generated: '2026-07-19' method: searched source: https://docs.larridin.com/api/scout-api-v1-reference supporting_sources: - https://docs.larridin.com/api/mcp - https://trust.larridin.com/ - well-known/larridin-oauth-authorization-server.json - well-known/larridin-oauth-protected-resource.json - openapi/larridin-scout-openapi.yml standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization server at https://login.larridin.com with authorization_code, refresh_token, and device_code grants, advertised in RFC 8414 metadata. - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server served at https://app.larridin.com - id: rfc9728-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource served at https://app.larridin.com - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported lists S256 - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint advertised and device_code grant supported - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint advertised; client_id_metadata_document_supported is true - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint advertised - id: oidc-core conforms: partial evidence: >- The openid, profile, and email scopes are supported by the authorization server, but no /.well-known/openid-configuration discovery document is published. - id: model-context-protocol conforms: true evidence: 'official MCP server documented at /mcp/larridin over streamable HTTP with OAuth 2.0' - id: llms-txt conforms: true evidence: https://docs.larridin.com/llms.txt published - id: rfc9457-problem-details conforms: false evidence: errors use a custom success/error envelope, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any Larridin host - id: rfc9727-api-catalog conforms: false evidence: no /.well-known/api-catalog document - id: rfc8594-sunset-header conforms: unknown evidence: no deprecation or sunset policy is published - id: openapi conforms: false evidence: >- Larridin publishes a human-readable API reference but no machine-readable OpenAPI description; the spec in this repo was generated by the API Evangelist pipeline from that reference. - id: asyncapi conforms: false evidence: no event, streaming, or webhook surface is documented - id: pagination conforms: true evidence: 'page/limit request params with data/total/page/limit response envelope' - id: idempotency conforms: false evidence: all documented operations are read-only GET; no idempotency-key contract is published compliance_program: published: true trust_center: https://trust.larridin.com/ platform: SafeBase certifications: - SOC 2 - SOC 2 Type 1 - SOC 2 Type 2 - SOC 3 - HIPAA - GDPR documents_listed: - SOC 2 Type 2 Report - SOC 3 Report - External Penetration Testing Report access: >- Reports are gated behind a Trust Center access request; the certification list itself is public. detail: security/larridin-trust-center.yml