generated: '2026-08-26' method: probed source: >- https://api.moz.com/.well-known/oauth-authorization-server, https://api.moz.com/.well-known/oauth-protected-resource/mcp/v1/data, https://moz.com/api/docs/guides/error-handling summary: >- Moz's conformance profile is entirely about the transport and the agent layer: JSON-RPC 2.0 for the data API, and a correctly-implemented OAuth 2.1 / MCP stack in front of the two beta MCP endpoints. It does not conform to the REST/HTTP-semantics standards (RFC 9457, RFC 8594, RFC 6585 rate-limit headers) because it does not use HTTP that way. standards: - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- Moz's getting-started guide names JSON-RPC 2.0 as the protocol and links the specification; live probes return spec-shaped {jsonrpc, id, result|error} bodies, and an invalid version string is rejected with 'jsonrpc must be "2.0"'. Probed 2026-08-26. deviation: >- Moz layers HTTP status codes on top of the JSON-RPC envelope (a JSON-RPC error is returned with a 400/401 rather than a 200), and adds a non-standard minimum length of 24 characters on the id member. - id: mcp name: Model Context Protocol conforms: true evidence: >- Two documented remote MCP endpoints (https://api.moz.com/mcp/v1/data and .../local) answered a tools/list JSON-RPC probe with a well-formed MCP error and an RFC 9728 challenge. Published in the Claude connector directory. Probed 2026-08-26. status: beta - id: oauth2 name: OAuth 2.0 / 2.1 authorization code conforms: true evidence: >- /.well-known/oauth-authorization-server returns issuer, authorization_endpoint, token_endpoint, registration_endpoint, response_types_supported [code], grant_types_supported [authorization_code]. Probed 2026-08-26. - id: rfc8414 name: 'RFC 8414: OAuth 2.0 Authorization Server Metadata' conforms: true evidence: https://api.moz.com/.well-known/oauth-authorization-server returned 200 with valid metadata - id: rfc9728 name: 'RFC 9728: OAuth 2.0 Protected Resource Metadata' conforms: true evidence: >- Both MCP endpoints return WWW-Authenticate with a resource_metadata parameter, and each per-resource document (/.well-known/oauth-protected-resource/mcp/v1/{data,local}) returns 200 with resource, authorization_servers, scopes_supported and bearer_methods_supported. deviation: >- The bare /.well-known/oauth-protected-resource path 404s; only the path-suffixed per-resource documents are served. - id: rfc7636 name: 'RFC 7636: PKCE' conforms: true evidence: 'code_challenge_methods_supported: ["S256"] in the authorization server metadata' - id: rfc7591 name: 'RFC 7591: OAuth 2.0 Dynamic Client Registration' conforms: true evidence: 'registration_endpoint: https://api.moz.com/oauth/register is advertised in the metadata' - id: rfc9116 name: 'RFC 9116: security.txt' conforms: partial evidence: >- https://moz.com/.well-known/security.txt returns 200 with Contact, Expiration, Encryption, Policy and Acknowledgements fields. deviation: >- The Expires/Expiration value is 2026-08-25T19:48:09-07:00, i.e. the document was expired at the time of probing (2026-08-26), and the Policy, Encryption and Acknowledgements URLs it advertises all return 404. See security/moz-vulnerability-disclosure.yml. - id: oidc name: OpenID Connect conforms: false evidence: '/.well-known/openid-configuration returned 404 on both moz.com and api.moz.com (2026-08-26)' - id: rfc9457 name: 'RFC 9457: Problem Details for HTTP APIs' conforms: false evidence: >- Errors are JSON-RPC error objects (code/status/message/data), not application/problem+json. See errors/moz-problem-types.yml. - id: rfc8594 name: 'RFC 8594: Sunset HTTP Header' conforms: false evidence: No Sunset or Deprecation headers observed; no deprecation policy is published. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI document is published. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on api.moz.com (all 404) and moz.com/api/openapi.json (403 Cloudflare). The docs site's own "Export docs" link points at /moz-ui-dev/api/export, which is behind Cloudflare Access. note: >- Moz does publish a complete machine-readable contract, just not as OpenAPI - see json-schema/moz-api-schema.json (74 actions, 930 JSON Schema definitions). - id: json-schema name: JSON Schema conforms: true evidence: >- The docs application serves a single JSON Schema document describing every action's payload, result and quota, with 930 definitions and $ref-linked object types. Harvested verbatim to json-schema/moz-api-schema.json on 2026-08-26. domain_standards: note: >- Search/SEO measurement has no ratified interchange standard (Domain Authority, Page Authority, Brand Authority and Spam Score are Moz's own proprietary metrics), so there is no domain standard to conform to and none is asserted here. Moz Local integrates with Google Business Profile as a downstream listing network, which is a vendor integration rather than a standard. domain_standard_conformance: not-applicable compliance: certifications_published: [] trust_center: false note: >- No trust center, SOC 2 / ISO 27001 / PCI / HIPAA certification page, or compliance program page could be found on moz.com (trust.moz.com does not resolve; moz.com/trust 404s). No Compliance pointer is emitted.