generated: '2026-08-26' method: probed source: >- Live probe of https://id.mercedes-benz.com/.well-known/openid-configuration and /.well-known/oauth-authorization-server (both 200, saved verbatim in well-known/), plus static analysis of the eleven refined OpenAPI documents in openapi/ and the four provider-published Swagger 2.0 originals in openapi/_original/. description: >- What the Mercedes-Benz contracts and identity provider actually DECLARE, checked one standard at a time. Every `conforms: true` below is backed by a document we fetched or a spec construct we can point at. Standards this market has but Mercedes-Benz does not declare are recorded as false, not omitted — an absence is a measurement. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: - 'https://id.mercedes-benz.com/.well-known/oauth-authorization-server -> 200' - 'authorization_endpoint https://id.mercedes-benz.com/as/authorization.oauth2' - 'token_endpoint https://id.mercedes-benz.com/as/token.oauth2' - 'grant_types_supported includes authorization_code, refresh_token, client_credentials' - id: oauth2-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: - '/.well-known/oauth-authorization-server served at the issuer, HTTP 200, application/json' - id: oidc name: OpenID Connect Core / Discovery 1.0 conforms: true evidence: - '/.well-known/openid-configuration served at the issuer, HTTP 200' - 'issuer https://id.mercedes-benz.com, jwks_uri https://id.mercedes-benz.com/pf/JWKS' - 'userinfo_endpoint, end_session_endpoint, claims_supported and subject_types_supported all present' - 'scopes_supported includes openid, profile, email, phone, address, offline_access' - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: - 'code_challenge_methods_supported: [plain, S256]' note: S256 is offered; `plain` is still advertised alongside it. - id: rfc9126-par name: Pushed Authorization Requests (RFC 9126) conforms: true evidence: - 'pushed_authorization_request_endpoint present in the discovery document' - 'require_pushed_authorization_requests present' - id: rfc8628-device-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: - 'device_authorization_endpoint present' - 'grant_types_supported includes urn:ietf:params:oauth:grant-type:device_code' - id: rfc8693-token-exchange name: OAuth 2.0 Token Exchange (RFC 8693) conforms: true evidence: - 'grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange' - id: rfc8705-mtls name: OAuth 2.0 Mutual-TLS Client Authentication (RFC 8705) conforms: true evidence: - 'token_endpoint_auth_methods_supported includes tls_client_auth' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: - 'registration_endpoint https://id.mercedes-benz.com/as/clients.oauth2' - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: - 'revocation_endpoint https://id.mercedes-benz.com/as/revoke_token.oauth2' - id: rfc7662-token-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: - 'introspection_endpoint https://id.mercedes-benz.com/as/introspect.oauth2' - id: ciba name: OpenID Connect Client-Initiated Backchannel Authentication conforms: true evidence: - 'backchannel_authentication_endpoint present' - 'grant_types_supported includes urn:openid:params:grant-type:ciba' - id: fapi name: FAPI 1.0 / 2.0 conforms: false evidence: - >- No FAPI profile is declared, and the authorization server still advertises the implicit and resource-owner-password grants and the `none` token-endpoint auth method, all of which FAPI forbids. The building blocks (PAR, mTLS, private_key_jwt, PKCE S256) are present, but the profile is not asserted and the forbidden grants are not withdrawn. - id: openapi name: OpenAPI Specification conforms: partial evidence: - >- Four Swagger 2.0 documents are published (openapi/_original/). No OpenAPI 3.x document is published by Mercedes-Benz. All four validate as Swagger 2.0 but carry NO securityDefinitions, so the contract does not describe how to authenticate. - >- No OpenAPI at all is published for the connected-vehicle family (Vehicle Status, Vehicle Lock Status, Fuel Status, Electric Vehicle Status, Pay As You Drive) or the Fleet API. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457 / RFC 7807) conforms: false evidence: - >- Errors use a bespoke {"errorMessage","statusCode","message"} envelope. No application/problem+json media type appears anywhere. See errors/mercedes-me-problem-types.yml. