generated: '2026-08-29' method: probed source: >- https://account.sentry.com/oauth2/default/.well-known/openid-configuration and https://account.sentry.com/oauth2/default/.well-known/oauth-authorization-server, fetched anonymously 2026-08-29 note: >- Every assertion below is read out of the two OAuth/OIDC discovery documents Sentry Insurance's own identity host publishes. They cover the PORTAL SIGN-IN surface only. Sentry Insurance publishes no product API, so there is nothing to assert about REST conventions, pagination, RFC 9457 problem details or idempotency — those are recorded as not-applicable rather than false. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- authorization_endpoint, token_endpoint, revocation_endpoint and the full grant_types_supported/response_types_supported sets are published at https://account.sentry.com/oauth2/default/.well-known/oauth-authorization-server - id: oidc name: OpenID Connect Core 1.0 + Discovery 1.0 conforms: true evidence: >- /.well-known/openid-configuration returns issuer, userinfo_endpoint, jwks_uri, id_token_signing_alg_values_supported [RS256], subject_types_supported [public] and the standard claims_supported set. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: /oauth2/default/.well-known/oauth-authorization-server returns 200 with a conformant metadata document. - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: >- code_challenge_methods_supported = ["S256"], and the live insight.sentry.com sign-in redirect carries code_challenge_method=S256. - id: rfc9449 name: OAuth 2.0 Demonstrating Proof of Possession — DPoP (RFC 9449) conforms: true evidence: dpop_signing_alg_values_supported = [RS256, RS384, RS512, ES256, ES384, ES512] - id: rfc8628 name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: device_authorization_endpoint published; urn:ietf:params:oauth:grant-type:device_code in grant_types_supported. - id: rfc7662 name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint = https://account.sentry.com/oauth2/default/v1/introspect - id: rfc7009 name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: revocation_endpoint = https://account.sentry.com/oauth2/default/v1/revoke - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: partial evidence: >- registration_endpoint = https://account.sentry.com/oauth2/v1/clients is advertised, but Sentry Insurance publishes no documentation offering third-party client registration, so the endpoint's availability to outside developers is unverified. - id: rfc7523 name: JWT client authentication (RFC 7523) conforms: true evidence: token_endpoint_auth_methods_supported includes private_key_jwt and client_secret_jwt. - id: ciba name: OpenID Connect Client Initiated Backchannel Authentication (CIBA) conforms: true evidence: urn:openid:params:grant-type:ciba in grant_types_supported. - id: fapi name: FAPI 1.0/2.0 conforms: false evidence: >- no FAPI profile is claimed; the server still advertises the implicit and resource-owner-password grants and permits token_endpoint_auth_method "none", all of which FAPI prohibits. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false applicable: false evidence: no public API surface exists to return problem+json. - id: pagination name: Documented pagination conforms: false applicable: false evidence: no public API surface. - id: idempotency name: Idempotency keys conforms: false applicable: false evidence: no public write API surface. domain_standards: note: >- REWARD-ONLY check. Sentry Insurance operates in US property & casualty insurance, whose domain standards are the ACORD family (ACORD XML / AL3 / ACORD Data Standards) for carrier-to-agency data exchange. No ACORD conformance is DECLARED in any contract Sentry Insurance publishes, because it publishes no contract — the probe found no WSDL, no XSD, no ACORD message-type reference and no download-service documentation on any Sentry or Dairyland host. Carrier ACORD exchange at this company is presumably conducted through appointed-agency channels that are not publicly documented. Recorded as "not declared", NOT as "does not conform" — absence of a published contract is not evidence of a missing standard. candidates_probed: - standard: ACORD (P&C XML / AL3) declared_in_contract: false evidence: >- no /*?wsdl, /services, /acord or download-service surface found on www.sentry.com, insight.sentry.com, quickpay.sentry.com, www.dairylandinsurance.com or www.dairyland.com; sitemap.xml (1,000+ URLs) contains no api/developer/integration path. compliance_certifications: [] compliance_note: >- No trust center, SOC 2 / ISO 27001 / PCI attestation page or published compliance program was found on any Sentry Insurance host. https://trust.sentry.com does not resolve; https://www.sentry.com/security returns 404. No Compliance pointer is emitted.