generated: '2026-08-13' method: searched source: - https://api.interchange.io/.well-known/oauth-authorization-server - https://api.interchange.io/.well-known/oauth-protected-resource - https://docs.interchange.io/.well-known/agent-card.json - https://docs.interchange.io/v2/reference/rate-limits - openapi/_original/scope3-buyer-openapi-original.yml - openapi/_original/scope3-storefront-openapi-original.yml standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization-code flow published at https://api.interchange.io/.well-known/oauth-authorization-server (issuer, authorization, token and registration endpoints), used by the Claude/ChatGPT MCP connectors. Upgraded from the 2026-07-21 reading of false, which was correct for the measurement APIs but predated discovery of the Interchange OAuth surface. - id: rfc8414-authorization-server-metadata conforms: true evidence: https://api.interchange.io/.well-known/oauth-authorization-server returns 200 JSON metadata. - id: rfc9728-protected-resource-metadata conforms: true evidence: >- https://api.interchange.io/.well-known/oauth-protected-resource returns 200 naming resource https://api.interchange.io/mcp and two authorization servers. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://api.interchange.io/auth/register - id: oidc conforms: true evidence: >- OIDC Discovery 1.0 documents at https://identity.scope3.com/.well-known/openid-configuration (scopes_supported openid/profile/email/offline_access) and https://api.interchange.io/.well-known/openid-configuration. WorkOS is the credential control plane. Upgraded from false. - id: http-bearer-jwt conforms: true evidence: aiapi securityScheme bearerAuth type http scheme bearer bearerFormat JWT - id: ietf-ratelimit-headers-draft-7 conforms: true evidence: >- Documented RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset plus Retry-After on 429, explicitly named as draft-7 in https://docs.interchange.io/v2/reference/rate-limits - id: rfc9457-problem-details conforms: false evidence: >- Neither regime uses application/problem+json. Interchange uses a proprietary {data, error:{code,message,field,details}} envelope; the measurement APIs use a plain Error schema. - id: openapi-3.0 conforms: true evidence: All four published specs are OpenAPI 3.0.0. - id: rest-json conforms: true evidence: JSON request/response over REST resources across all four specs. - id: pagination conforms: true evidence: >- Documented offset pagination (take/skip) with a meta.pagination block, plus a custom group/product offset scheme for discovery. See conventions/scope3-conventions.yml. - id: idempotency conforms: true evidence: >- Body-level idempotencyKey (minLength 8, maxLength 128, pattern ^[A-Za-z0-9._:-]+$) is REQUIRED on rate-card acceptance in both Interchange specs; external_row_id gives upsert idempotency on measurement sync; the activity response carries idempotencyReplayOfActivityUid so a caller can detect a replay. No Idempotency-Key header. Upgraded from false. - id: mcp conforms: true evidence: >- Two hosted remote MCP endpoints (api.interchange.io/mcp/buyer and /mcp/storefront), OAuth metadata published per the MCP authorization spec, and services.mcp "ready" on the unauthenticated health endpoint. - id: a2a conforms: near evidence: >- A2A agent card served at https://docs.interchange.io/.well-known/agent-card.json; graded near-conformant against A2A 1.0.0 (supportedInterfaces rather than additionalInterfaces, protocolVersion "0.3"). services.a2a reports "ready". See a2a/scope3-a2a.yml. - id: adcp conforms: true evidence: >- The Interchange platform transacts on the Ad Context Protocol; MCP tool errors follow the AdCP error spec (adcontextprotocol.org/schemas/3.0.0-rc.3/core/error.json), and AdCP versioning and negotiation are documented concepts. - id: agent-skills conforms: true evidence: >- Three provider-published skill.md files (buyer, storefront, and the platform skill at /.well-known/agent-skills/scope3/skill.md referenced by the agent card). - id: llms-txt conforms: true evidence: llms.txt published at both https://docs.scope3.com/llms.txt and https://docs.interchange.io/llms.txt - id: webhooks conforms: true evidence: >- First-class webhook-subscription resource with three operations and a required shared secret in the buyer spec. See asyncapi/scope3-webhooks.yml. - id: asyncapi conforms: false evidence: No AsyncAPI document is published on any host. - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false compliance_program: published: false note: >- No certification claims (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) are published on any Scope3 or Interchange host. scope3.com/security, /trust and /responsible-disclosure all return 404 and trust.scope3.com does not resolve (checked 2026-08-13). No Compliance or TrustCenter pointer is emitted — recording the absence, not asserting a program. probed: - {url: 'https://trust.scope3.com', status: 000, note: DNS does not resolve} - {url: 'https://scope3.com/security', status: 404} - {url: 'https://scope3.com/trust', status: 404} - {url: 'https://scope3.com/responsible-disclosure', status: 404} - {url: 'https://scope3.com/.well-known/security.txt', status: 404} industry_standards_participation: note: >- Scope3 maintains public forks/mirrors of ad-industry standards work in its GitHub org (Prebid.js, prebid-server, prebid-server-java, openrtb) and publishes its emissions measurement methodology openly at github.com/scope3data/methodology. Recorded as context, not as a conformance claim about the APIs.