# OSSIO > OSSIO is an orthopedic fixation medical device company (Woburn, Massachusetts; founded > in Israel, 2014) that makes OSSIOfiber, a bio-integrative, metal-free implant material. > OSSIO sells physical implants — screws, suture anchors, staples, bone pins and trimmable > fixation nails — not software. It publishes no developer program, no product API and no > OpenAPI. The only machine-readable surface it serves is its own WordPress corporate site. Generated by API Evangelist on 2026-08-26 from probes of ossio.io and this repository. This file is NOT published by OSSIO; it is an independent third-party profile. Method: generated. Source: apis.yml + repo artifacts. OSSIO serves no /llms.txt (https://ossio.io/llms.txt -> HTTP 404). ## API surface - [OSSIO Site MCP Server](https://ossio.io/wp-json/mcp/mcp-oauth-server): OAuth-protected Model Context Protocol endpoint mounted on the corporate WordPress site by the MCP Adapter plugin. Exposes site content and WordPress abilities to agents. It is NOT an OSSIOfiber product API. Anonymous `tools/list` returns HTTP 401, so the tool list is auth-gated and has not been enumerated. - [MCP server registry](https://ossio.io/wp-json/mcp): lists two servers — `mcp-oauth-server` (OAuth bearer) and `mcp-adapter-default-server` (WordPress cookie/application-password). - [WordPress REST API](https://ossio.io/wp-json/): 634 routes across 45 namespaces, mostly plugin-private. Content routes under `wp/v2` are readable anonymously. ## Authentication - [Authorization server metadata](https://ossio.io/.well-known/oauth-authorization-server): RFC 8414. Issuer `https://ossio.io`. Authorization code + refresh token. PKCE `S256` required. Public clients (`token_endpoint_auth_methods_supported: ["none"]`) identified by a client-ID metadata document. Single scope: `mcp`. - [Protected resource metadata](https://ossio.io/.well-known/oauth-protected-resource): RFC 9728. Names the MCP endpoint as the protected resource; bearer token in the header. - The 401 challenge carries `WWW-Authenticate: Bearer realm="https://ossio.io", resource_metadata="..."`, so a client can discover everything from the challenge alone. ## Not published - No OpenAPI, Swagger, AsyncAPI, GraphQL, gRPC/Protobuf or WSDL contract. - No A2A agent card (`/.well-known/agent-card.json` and `/.well-known/agent.json` -> 404). - No `security.txt`, no `api-catalog`, no `openid-configuration`, no `ai-plugin.json`. - No SDKs or client libraries on npm, PyPI, Maven Central, NuGet, RubyGems or crates.io. - No GitHub organization (`ossio`, `ossiofiber`, `ossio-io`, `ossio-ltd` -> 404). - No CLI, no sandbox, no Postman collection, no changelog, no status page, no roadmap. - No pricing, no API plans (`plan_count: 0`), no documented rate limits (`limit_count: 0`). - No vulnerability disclosure program and no trust center. ## Company - [Website](https://ossio.io/) - [Who we are](https://ossio.io/who-we-are/) - [For surgeons](https://ossio.io/surgeons/) - [For patients](https://ossio.io/patients/) - [Resource library](https://ossio.io/resources/) - [Surgeon locator](https://ossio.io/patients/surgeon-locator/) - [Press releases](https://ossio.io/press/) - [RSS feed](https://ossio.io/feed/) - [Contact](https://ossio.io/contact/) — info@ossio.io, 833-781-7373 - [Privacy policy](https://ossio.io/privacy-policy/) - [SMS terms of service](https://ossio.io/ossio-sms-terms-of-service/) - [LinkedIn](https://www.linkedin.com/company/ossio-ltd.) ## Note for agents ossio.com is a DIFFERENT entity — the personal site of Daniel Ossio, a cybersecurity speaker and wingsuit pilot. It has no relationship to OSSIO the medical device company. The company's domain is ossio.io.