generated: '2026-07-19' method: searched source: https://use.kick.co/.well-known/oauth-authorization-server standards: - id: oauth2 conforms: true evidence: MCP surface secured with OAuth 2.1 (authorization code + refresh) per RFC 8414 authorization-server metadata. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://use.kick.co/.well-known/oauth-authorization-server returns application/json metadata. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://use.kick.co/.well-known/oauth-protected-resource advertises the MCP resource and authorization server. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"]. - id: rfc7591-oauth-dynamic-client-registration conforms: true evidence: registration_endpoint present (https://use.kick.co/mcp/oauth/register). - id: model-context-protocol conforms: true evidence: Hosted MCP server at https://use.kick.co/mcp with a published tool roster. - id: oidc conforms: false evidence: No /.well-known/openid-configuration published (SPA soft-404). - id: rfc9457-problem-details conforms: false evidence: Error envelope is {message, statusCode, traceId}, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on kick.co, docs.kick.co, or use.kick.co. notes: >- Derived/searched from the OAuth well-known metadata and MCP docs. No published compliance-certification program (SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP) was found; the security docs state TLS in transit and AES-256 at rest and that bank connections run through Plaid, but name no third-party certification, so no Compliance pointer is emitted.