generated: '2026-07-19' method: searched source: https://auth.jit.io/.well-known/openid-configuration standards: - id: oauth2 conforms: true evidence: >- RFC 8414 authorization-server metadata published at auth.jit.io/.well-known/oauth-authorization-server; client_credentials, authorization_code, device_code, token-exchange, and refresh_token grants. - id: oidc conforms: true evidence: OpenID Connect discovery document at auth.jit.io/.well-known/openid-configuration (issuer, jwks_uri, userinfo). - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported includes S256. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200. - id: oauth2-device-authorization-grant conforms: true evidence: device_authorization_endpoint present; urn:ietf:params:oauth:grant-type:device_code advertised. - id: oauth2-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange advertised in grant_types_supported. - id: soc2-type2 conforms: true evidence: >- SOC 2 Type 2 badge on jit.io; SOC 2 report available via the Trust Portal (trust.jit.io) on request. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on jit.io, www.jit.io, docs.jit.io, or auth.jit.io. - id: rfc9457-problem-details conforms: false evidence: No published OpenAPI; error envelope not confirmed as application/problem+json.