generated: '2026-08-13' method: searched source: >- github.com/PubMatic/pubmatic-mcp-server integration guides, github.com/PubMatic/OpenWrap, and live probes of pubmatic.com note: >- No Compliance pointer is emitted from this file. PubMatic publishes no trust center, no certification page and no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim that this pass could find (trust.pubmatic.com does not resolve; pubmatic.com/security/, /security-and-compliance/ and /legal/security/ all return 404; the /legal/ index lists no security or certification document). Standards below are the ones PubMatic itself names in its own public artifacts. standards: - id: mcp-2025-06-18 name: Model Context Protocol conforms: true evidence: >- "The PubMatic MCP Server implements the Model Context Protocol (MCP) specification" with an explicit link to modelcontextprotocol.io/specification/2025-06-18/server/tools#structured-content; live endpoint https://mcp.pubmatic.com/mcp answers a tools/list JSON-RPC POST with a protocol-shaped 401 (JSON-RPC error object, code -32002) rather than an HTTP error page. source: https://github.com/PubMatic/pubmatic-mcp-server/blob/main/Deal%20Management/README.md - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- All MCP requests and responses documented as JSON-RPC 2.0 with structured content; observed error body {"jsonrpc":"2.0","error":{"code":-32002,...}}. - id: oauth2-bearer name: OAuth 2.0 Bearer Token Usage (RFC 6750) conforms: partial evidence: >- Live 401 carries a conformant WWW-Authenticate: Bearer error="invalid_token" error_description=... challenge. PARTIAL because the companion discovery documents are absent — /.well-known/oauth-authorization-server (RFC 8414) and /.well-known/oauth-protected-resource (RFC 9728) both 404 on mcp.pubmatic.com, so a client cannot follow the challenge to an authorization server. - id: rfc8414-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on mcp.pubmatic.com - id: rfc9728-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata conforms: false evidence: /.well-known/oauth-protected-resource returns 404 on mcp.pubmatic.com - id: openrtb-2.5 name: IAB Tech Lab OpenRTB 2.5 conforms: true evidence: >- The DSP Onboarding agent "send[s] OpenRTB bid requests to the DSP's endpoint" and "Validate[s] bid responses against OpenRTB 2.5 standards and PubMatic-specific requirements"; DSPs must expose an endpoint "capable of handling OpenRTB 2.5 POST requests". source: https://github.com/PubMatic/pubmatic-mcp-server/blob/main/DSP%20Onboarding/DSP_onboarding_integration_guide.md - id: iab-sellers-json name: IAB Tech Lab sellers.json conforms: true evidence: >- https://pubmatic.com/sellers.json returns HTTP 200 (933,094 bytes) after a 301 to https://cdn.pubmatic.com/sellers/data/sellers.json - id: prebid name: Prebid.js conforms: true evidence: >- OpenWrap is PubMatic's open-source Prebid-based header-bidding wrapper (github.com/PubMatic/OpenWrap), with web, iOS, Android, Flutter, React Native and Unity SDK distributions. - id: iab-vast name: IAB VAST (video ad serving) conforms: true evidence: >- DSP onboarding agent previews and verifies creatives returned as "HTML/Native/VAST" directly from the DSP bid response. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Errors are JSON-RPC error objects, not application/problem+json. No REST error envelope is published. - id: openapi name: OpenAPI Specification conforms: false evidence: >- No OpenAPI/Swagger document found on any host. Probed pubmatic.com, api.pubmatic.com, mcp.pubmatic.com and help.pubmatic.com for /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc, /swagger-ui.html — all 404/500/302. - id: asyncapi name: AsyncAPI conforms: false evidence: No event/streaming/webhook specification published; no /asyncapi.yaml served. - id: graphql name: GraphQL conforms: false evidence: >- POST of an introspection query to https://api.pubmatic.com/graphql returns the Apigee SOAP catch-all fault, not a GraphQL response. No /graphql surface exists on any PubMatic host. (A conceptual GraphQL schema previously stored in this repo was removed on 2026-08-13 as fabricated — see the repository README/commit note.) - id: a2a name: A2A Agent2Agent Protocol conforms: unclaimed evidence: >- PubMatic's MCP repository README repeatedly names A2A as a target protocol ("agents collaborate directly", "protocols like MCP or A2A"), but no Agent Card is served — /.well-known/agent-card.json and /.well-known/agent.json return 404 (or 502) on every host probed. Aspiration in prose, not a deployed surface. - id: rfc8594-sunset-header name: RFC 8594 Sunset header / deprecation signalling conforms: unknown evidence: No deprecation or versioning policy published publicly; docs are login-gated.