods_supported, scopes_supported - Observed 401 WWW-Authenticate on POST https://mcp.ironfang.uk/mcp carrying resource_metadata="https://mcp.ironfang.uk/.well-known/oauth-protected-resource/mcp" - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: - registration_endpoint https://id.ironfang.uk/oauth/register in the authorization server metadata - 'MCP reference: "public Dynamic Client Registration with PKCE"' - id: rfc8693 name: OAuth 2.0 Token Exchange conforms: true evidence: - grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange - 'MCP reference: the server exchanges the MCP token for a separate two-minute token addressed to the product, marked as acting on the person''s behalf.' - id: rfc8707 name: Resource Indicators for OAuth 2.0 conforms: true evidence: - MCP reference instructs clients to send resource=https://mcp.ironfang.uk/mcp on /oauth/authorize; tokens are audience-bound and products reject an MCP token. - id: rfc9207 name: OAuth 2.0 Authorization Server Issuer Identification conforms: true evidence: - 'authorization_response_iss_parameter_supported: true' - id: oidc name: OpenID Connect Discovery conforms: true evidence: - https://id.ironfang.uk/.well-known/openid-configuration (HTTP 200) - ES256 id tokens, scopes openid/profile/email/offline_access - id: cimd name: Client ID Metadata Documents conforms: true evidence: - 'client_id_metadata_document_supported: true in the authorization server metadata' - MCP reference names CIMD as the preferred client identification method note: Draft, not an RFC. Recorded because it is the mechanism by which Claude Code and claude.ai connect without registration, and it is genuinely uncommon in this catalog. - id: mcp name: Model Context Protocol conforms: true version: '2026-07-28' accepted_revisions: - '2026-07-28' - '2025-11-25' - '2025-06-18' - '2025-03-26' evidence: - Registered in the official MCP Registry as uk.ironfang/ironfang, status active, published 2026-08-31 - https://ironfang.uk/docs/mcp note: Streamable HTTP transport, stateless (POST /mcp only). Implements the io.modelcontextprotocol/tasks extension and resource templates. No prompts, sampling, roots or apps. - id: rfc9457 name: RFC 9457 Problem Details (application/problem+json) conforms: false evidence: - No operation in openapi/ironfang-openapi.yaml declares application/problem+json - 'Error envelope is {"error": {"code", "message"}} - see errors/ironfang-problem-types.yml' - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: - https://api.ironfang.uk/.well-known/security.txt -> 404 - https://ironfang.uk/.well-known/security.txt -> 404 - https://id.ironfang.uk/.well-known/security.txt -> 404 - https://mcp.ironfang.uk/.well-known/security.txt -> 404 - id: rfc8594 name: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: - No Sunset or Deprecation header is documented; the one deprecated field (usage.renders) is announced in prose with no date - id: rfc6585-ratelimit name: Rate-limit response headers (RateLimit-* / Retry-After on 429) conforms: false evidence: - The docs publish two rate limits and their 429 error codes but no response header. See rate-limits/ironfang-rate-limits.yml. note: Ironfang does honour a bounded Retry-After on the OUTBOUND webhook delivery path - it reads the header, it does not emit one. - id: asyncapi name: AsyncAPI conforms: false evidence: - 'A four-event signed webhook surface is documented in prose; no AsyncAPI document is served and the OpenAPI 3.1 webhooks: block is empty' - id: json-api name: JSON:API conforms: false evidence: - Plain JSON resources; no JSON:API document structure - id: odata name: OData conforms: false evidence: - No $metadata surface - id: scim name: SCIM conforms: false evidence: - No urn:ietf:params:scim:schemas:* URN in the contract; no user-provisioning surface domain_standards: market: web rendering / screenshot and document generation APIs standard_declared: false note: REWARD-ONLY, and correctly empty. There is no interoperability standard for browser rendering APIs - the competitor set Ironfang itself names (ScreenshotOne, Urlbox) each publishes a bespoke parameter vocabulary, which is exactly why Ironfang ships parameter-mapping tables for switching rather than a conformance claim. Renderwolf does handle standard MEDIA formats (PNG, JPEG, WebP, PDF, H.264/MP4) and standard QR error correction levels, but consuming a format is not conforming to a domain API standard. probed_for: - 'ISO 32000 / PDF-A declaration in the PDF surface: not declared' - 'W3C Web Content Accessibility conformance claim on rendered output: not declared' compliance_certifications: published: false note: 'No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim is published, and no trust centre exists. See security/ironfang-trust-center.yml. The only regulatory identifiers Ironfang publishes are UK corporate ones: Companies House registration 12764014 (England & Wales) and ICO data protection registration ZB444797, both in the site footer.' standards: - id: openapi-3.2 conforms: true evidence: the document declares 3.2.0 - id: oauth2 conforms: false evidence: 'securitySchemes: apiKey (http)' - id: rfc9457 conforms: false evidence: no response declares application/problem+json - id: idempotency conforms: false evidence: no idempotency key parameter on mutating operations - id: pagination conforms: true evidence: list operations take cursor, limit, offset