generated: '2026-08-13' method: searched source: >- openapi/_original/paragraph-openapi-original.json plus live probes of https://paragraph.com/.well-known/*, https://mcp.paragraph.com/.well-known/* and https://paragraph.com/robots.txt standards: - id: openapi-3.1 conforms: true evidence: Published OpenAPI 3.1.0 document (Paragraph API 1.0.0) with 45 operations, served from https://github.com/paragraph-xyz/paragraph-sdk-js/blob/main/openapi.json. - id: http-bearer-auth conforms: true evidence: components.securitySchemes.apiKey — type http, scheme bearer — applied to the protected operations. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 200 at https://paragraph.com/.well-known/oauth-authorization-server and https://mcp.paragraph.com/.well-known/oauth-authorization-server. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: 200 at https://paragraph.com/.well-known/oauth-protected-resource and https://mcp.paragraph.com/.well-known/oauth-protected-resource; the MCP 401 also names the metadata document in its WWW-Authenticate header. - id: rfc7591-dynamic-client-registration conforms: true evidence: mcp.paragraph.com advertises registration_endpoint https://mcp.paragraph.com/register. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["plain","S256"] on the MCP authorization server. - id: oauth2 conforms: partial evidence: >- The hosted MCP server runs a full OAuth 2.1 authorization code flow. The REST API advertises OAuth discovery metadata and two scopes (api.read, api.write) but issues a non-fine-grained API key rather than an OAuth access token, and declares no oauth2 securityScheme in the spec. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on paragraph.com and public.api.paragraph.com. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom { success:false, msg } JSON envelope, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on paragraph.com, public.api.paragraph.com and mcp.paragraph.com. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every host. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header or deprecation policy is published; the API is simply labelled alpha. - id: rfc6585-429-rate-limit conforms: false evidence: Rate limiting is stated in prose but no 429 response is declared on any operation and no RateLimit-*/Retry-After header is documented. - id: cursor-pagination conforms: true evidence: List endpoints accept cursor + limit and return { items, pagination }. - id: idempotency conforms: false evidence: No Idempotency-Key header is documented or declared. Update operations use optimistic concurrency (409 Conflict) instead. - id: agent-skills-discovery conforms: true evidence: Publishes /.well-known/agent-skills/index.json against the agentskills.io discovery schema 0.2.0 (Cloudflare Agent Skills Discovery RFC). - id: content-signals conforms: true evidence: >- robots.txt carries "Content-Signal: search=yes, ai-input=yes, ai-train=no" applied to * and named explicitly to GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, Claude-Web, anthropic-ai, PerplexityBot, meta-externalagent, Amazonbot, cohere-ai and YouBot (contentsignals.org). - id: mcp conforms: true evidence: Hosted server at https://mcp.paragraph.com/mcp (streamable HTTP, OAuth) plus the @paragraph-com/mcp stdio server. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: llms-txt conforms: true evidence: llms.txt and llms-full.txt served at docs.paragraph.com, plus a .md variant of every docs page and an llms.txt at paragraph.com. certifications: published: false searched: - url: https://trust.paragraph.com status: 200 result: soft-200 — resolves to https://paragraph.com/ and serves the marketing homepage - url: https://paragraph.com/trust status: 404 - url: https://paragraph.com/security status: 404 note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published anywhere on Paragraph's public surface, and no trust center exists. No Compliance or TrustCenter pointer is emitted. notes: >- Re-probed 2026-08-13. The material change since 2026-07-20 is the arrival of OAuth 2.0 discovery metadata on two hosts (RFC 8414 + RFC 9728) and a full authorization server with dynamic client registration in front of the MCP endpoint. Paragraph's conformance profile is now noticeably stronger on agent/authorization standards than on classic HTTP API hygiene: it publishes discovery metadata, content signals and agent skills, but no problem+json, no security.txt, no api-catalog, no Sunset policy and no 429 semantics.