generated: '2026-07-20' method: searched source: https://docs.lucenthq.com/mcp/oauth + /.well-known/ metadata standards: - id: oauth2.1 conforms: true evidence: OAuth 2.1 authorization server with authorization_code + refresh_token grants, documented at /mcp/oauth. - id: rfc8414-as-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer/endpoints/PKCE metadata. - id: rfc9728-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource returns 200 describing the MCP resource. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint advertised; docs describe Dynamic Client Registration. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = [S256]. - id: mcp conforms: true evidence: Hosted Model Context Protocol server at https://app.lucenthq.com/api/mcp (streamable HTTP transport). - id: rfc9457-problem-details conforms: false evidence: 'Error envelope is a simple { "error": string }, not application/problem+json.' - id: bearer-token-rfc6750 conforms: true evidence: Data API uses Authorization Bearer tokens. compliance_program: published: false note: No SOC 2 / ISO 27001 / HIPAA / PCI certifications published at probe time.