generated: '2026-08-04' method: probed source: https://login.mainstreet.com/.well-known/openid-configuration note: >- MainStreet publishes no OpenAPI, AsyncAPI, GraphQL or MCP contract, so every spec-derived standard below is recorded as not conforming on the basis of absence rather than failure. The identity host's OIDC/OAuth discovery pair is the only standards-bearing surface, and everything asserted for it is read directly out of that document. standards: - id: openid-connect-discovery-1.0 conforms: true evidence: https://login.mainstreet.com/.well-known/openid-configuration returns 200 application/json with issuer, authorization_endpoint, token_endpoint, jwks_uri, userinfo_endpoint - id: oauth2 conforms: true evidence: authorization_code, client_credentials, refresh_token, implicit and password grants advertised in grant_types_supported - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://login.mainstreet.com/.well-known/oauth-authorization-server returns 200 application/json - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 and plain - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint present; urn:ietf:params:oauth:grant-type:device_code in grant_types_supported - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported - id: rfc7523-jwt-bearer conforms: true evidence: urn:ietf:params:oauth:grant-type:jwt-bearer in grant_types_supported - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported = [ES256] - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint = https://login.mainstreet.com/oidc/register - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint = https://login.mainstreet.com/oauth/revoke - id: rfc7517-jwks conforms: true evidence: jwks_uri = https://login.mainstreet.com/.well-known/jwks.json - id: openid-connect-back-channel-logout-1.0 conforms: true evidence: backchannel_logout_supported = true, backchannel_logout_session_supported = true - id: openid-connect-ciba conforms: true evidence: backchannel_authentication_endpoint present, backchannel_token_delivery_modes_supported = [poll] - id: llmstxt conforms: true evidence: https://mainstreet.ai/llms.txt returns 200 text/plain in llms.txt format - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on mainstreet.ai and login.mainstreet.com - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every resolvable host - id: openapi conforms: false evidence: no OpenAPI or Swagger document found at any probed path on any resolvable host - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published - id: mcp conforms: false evidence: no hosted Model Context Protocol server published or referenced - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on resolvable hosts; SPA hosts return HTML shells - id: rfc9457-problem-details conforms: false evidence: no public API contract to evaluate - id: ccpa-cpra conforms: true evidence: https://mainstreet.ai/privacy.html documents CCPA/CPRA consumer rights; https://mainstreet.ai/privacy-choices.html serves the opt-out surface certifications_published: [] certifications_note: >- No trust center, compliance page, or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) is published on any MainStreet host. trust.mainstreet.com and security.mainstreet.com do not resolve. No Compliance pointer is emitted. x-evidence: fetched: '2026-08-04' hosts_probed: - mainstreet.ai - login.mainstreet.com - mainstreet.com - dashboard.mainstreet.com - books.mainstreet.com