generated: '2026-08-12' method: probed source: >- live probes of https://projects.motionapp.com/mcp and its /.well-known documents, plus https://help.motionapp.com/en/articles/14315735-motion-mcp name: Motion — standards conformance note: >- Assertions below are graded against what Motion actually serves. Motion publishes no OpenAPI, so nothing here is derived from a spec; every `conforms: true` row is backed by a document we fetched or a response we observed. Compliance CERTIFICATIONS (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) are a separate question and Motion publishes none — see the compliance block at the end. No Compliance pointer is emitted in apis.yml. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Motion operates a hosted remote MCP server at https://projects.motionapp.com/mcp, documents it as such, distributes it through the Anthropic connector directory, and it answers a JSON-RPC 2.0 tools/list request with a well-formed JSON-RPC error object plus an RFC 9728 auth challenge. evidence_url: https://help.motionapp.com/en/articles/14315735-motion-mcp protocol_version_declared: false protocol_version_note: >- No MCP protocol version is published on the landing page, in the help article, or negotiable without authenticating. - id: jsonrpc2 name: JSON-RPC 2.0 conforms: true evidence: >- Observed 2026-08-12 — POST tools/list returned {"jsonrpc":"2.0","error":{"code":-32001,"message":"Missing or invalid Authorization header"},"id":null}, a conformant JSON-RPC 2.0 error object using the implementation-defined -32000..-32099 range. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Authorization-code, client-credentials and refresh-token grants advertised; authorize/token/ revoke/introspect endpoints all published and reachable. evidence_url: https://projects.motionapp.com/.well-known/oauth-authorization-server - id: oauth2-pkce name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: ["S256"] — S256 only, plain is not offered.' evidence_url: https://projects.motionapp.com/.well-known/oauth-authorization-server - id: oauth2-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- HTTP 200 JSON at /.well-known/oauth-authorization-server with issuer, authorization_endpoint, token_endpoint, jwks_uri, registration_endpoint, introspection_endpoint, revocation_endpoint. evidence_url: https://projects.motionapp.com/.well-known/oauth-authorization-server - id: oauth2-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: true evidence: >- HTTP 200 JSON naming the MCP endpoint as the resource and the issuer as its authorization server, and the endpoint's 401 WWW-Authenticate header carries the matching resource_metadata parameter. Served at all three discovery shapes we probed. evidence_url: https://projects.motionapp.com/mcp/.well-known/oauth-protected-resource - id: oauth2-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: >- registration_endpoint advertised at /api/auth/oauth2/register, with token_endpoint_auth_methods_supported including "none" — the public-client path an MCP client needs to self-register. evidence_url: https://projects.motionapp.com/.well-known/oauth-authorization-server - id: oidc name: OpenID Connect Core / Discovery conforms: true partial: true evidence: >- openid/profile/email scopes, an id_token signed with EdDSA, a userinfo_endpoint, an end_session_endpoint and a full claims_supported list are advertised, and OIDC discovery is served at /api/auth/.well-known/openid-configuration. deviation: >- Discovery is NOT served at the host-root /.well-known/openid-configuration (404). A relying party that assumes the host root rather than the issuer prefix will fail discovery. evidence_url: https://projects.motionapp.com/api/auth/.well-known/openid-configuration - id: llmstxt name: llms.txt conforms: true evidence: >- https://motionapp.com/llms.txt returns HTTP 200 text/plain — a hand-maintained 8.7KB file with Last-Updated, Last-Verified-By-Human, a named corrections contact, canonical-page list, disambiguation section and preferred citation. evidence_url: https://motionapp.com/llms.txt - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors are JSON-RPC 2.0 objects served as application/json. No application/problem+json anywhere on Motion's surface. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document found. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc against motionapp.com, app.motionapp.com, projects.motionapp.com, sapi.motionapp.com and the docs host — every hit was either a 404 or an HTML SPA/Cloudflare-Access shell, never a parseable spec. - id: asyncapi name: AsyncAPI conforms: false evidence: >- Not applicable — Motion publishes no event, streaming or webhook API. Its Slack integration is an outbound report scheduler, not a subscribable event surface. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on motionapp.com (404), projects.motionapp.com (404) and app.motionapp.com (200 Cloudflare Access HTML — not a card). - id: security-txt name: RFC 9116 security.txt conforms: false evidence: >- 404 on motionapp.com and projects.motionapp.com. The only security.txt reachable on a Motion hostname is Intercom's, served on the Intercom-hosted help centre with Canonical https://app.intercom.com/.well-known/security.txt — a vendor's document, not Motion's. - id: hsts name: HTTP Strict Transport Security conforms: true evidence: >- strict-transport-security max-age=15552000 observed on both motionapp.com and the MCP endpoint; the MCP host adds includeSubDomains. - id: dnssec name: DNSSEC conforms: false evidence: See security/motion-domain-security.yml — no DNSSEC on motionapp.com. compliance: certifications_published: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears on motionapp.com, its privacy policy, its terms, its llm-info page, or the help centre. There is no trust centre and no security page (/security and /trust both 404). The strongest published statements are prose: "enterprise-grade security and transparent data practices", "we follow modern data-security standards and comply with applicable privacy regulations (e.g. GDPR)" (llm-info), and "Advanced security requirements" as a Growth-tier contract line item. Named certifications are the bar for a Compliance pointer and Motion does not meet it. gdpr_claimed: true gdpr_evidence: https://motionapp.com/llm-info privacy_contact: privacy@motionapp.com legal_entity: Motion Creative Cloud Inc.