generated: '2026-08-17' method: searched source: >- https://mcp.kotzilla.io/.well-known/oauth-authorization-server + https://mcp.kotzilla.io/.well-known/oauth-protected-resource + https://doc.kotzilla.io/ note: >- Assertions below are grounded in documents Kotzilla actually serves or statements Kotzilla actually publishes. Kotzilla has no OpenAPI, so nothing here is derived from a spec. `conforms: false` entries are recorded absences, not defects — most are simply not applicable to an SDK+MCP vendor. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted remote MCP server at https://mcp.kotzilla.io/mcp; an unauthenticated tools/list POST returns a JSON-RPC-shaped 401 invalid_token, and the server publishes MCP-standard OAuth discovery documents. 15 tools documented at https://doc.kotzilla.io/docs/discover/mcpServer - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- authorization_code + refresh_token grants, response_type=code, bearer tokens in the Authorization header, per /.well-known/oauth-authorization-server - id: rfc8414-oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://mcp.kotzilla.io/.well-known/oauth-authorization-server returns 200 application/json - id: rfc9728-oauth-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: https://mcp.kotzilla.io/.well-known/oauth-protected-resource returns 200 application/json, resource_name "Kotzilla MCP Server" - id: rfc7636-pkce name: Proof Key for Code Exchange conforms: true evidence: 'code_challenge_methods_supported: ["S256"]' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: 'registration_endpoint: https://mcp.kotzilla.io/oauth/register' - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation conforms: true evidence: 'revocation_endpoint: https://mcp.kotzilla.io/oauth/revoke' - id: oidc name: OpenID Connect conforms: false evidence: >- `openid` and `email` are offered as scope names, but /.well-known/openid-configuration returns 404 on every Kotzilla host — OIDC discovery is not served, so this is OAuth 2.0 with OIDC-style scope names rather than an OIDC provider. - id: gdpr name: General Data Protection Regulation conforms: true claimed: true evidence: >- Kotzilla SAS is a French (Toulouse) controller; the privacy policy publishes a retention schedule (customers 3y identification / 10y billing, prospects 3y, cookies 12mo, Koin IDE plugin analytics 12mo from last authentication) and states transfers outside the EU/EEA rely on adequacy decisions or European Commission standard contractual clauses. The SDK data page describes the SDK as "GDPR-compliant" and states it "does not capture any business logic or user-sensitive data". source: https://kotzilla.io/privacy-policy caveat: >- This is a self-published compliance statement, not an audited certification. No named subprocessors are disclosed; hosting is described only as "servers located in different place in the world". - id: semver name: Semantic Versioning conforms: true evidence: >- SDK releases follow major.minor.patch with documented drop-in vs breaking semantics ("2.3.0 is a drop-in upgrade from 2.2.x"), per https://doc.kotzilla.io/docs/releaseNotes/versionUpgrades - id: apache-2.0 name: Apache License 2.0 (open source) conforms: true evidence: >- Koin — the DI framework Kotzilla created and maintains — and Kotzilla's public sample/workshop repositories are Apache-2.0. Kotzilla markets an "audited Apache2 license" as a Koin LTS benefit (https://kotzilla.io/koin-lts). NOTE: the commercial Kotzilla Platform SDK is NOT open source; it is licensed under the Kotzilla Platform License 1.0 EULA (https://doc.kotzilla.io/docs/discover/license). - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: >- No HTTP API is published, so no error envelope is documented. The MCP 401 body is a flat {"error","error_description"} OAuth-style object, not application/problem+json. - id: rfc9116-security-txt name: security.txt conforms: false evidence: /.well-known/security.txt returns 404 on kotzilla.io and mcp.kotzilla.io - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI served on any host. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /v3/api-docs, /api-docs and /redoc were probed on kotzilla.io, doc.kotzilla.io, console.kotzilla.io and mcp.kotzilla.io; console/doc return HTML app shells, the rest 404. api.kotzilla.io does not resolve. - id: graphql name: GraphQL conforms: false evidence: POST /graphql on console.kotzilla.io returns nginx 405 Not Allowed; no GraphQL surface published. - id: asyncapi name: AsyncAPI conforms: false evidence: >- Not applicable — Kotzilla publishes no webhooks, no event stream and no pub/sub surface. Telemetry flows one way from the instrumented app into the platform; there is no outbound event surface for customers. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on mcp.kotzilla.io and kotzilla.io; doc/console return HTML shells (soft 200s), which are not cards. - id: soc2 name: SOC 2 conforms: false evidence: No SOC 2 claim found on the website, docs, privacy policy or any trust page; no trust center exists (trust.kotzilla.io does not resolve). - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: No ISO 27001 claim found on any Kotzilla public surface. summary: conforms_count: 9 standards_checked: 19 posture: >- Kotzilla's standards posture is concentrated entirely in the agent layer. The MCP server is a textbook implementation of the current MCP authorization stack — RFC 8414 + RFC 9728 discovery, PKCE S256, dynamic client registration and token revocation, all served anonymously. Outside that, there is no HTTP API contract of any kind, and no third-party security certification.