generated: '2026-07-19' method: searched source: >- https://linktr.ee/.well-known/oauth-authorization-server, https://linktr.ee/.well-known/api-catalog, https://mcp.linktr.ee/.well-known/oauth-protected-resource, https://mcp.linktr.ee/docs surface: mcp-only standards: - id: model-context-protocol conforms: true version: '2025-03-26' evidence: streamable-http MCP server at https://mcp.linktr.ee/mcp with a published tool manifest - id: oauth2 conforms: true evidence: RFC 8414 authorization server metadata published at /.well-known/oauth-authorization-server - id: rfc8414-authorization-server-metadata conforms: true evidence: https://linktr.ee/.well-known/oauth-authorization-server returns application/json metadata - id: rfc9728-protected-resource-metadata conforms: true evidence: >- https://mcp.linktr.ee/.well-known/oauth-protected-resource returns resource metadata; the 401 challenge carries WWW-Authenticate Bearer resource_metadata=... - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint published in the authorization server metadata - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported published with 10 algorithms - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint published and urn:ietf:params:oauth:grant-type:device_code in grant_types_supported - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported - id: ciba conforms: true evidence: backchannel_authentication_endpoint published and urn:openid:params:grant-type:ciba in grant_types_supported - id: rfc9727-api-catalog conforms: true evidence: https://linktr.ee/.well-known/api-catalog returns application/linkset+json - id: llms-txt conforms: true evidence: llms.txt published on both https://linktr.ee/llms.txt and https://mcp.linktr.ee/llms.txt - id: oidc conforms: partial evidence: >- userinfo_endpoint, id_token_signing_alg_values_supported and claims_supported are published, but /.well-known/openid-configuration returns 404 on every host. - id: shadcn-registry conforms: true version: '1.0' added: '2026-08-13' evidence: >- https://arbor.linktr.ee/manifest.json and /r/{name}.json validate against the published shadcn registry schemas ($schema https://ui.shadcn.com/schema/registry.json and .../registry-item.json); the manifest declares protocol_version 1.0. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger definition is published on any host. There is no public REST API for the product. The Arbor registry (arbor.linktr.ee) IS a public unauthenticated HTTP API with four endpoints, but ships no OpenAPI: /openapi.json, /swagger.json and /api-docs all 404. rechecked: '2026-08-13' hosts_probed: [linktr.ee, mcp.linktr.ee, api.linktr.ee, arbor.linktr.ee] - id: rfc9457-problem-details conforms: false evidence: errors are MCP tool-result envelopes, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on linktr.ee, mcp.linktr.ee and arbor.linktr.ee. (https://linktr.ee/security.txt returns HTTP 200 but serves the marketing SPA shell, not an RFC 9116 document — a soft-200, recorded as a miss.) - id: a2a-agent-card conforms: false added: '2026-08-13' evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on every Linktree host. See well-known/linktree-well-known.yml. - id: asyncapi conforms: false evidence: no event, streaming, or webhook surface is published compliance_certifications: published: false note: >- No SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP certification is named on the Trust Center. See security/linktree-trust-center.yml.