generated: '2026-09-16' method: searched source: https://docs.getmontecarlo.com/ conformance: - id: oauth2 conforms: true evidence: https://docs.getmontecarlo.com/docs/api-authentication#authenticating-with-oauth-client-credentials note: OAuth 2.0 client credentials for the GraphQL API; token URL https://api.getmontecarlo.com/oauth2/token. - id: oauth2.1-mcp conforms: true evidence: https://docs.getmontecarlo.com/docs/mcp-server note: OAuth 2.1 with PKCE S256 for the hosted MCP server. - id: rfc7591-dynamic-client-registration conforms: true evidence: well-known/monte-carlo-auth-oauth-authorization-server.json note: registration_endpoint https://auth.getmontecarlo.com/oauth2/register; docs say clients register via DCR. - id: rfc8414-authorization-server-metadata conforms: true evidence: https://auth.getmontecarlo.com/.well-known/oauth-authorization-server - id: rfc9728-protected-resource-metadata conforms: true evidence: https://mcp.getmontecarlo.com/.well-known/oauth-protected-resource/mcp note: 401 challenge carries resource_metadata pointing at the document. - id: oidc conforms: true evidence: https://auth.getmontecarlo.com/.well-known/openid-configuration - id: rfc8628-device-authorization conforms: true evidence: well-known/monte-carlo-auth-oauth-authorization-server.json note: device_authorization_endpoint and urn:ietf:params:oauth:grant-type:device_code advertised. - id: rfc9264-api-catalog conforms: true evidence: https://montecarlo.ai/.well-known/api-catalog note: Linkset with service-doc, service-desc and status relations; also advertised in a Link header. - id: rfc9116-security-txt conforms: true evidence: https://montecarlo.ai/.well-known/security.txt - id: scim2 conforms: true domain_standard: true evidence: https://docs.getmontecarlo.com/docs/auth-provisioning-with-scim note: SCIM v2 endpoint for user and group provisioning from Okta and Microsoft Entra ID (Scale plan and above). Endpoint URL is issued per account; no public SCIM schema document. - id: mcp conforms: true evidence: https://docs.getmontecarlo.com/docs/mcp-server note: Streamable HTTP transport, tools + prompts capabilities. - id: opentelemetry-genai conforms: true domain_standard: true evidence: https://docs.getmontecarlo.com/docs/google-adk-integration note: Agent Observability ingests OpenTelemetry GenAI traces; Monte Carlo maintains an OpenTelemetry Collector fork and Terraform modules. - id: graphql-relay-cursor-pagination conforms: true evidence: https://docs.getmontecarlo.com/docs/push-ingest-api#check-query-logs - id: rfc9457 conforms: false evidence: https://docs.getmontecarlo.com/docs/push-ingest-api#error-codes note: Errors are not application/problem+json. - id: idempotency conforms: false evidence: https://docs.getmontecarlo.com/docs/push-ingest-api note: No idempotency key documented. - id: webhook-signatures-hmac conforms: true evidence: https://docs.getmontecarlo.com/docs/webhooks note: Optional HMAC SHA-512 signature in x-mcd-signature. compliance: - {program: SOC 2, evidence: 'https://trust.montecarlo.ai/'} - {program: ISO 27001, evidence: 'https://trust.montecarlo.ai/'}