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: - 'developer.mercedes-benz.com/.well-known/security.txt -> 200 but the body is the SPA shell, not a document' - 'api.mercedes-benz.com/.well-known/security.txt -> 401' - 'connectivity.mercedes-benz.com/.well-known/security.txt -> 404' - id: rfc9727-api-catalog name: '/.well-known/api-catalog (RFC 9727)' conforms: false evidence: - 'No host in the estate serves it. See well-known/mercedes-me-well-known.yml.' - id: rfc8594-sunset name: Sunset HTTP Header (RFC 8594) conforms: false evidence: - 'No Sunset or Deprecation header is declared on any operation in any published spec.' - id: rfc6585-rate-limit name: RateLimit header fields conforms: false evidence: - >- 429 is returned but with no Retry-After and no RateLimit-* headers. The retry interval is carried in English prose in the response body: "Rate limit is exceeded. Try again in 58 seconds." - id: hal name: HAL (Hypertext Application Language) conforms: partial evidence: - >- The contract defines HalifiedDealers, HalifiedCountries, SelfLink, DefaultLinks, HRef and Link schemas and embeds navigational links in responses, but every document declares produces: [application/json] rather than application/hal+json — so the representation is HAL-shaped without advertising the HAL media type. - id: pagination name: Collection pagination conforms: false evidence: - 'No limit/offset/page/cursor parameter exists on any of the 39 operations.' - id: idempotency name: Idempotent write semantics conforms: false evidence: - 'No Idempotency-Key header or equivalent on any of the five write operations.' - id: json-schema name: JSON Schema conforms: partial evidence: - >- Swagger 2.0 `definitions` (101 schemas across the four documents) are JSON Schema draft-4 subset. Mercedes-Benz publishes no standalone JSON Schema documents; the two in json-schema/ are ours. domain_standards: market: Automotive / connected vehicle declared: false finding: >- NOT DECLARED, and this is a reward-only check so nothing is deducted. We looked specifically for a contract-level signature of an automotive interoperability standard — a W3C VISS/VSS vehicle-signal namespace, a COVESA/Genivi signal path, an ISO 20078 (ExVe / extended vehicle) resource shape, an OpenADR or OCPI charging surface, or an ISO 15118 / OCPP identifier — and found none of them in any published Mercedes-Benz contract. Mercedes-Benz signal names are bespoke (fuelstatus, evstatus, payasyoudrive), and their FIN/VIN keying is an industry identifier, not an interoperability profile. adjacent_observation: >- Mercedes-Benz DOES publish a W3C Vehicle Information Service implementation at github.com/mercedes-benz/vehicle-information-service (Rust, last pushed 2020-11-17), but that is an open-source project, not a signature in any of the contracts it sells. It does not satisfy this check and is recorded here so the distinction is on the record rather than lost. regulatory_signal: name: EU Data Act — in-vehicle data access declared: true where: identity provider scope namespace evidence: - >- Nine production OAuth scopes on https://id.mercedes-benz.com carry an explicit `euda` segment: mb:vehicle:mbdata:euda:vehicleoperation, :maintenancediagnostic, :navigationpositioning, :bodyfeature, :bodymountingwork, :climatecomfort, :energyconsumption, :infotainmentuserinteraction, and mb:wallbox:mbdata:euda:wallbox. note: >- This is a live, machine-readable declaration that Mercedes-Benz has modelled EU Data Act in-vehicle data categories as first-class authorization scopes. It is a regulatory conformance signal, not an interoperability-standard signature, so it is recorded here rather than claimed as domain_standard_conformance. compliance: published_certifications: [] trust_center: null note: >- probe-security-programs.py found no trust centre and no named certification (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) reachable from the API estate. Mercedes-Benz Group publishes corporate compliance material at group.mercedes-benz.com, but that host answers 403 to our probe under an Akamai bot policy, so nothing there was read and nothing is claimed from it.