generated: '2026-07-21' method: derived source: https://app.seezo.io/.well-known/oauth-authorization-server notes: >- Derived from the provider's live OAuth 2.0 Authorization Server metadata. Seezo publishes no OpenAPI, so only the identity/authorization standards its discovery document evidences are asserted here. Compliance certifications (SOC 2, ISO 27001) are captured in security/seezo-trust-center.yml. standards: - id: oauth2 conforms: true evidence: RFC 8414 authorization-server metadata publishes authorization_code and refresh_token grants - id: rfc8414-as-metadata conforms: true evidence: /.well-known/oauth-authorization-server served as application/json - id: pkce-rfc7636 conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint present in AS metadata - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint present in AS metadata - id: oidc conforms: false evidence: no /.well-known/openid-configuration (400/404) - id: rfc9457-problem-details conforms: false - id: soc2 conforms: true evidence: SOC 2 listed on trust center (trust.seezo.io) - id: iso-27001 conforms: true evidence: ISO 27001 v2022 listed on trust center (trust.seezo.io)