generated: '2026-08-13' method: derived source: openapi/_original/se-ranking-data-api-openapi.yml + well-known/se-ranking-well-known.yml + mcp/se-ranking-mcp.yml standards: - id: openapi-3.0 conforms: true evidence: Provider-published OpenAPI 3.0.0, 64 paths / 86 operations, at https://github.com/seranking/openapi - id: openapi-3.1 conforms: false evidence: 'Spec declares openapi: 3.0.0' - id: mcp conforms: true evidence: Hosted Streamable-HTTP MCP server at https://api.seranking.com/mcp; tools/list returned 217 tools and prompts/list 5 prompts on an anonymous POST, 2026-08-13. Server advertises protocol versions 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07. - id: oauth2 conforms: true evidence: OAuth 2.1 authorization-code + PKCE S256 authorization server for the MCP resource - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 200 at https://seranking.com/.well-known/oauth-authorization-server - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: '200 at https://seranking.com/.well-known/oauth-protected-resource; 401s from the gated MCP route carry WWW-Authenticate: Bearer resource_metadata=...' - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint published and live (400 invalid_redirect_uri on an empty POST, i.e. the endpoint exists and validates) - id: oidc conforms: false evidence: /.well-known/openid-configuration is 403 on seranking.com and 404 on api.seranking.com, despite SE Ranking's own skill reference listing it - id: rfc9457-problem-details conforms: false evidence: Vendor {"error":{code,message,description}} envelope; no application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt is 403 on seranking.com and 404 on api.seranking.com - id: rfc8594-sunset-header conforms: false evidence: No sunset/deprecation policy or headers published - id: rfc9331-ratelimit-headers conforms: false evidence: 429 is returned with no RateLimit-*/Retry-After headers documented - id: idempotency-key conforms: false evidence: No idempotency key in spec, MCP inputSchemas or docs - id: asyncapi conforms: false evidence: No event/streaming surface; only a per-task pingback_url on SERP task creation - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json miss on both hosts (403 / 404) - id: agent-skills conforms: true evidence: 32 Agent Skills published by SE Ranking at https://github.com/seranking/seo-skills (MIT), saved verbatim in skills/ - id: json-schema conforms: true evidence: All 217 MCP tools carry JSON Schema inputSchema objects; json-schema/ holds four response schemas derived from live payloads compliance_program: published: false note: No trust center, no named certifications (SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP) found on seranking.com; trust.seranking.com does not resolve and /trust, /compliance, /security are all 404. No Compliance pointer is emitted.