generated: '2026-08-26' method: derived source: >- openapi/scimar-content-openapi.yml, live response headers, well-known/scimar-well-known.yml, mcp/scimar-mcp.yml and security/scimar-domain-security.yml standards: - id: openapi-3.1 conforms: true evidence: >- openapi/scimar-content-openapi.yml — DERIVED by API Evangelist from the provider's live route-discovery document, not published by Scimar. provider_published: false - id: json-schema conforms: true evidence: WordPress REST route args are JSON Schema fragments (type/enum/default/minimum/maximum) - id: rfc7617-http-basic conforms: true evidence: securitySchemes.applicationPassword — http/basic (WordPress Application Passwords) - id: rfc8288-web-linking conforms: true evidence: 'Link: <...>; rel="next" observed on GET /wp/v2/posts; resources carry _links relations' - id: model-context-protocol conforms: partial evidence: >- Two JSON-RPC MCP endpoints served at /wp-json/mcp/mcp-oauth-server and /wp-json/mcp/mcp-adapter-default-server; anonymous tools/list returns 401 on both, so protocol conformance beyond the transport and the auth challenge could not be verified. - id: oauth2 conforms: true evidence: >- https://scimar.ca/.well-known/oauth-authorization-server returns 200 with issuer, authorization, token and revocation endpoints, authorization_code + refresh_token grants and S256 PKCE. Scoped to the MCP surface (scopes_supported ["mcp"]); wp/v2 itself is not OAuth-protected. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- /.well-known/oauth-authorization-server returns 200 application/json with issuer https://scimar.ca. Deviation: the canonical no-trailing-slash path 301-redirects to the trailing-slash form before serving. saved: well-known/scimar-oauth-authorization-server.json - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 naming https://scimar.ca/wp-json/mcp/mcp-oauth-server, and the 401 from that endpoint carries a matching WWW-Authenticate Bearer challenge with resource_metadata pointing back at it. This is the full RFC 9728 round trip, correctly wired. saved: well-known/scimar-oauth-protected-resource.json - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] with token_endpoint_auth_methods_supported ["none"] - id: llms-txt conforms: true evidence: >- https://scimar.ca/llms.txt returns 200 text/plain (34,293 bytes) in valid llms.txt shape — H1 site name, then ## Sitemaps / ## Posts / ## Pages / ## Team / ## Categories / ## Member Category link lists. Generated by All in One SEO v5.0.0.1. Saved verbatim to llms/scimar-llms.txt. provider_published: true - id: rfc9457-problem-details conforms: false evidence: errors use the WordPress {code,message,data.status} envelope, not application/problem+json - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404 - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404 on scimar.ca - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface published; /asyncapi.yaml, /asyncapi.json, /events and /webhooks all 404. - id: graphql conforms: false evidence: no /graphql route in any of the 12 registered WordPress REST namespaces; /graphql 404 - id: soap-wsdl conforms: false evidence: >- https://scimar.ca/?wsdl and ?singleWsdl both return 200 but with an HTML body — the WordPress homepage ignoring an unknown query parameter. Not a WSDL. Recorded so a later round does not re-report the 200 as a hit. - id: sitemaps-org conforms: true evidence: >- https://scimar.ca/sitemap.xml returns a valid sitemapindex with five child sitemaps (post, page, team, category, member-category) - id: rfc9309-robots conforms: true evidence: 'robots.txt present, disallows /wp-admin/ only, and declares both sitemaps' - id: tls-1-3 conforms: true evidence: security/scimar-domain-security.yml — TLSv1.3 negotiated on scimar.ca - id: hsts conforms: true evidence: 'Strict-Transport-Security present, max-age=63072000 (two years)' - id: dnssec conforms: false evidence: security/scimar-domain-security.yml — no DNSKEY on scimar.ca - id: spf conforms: true evidence: SPF record present on scimar.ca - id: dmarc conforms: false evidence: no DMARC record on scimar.ca - id: caa conforms: false evidence: no CAA record on scimar.ca domain_standard: applicable: false sector: life sciences / pharmaceutical R&D candidates_considered: - {standard: HL7 FHIR, present: false, note: 'no clinical data exchange surface; Scimar ships no health-data API'} - {standard: CDISC SDTM/ODM, present: false, note: 'clinical trial data standards — no trial data is exposed through any API'} - {standard: ORCID / DataCite / Crossref, present: false, note: 'no research-identifier scheme appears in any served document'} - {standard: OAI-PMH, present: false, note: 'no repository verb endpoint served'} note: >- REWARD-ONLY check, deliberately left empty. Scimar's market (pre-commercial diabetes diagnostics and therapeutics) does have domain standards, but Scimar exposes no contract in that market at all — the only API surface on scimar.ca is its CMS. There is nothing in any served spec that declares a domain standard, so none is asserted. compliance_certifications: [] compliance_note: >- No trust center, no SOC 2 / ISO 27001 / HIPAA / PIPEDA attestation page and no compliance program page was found on scimar.ca. No Compliance pointer is wired.