generated: '2026-07-21' method: derived source: - openapi/supernormal-openapi-original.json - well-known/supernormal-oauth-authorization-server.json standards: - id: oauth2 conforms: true evidence: >- RFC 8414 authorization-server metadata at /.well-known/oauth-authorization-server (authorize/token/revoke endpoints, authorization_code + refresh_token grants). - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported includes S256. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint advertised (https://api.supernormal.com/oauth/register). - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer + endpoints. - id: rfc9728-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource(/mcp) returns 200 pointing MCP at the AS. - id: mcp conforms: true evidence: OAuth-protected Model Context Protocol server at https://api.supernormal.com/mcp. - id: apikey-auth conforms: true evidence: securityScheme ApiKeyAuth (X-API-TOKEN header) with scoped x-scopes. - id: rfc9457-problem-details conforms: false evidence: Error schema is a custom {error:int, message:string}, not application/problem+json. notes: >- Standards asserted from the published OpenAPI and OAuth discovery documents. No published compliance program (SOC 2 / ISO 27001 / HIPAA / GDPR certification page) was verified, so no Compliance pointer is emitted.