# Vendor facets — Stytch (Connected Apps). Stytch's project domain — or a custom domain, which Stytch # "strongly recommends" — serves root discovery documents with issuer, authorization_code and, in the RFC # 8414 document, a registration_endpoint and CIMD support (fetched live from Stytch's own MCP demo auth # server). The MCP server must serve its own protected-resource metadata; Stytch documents the shape but # the fetched pages show no library that serves it. vendor: stytch name: Stytch website: https://stytch.com areas: - identity registry_keys: - stytch rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- With a custom domain on its own namespace, a Stytch Connected Apps project reads as served auth (0.9), served delegated identity and — once the opt-in DCR is enabled — dynamic client registration, because the root oauth-authorization-server document carries all three. The default *.customers.stytch.com project domain is not a host the provider owns, so the custom domain is the lift. Protected-resource metadata and every OpenAPI check remain the provider's own work. features: - id: custom-domain name: Custom domains description: >- Moves the frontend API, Connected Apps OAuth/OIDC endpoints, JWT issuance and JWKS onto the customer's domain; the default is a Stytch project domain. source: https://stytch.com/docs/guides/custom-domains/overview tier: unknown - id: connected-apps-mcp name: Connected Apps as MCP authorization server description: >- OAuth 2.1 authorization server for MCP with a hosted consent UI; serves oauth-authorization-server metadata on the project domain; opt-in DCR for third-party public clients; the MCP server hosts its own oauth-protected-resource. source: https://stytch.com/docs/connected-apps/guides/mcp-auth-overview tier: all - id: root-discovery-document name: Root authorization server metadata description: >- /.well-known/oauth-authorization-server at the host root with issuer, authorization_code, jwt-bearer, registration_endpoint and client_id_metadata_document_supported. source: https://rustic-kilogram-6347.customers.stytch.com/.well-known/oauth-authorization-server tier: all maps: - feature: root-discovery-document check: auth_clarity layer: agent_readiness grade: served provider_must: >- Configure a custom domain on its own namespace and get that host onto its record; the *.customers.stytch.com default is not a provider-owned host and the harvest never probes it. points: 10 baseline_pass_rate: 0.474 - feature: root-discovery-document check: delegated_identity layer: agent_readiness grade: served provider_must: Same custom-domain host on record; authorization_code is in grant_types_supported. points: 6 baseline_pass_rate: 0.209 - feature: connected-apps-mcp check: dynamic_client_registration layer: agent_readiness provider_must: Same host on record, and enable the opt-in DCR in the Connected Apps dashboard. points: 6 baseline_pass_rate: 0.134 - feature: connected-apps-mcp check: oauth_scopes_enumerated layer: composite conditional: true condition: >- Only if the provider's own OpenAPI declares oauth2 and enumerates the scopes its Connected Apps grant. catalog_pass_rate: 0.866 facet: contract_quality points: 4 baseline_pass_rate: 0.902 saturated: true saturated_note: >- 90% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: connected-apps-mcp check: reg_consent_model layer: composite conditional: true condition: >- Regulated regime only, and only when the provider documents the consent model behind Stytch's hosted consent UI. catalog_pass_rate: 0.126 facet: regulatory points: 7 baseline_pass_rate: 0.431 earns_nothing: - feature: connected-apps-mcp check: consent_identity why: >- The hosted OAuth consent screen is user consent to a client, not an AI usage preference or cryptographic agent identity. - feature: root-discovery-document check: well_known_published why: Authorization-server metadata is not one of the documents that check reads. out_of_reach: checks: - protected_resource_metadata - security_schemes_defined - oauth_flows_current - reg_fapi_profile note: >- Stytch's guide assigns RFC 9728 to the MCP server and no serving library appears on the fetched pages; the OpenAPI checks are the provider's contract. unscored_practice: - feature: root-discovery-document why: The served metadata declares client_id_metadata_document_supported (CIMD); no dimension reads it. surface: contract_quality: reachable: 4.0 total: 211 regulatory: reachable: 7.0 total: 108 agent_readiness: reachable: 21.0 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://rustic-kilogram-6347.customers.stytch.com/.well-known/oauth-authorization-server - https://stytch.com/docs/connected-apps/guides/mcp-auth-overview - https://stytch.com/docs/guides/custom-domains/overview measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8071 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 0.0 p75: 0.0 p90: 0.0 max: 0.0 mean_among_movers: 0.0 agent_readiness_lift: median: 12.6 p75: 12.6 p90: 14.6 max: 17.6 mean_among_movers: 12.3 facet_lift_median_among_movers: {} composite_band_moves: {} agent_readiness_band_moves: agent-aware -> agent-ready: 4886 agent-ready -> agent-native: 314 agent-aware -> agent-native: 43 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written