generated: '2026-08-13' method: probed source: >- https://mcp.mutinyhq.com/.well-known/oauth-authorization-server, https://mcp.mutinyhq.com/.well-known/oauth-protected-resource, https://www.mutinyhq.com/dpa standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Mutiny operates a first-party hosted MCP server at https://mcp.mutinyhq.com/mcp over the streamable HTTP transport. POST /mcp answers JSON-RPC 2.0; GET /mcp returns JSON-RPC error -32000 stating that server-initiated streaming is not supported and that clients must use stateless POST. Documented for Claude web, Claude Desktop and Claude Code in Mutiny's help centre. verified: probed 2026-08-13 - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- Every observed MCP response is a well-formed JSON-RPC 2.0 envelope with jsonrpc/error/id members (errors -32001 and -32000 observed). verified: probed 2026-08-13 - id: oauth2 name: OAuth 2.0 / 2.1 authorization code conforms: true evidence: >- response_types_supported ["code"], grant_types_supported ["authorization_code"], with authorize and token endpoints published in the authorization-server metadata. verified: probed 2026-08-13 - id: rfc7636 name: PKCE (Proof Key for Code Exchange) conforms: true evidence: code_challenge_methods_supported ["S256"] — the plain method is not offered. verified: probed 2026-08-13 - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- https://mcp.mutinyhq.com/.well-known/oauth-authorization-server returns HTTP 200 application/json with issuer, authorization_endpoint, token_endpoint, registration_endpoint, response_types_supported, grant_types_supported, code_challenge_methods_supported, token_endpoint_auth_methods_supported and scopes_supported. Saved verbatim at well-known/mutiny-mcp-oauth-authorization-server.json. verified: probed 2026-08-13 - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: partial evidence: >- https://mcp.mutinyhq.com/.well-known/oauth-protected-resource returns HTTP 200 with resource, authorization_servers and scopes_supported. However the 401 from POST /mcp carries no WWW-Authenticate challenge pointing at that metadata, which is the discovery affordance RFC 9728 exists to provide — the document is served but not advertised. verified: probed 2026-08-13 - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://mcp.mutinyhq.com/oauth/register is published in the metadata. verified: probed 2026-08-13 - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document is served on any Mutiny host. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all 404 on api.mutinyhq.com and www.mutinyhq.com, and 401 on app.mutinyhq.com. verified: probed 2026-08-13 - id: graphql name: GraphQL conforms: false evidence: /graphql returns 404 on api.mutinyhq.com; no GraphQL surface is documented. verified: probed 2026-08-13 - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook contract is published. Not applicable to the current product surface. verified: probed 2026-08-13 - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.mutinyhq.com, api.mutinyhq.com and mcp.mutinyhq.com, and 401 on app.mutinyhq.com. verified: probed 2026-08-13 - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors are JSON-RPC 2.0 error objects, not application/problem+json. This is correct for an MCP server; recorded for completeness, not as a defect. verified: probed 2026-08-13 - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on www.mutinyhq.com, api.mutinyhq.com and mcp.mutinyhq.com. verified: probed 2026-08-13 compliance: source: https://www.mutinyhq.com/dpa method: searched certifications: - name: SOC 2 Type II status: achieved-or-pursuing evidence: >- Mutiny's Data Processing Addendum states it "has achieved or is pursuing the following certifications: SOC 2 Type II" and that on written request it makes available up-to-date third-party audit reports and certifications, "including SOC 2 Type II reports and ISO 27001 certificates, where available". regulations: - GDPR (Regulation (EU) 2016/679) - UK GDPR / Data Protection Act 2018 - CCPA / CPRA - Swiss FADP controls: - Data in transit encrypted using TLS 1.2 or higher - Data at rest encrypted using AES-256 or equivalent - Encryption keys managed through AWS KMS - Role-based access control (RBAC) - Multi-factor authentication required for access to production systems - Breach notification within forty-eight (48) hours of becoming aware - RTO 4 hours, RPO 1 hour - Sub-processor list maintained at https://www.mutinyhq.com/dpa with 30 days' prior written notice of change privacy_contact: privacy@mutinyhq.com note: >- Mutiny publishes no trust centre, no dedicated security page (/security and /trust both 404) and no downloadable certificate. The compliance claims above are quoted from Mutiny's own DPA and are the only first-party compliance statements found; third-party rating aggregators were disregarded.