generated: '2026-08-13' method: searched source: >- https://poggio.io/docs and Poggio /.well-known/ OAuth metadata; Goalkeeper entries from https://docs.gkeeper.ai and openapi/poggio-labs-goalkeeper-openapi.json (v0.5.0) standards: - id: oauth2 conforms: true evidence: OAuth 2.0 with authorization_code, client_credentials, refresh_token flows (well-known/poggio-labs-oauth-authorization-server.json). - id: oauth2-pkce-rfc7636 conforms: true evidence: code_challenge_methods_supported = [S256]. - id: oauth2-dcr-rfc7591 conforms: true evidence: registration_endpoint published; Dynamic Client Registration documented for MCP clients. - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer/endpoints/grant_types. - id: rfc9728-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource (api + mcp) return 200 with resource + authorization_servers. - id: mcp conforms: true evidence: Hosted MCP server at https://mcp.poggio.io/mcp (version 1.0.05) with published tool specs. - id: saml2 conforms: true evidence: SAML 2.0 SSO documented at https://poggio.io/docs/admin/saml. - id: scim2 conforms: true evidence: SCIM 2.0 user provisioning documented at https://poggio.io/docs/admin/scim. - id: soc2 conforms: true evidence: SOC 2 listed on Poggio trust center (security/poggio-labs-trust-center.yml). - id: iso27001 conforms: true evidence: ISO 27001 listed on Poggio trust center (security/poggio-labs-trust-center.yml). - id: openapi-3.1 conforms: true scope: goalkeeper evidence: >- Goalkeeper publishes an OpenAPI 3.1.0 document covering 36 operations (services/api/openapi.json at tag v0.5.0), generated by `bun run api:specs` and used to render its own API reference. - id: mcp-2026-07-28 conforms: true scope: goalkeeper evidence: >- The Goalkeeper MCP service implements MCP protocol 2026-07-28 with a stateless 2025-11-25 fallback (https://docs.gkeeper.ai/docs/concepts/mcp). - id: rfc9728-protected-resource-metadata conforms: true scope: goalkeeper evidence: >- A Goalkeeper deployment with an McpOAuthProvider publishes RFC 9728 Protected Resource Metadata and includes its URL in bearer challenges. - id: oauth2-pkce-rfc7636 conforms: true scope: goalkeeper evidence: >- Goalkeeper advertises the authorization-code + S256 PKCE contract required by MCP and supports Client ID Metadata Documents or Dynamic Client Registration via the provider. - id: semver-2.0.0 conforms: true scope: goalkeeper evidence: >- vMAJOR.MINOR.PATCH tags with a documented pre-1.0 policy (https://docs.gkeeper.ai/docs/releases); current release v0.5.0. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json error format documented on either surface. Goalkeeper returns its own {"error","message"} object (errors/poggio-labs-goalkeeper-problem-types.yml). - id: fhir-r4 conforms: false - id: fapi conforms: false