generated: '2026-08-29' method: probed source: >- https://mcp.pluralsight.com/.well-known/oauth-authorization-server, https://mcp.pluralsight.com/.well-known/oauth-protected-resource, https://pluralsight.com/.well-known/security.txt, https://developer.pluralsight.com/docs/getting-started/pagination, https://trust.pluralsight.com/ provider: Pluralsight providerId: pluralsight description: >- Cross-cutting and domain standards asserted by Pluralsight's own contracts and served documents. Each entry carries the exact location the evidence was read from. standards: - id: oauth2 name: OAuth 2.0 / 2.1 authorization code with PKCE conforms: true evidence: url: https://mcp.pluralsight.com/.well-known/oauth-authorization-server http_status: 200 detail: >- grant_types_supported [authorization_code, refresh_token], response_types_supported [code], code_challenge_methods_supported [S256], token_endpoint_auth_methods_supported [none] - a public-client PKCE profile. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: url: https://mcp.pluralsight.com/.well-known/oauth-authorization-server http_status: 200 - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: url: https://mcp.pluralsight.com/.well-known/oauth-protected-resource http_status: 200 detail: >- the 401 on https://mcp.pluralsight.com/mcp also emits the matching challenge - WWW-Authenticate: Bearer error="invalid_token", resource_metadata="..." - which is the behaviour RFC 9728 specifies, not just the document. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: url: https://mcp.pluralsight.com/.well-known/oauth-authorization-server http_status: 200 detail: registration_endpoint https://mcp.pluralsight.com/register is advertised. - id: oidc name: OpenID Connect Discovery conforms: partial evidence: url: https://mcp.pluralsight.com/.well-known/openid-configuration http_status: 200 detail: >- a discovery document is served at the OIDC path, but its body is byte-identical to the OAuth authorization-server metadata - it declares no userinfo_endpoint, no id_token signing algorithms and no subject types. It is OAuth metadata served at the OIDC URL, not an OpenID Provider configuration. - id: rfc9116 name: security.txt conforms: true evidence: url: https://pluralsight.com/.well-known/security.txt http_status: 200 detail: >- Canonical, Contact (HackerOne + mailto), Expires 2027-02-04T10:43:00Z, Policy, Preferred-Languages. Served identically from developer., paas-api., paas-rest-api., app. and mcp. hosts. - id: mcp name: Model Context Protocol conforms: true evidence: url: https://mcp.pluralsight.com/mcp http_status: 401 detail: >- an anonymous JSON-RPC tools/list returns a well-formed MCP protocol error object; streamable HTTP and SSE transports both answer. Protocol version could not be read without a token. - id: graphql-cursor-connections name: GraphQL Cursor Connections (Relay) Specification conforms: true evidence: url: https://developer.pluralsight.com/docs/getting-started/pagination http_status: 200 detail: >- first/after arguments, edges[].cursor, edges[].node, nodes, pageInfo.endCursor, pageInfo.hasNextPage, totalCount - the full connection shape, documented by Pluralsight as "Cursor Based Pagination". - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: detail: no operation in any spec in this repo declares application/problem+json. - id: idempotency name: Idempotency keys for unsafe HTTP methods conforms: false evidence: detail: >- no idempotency key, header or dedup window is documented for any of the 24 GraphQL mutations. - id: rfc8594 name: Sunset HTTP header conforms: false evidence: url: https://developer.pluralsight.com/docs/deprecations/deprecation-policy http_status: 200 detail: >- Pluralsight runs a real 9-month deprecation programme but signals it in the GraphQL response body (extensions.warnings), not in Sunset or Deprecation headers. - id: scim name: SCIM 2.0 conforms: false evidence: detail: >- no urn:ietf:params:scim:schemas:* URN, no /scim/v2 surface and no SCIM endpoint appears in any contract in this repo, despite Pluralsight shipping user/team provisioning mutations that cover the same ground. domain_standards: - id: xapi name: xAPI / Experience API (ADL, e-learning activity statements) conforms: unknown evidence: url: https://developer.pluralsight.com/xapi-provider http_status: 200 detail: >- the developer portal's route manifest declares a first-party /xapi-provider page and it answers 200, but the page is client-rendered and served no readable content, no LRS endpoint, no statement schema and no xAPI version to an anonymous crawler. Third-party sources describe Pluralsight sending xAPI statements to partner LRSs. NO xAPI conformance is asserted here because no Pluralsight-published contract, endpoint or statement shape was reachable. action: >- a human with a Pluralsight plan should open https://developer.pluralsight.com/xapi-provider and record what it actually documents - this is the single highest-value unresolved lead on this provider, because xAPI is the domain standard for this market. - id: lti name: IMS Learning Tools Interoperability conforms: false evidence: detail: >- no LTI launch URL, tool configuration, or OIDC-launch surface is published on developer.pluralsight.com. LMS integration is delivered as partner connectors, not as a standards-based launch. - id: scorm name: SCORM conforms: false evidence: detail: no SCORM package endpoint or manifest is published on any Pluralsight developer surface. compliance: published: true source: https://trust.pluralsight.com/ certifications: - SOC 2 - ISO 27001 - PCI DSS - GDPR see_also: ../security/pluralsight-trust-center.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com