generated: '2026-08-13' method: probed source: >- live probes of https://mcp.realize.com/.well-known/*, https://developers.taboola.com/.well-known/api-catalog, https://backstage.taboola.com/backstage/api/1.0/, plus https://developers.taboola.com/backstage-api/reference/* and openapi/*.yml provider: Taboola providerId: taboola description: |- Cross-cutting standards conformance for Taboola. The picture splits cleanly in two: the classic Backstage REST API conforms to very little beyond OAuth 2.0 client credentials and plain JSON, while the newer Realize MCP surface is materially more standards- conformant than the API it fronts — OAuth 2.1 with PKCE, RFC 9728 protected-resource metadata, RFC 8414 authorization-server metadata, RFC 7591 dynamic client registration, and MCP Streamable HTTP. That inversion is the finding. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Backstage API authenticates with the client credentials grant against https://backstage.taboola.com/backstage/oauth/token; access token carried as a bearer in the Authorization header, expires_in 43200, no refresh token. Documented at /backstage-api/reference/authentication-basics. - id: oauth21 name: OAuth 2.1 conforms: true scope: Realize MCP only evidence: >- https://mcp.realize.com/.well-known/oauth-authorization-server (HTTP 200) declares code_challenge_methods_supported ["S256"] and grant types authorization_code, refresh_token, client_credentials. The realize-mcp README calls it OAuth 2.1 explicitly. - id: rfc7636 name: PKCE (RFC 7636) conforms: true scope: Realize MCP only evidence: 'code_challenge_methods_supported: ["S256"] in the AS metadata.' - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true scope: Realize MCP only evidence: >- https://mcp.realize.com/.well-known/oauth-authorization-server returns 200 application/json with issuer, authorization_endpoint, token_endpoint, introspection_endpoint and registration_endpoint. Saved to well-known/taboola-mcp-oauth-authorization-server.json. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: true scope: Realize MCP only evidence: >- POST tools/list to https://mcp.realize.com/mcp returned 401 with WWW-Authenticate: Bearer resource_metadata="https://mcp.realize.com/.well-known/oauth-protected-resource", and that URL returns 200 with resource, authorization_servers, bearer_methods_supported and scopes_supported. The full challenge-then-discover loop works. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: partial evidence: >- AS metadata advertises registration_endpoint https://mcp.realize.com/register. The endpoint was not exercised (registering a client is a write), so advertised but not verified. - id: rfc8707 name: Resource Indicators for OAuth 2.0 (RFC 8707) conforms: true scope: Realize MCP only evidence: 'resource_indicators_supported: true in the AS metadata.' - id: mcp name: Model Context Protocol conforms: true version: Streamable HTTP transport (2025-03-26 spec revision cited by the provider) evidence: >- First-party hosted server at https://mcp.realize.com/mcp; a pip package (realize-mcp 1.0.7) for self-hosting; a published plugin manifest (taboola/realize-claude-plugin .mcp.json) declaring type "http". - id: agent-skills name: Agent Skills (SKILL.md) conforms: true evidence: >- Six provider-authored SKILL.md files with name/description/allowed-tools frontmatter in github.com/taboola/realize-claude-plugin, saved verbatim in skills/. - id: rfc9727 name: 'api-catalog: a Well-Known URI for Publishing API Catalogs (RFC 9727)' conforms: partial evidence: >- https://developers.taboola.com/.well-known/api-catalog returns 200 application/linkset+json naming five API sections. But it is generated by the ReadMe platform rather than curated: every child service-desc it advertises 404s, and three of the five service-doc /reference targets (web-integrations, newsroom, pixel) also 404. Real document, unreliable contents. - id: rfc8288 name: Web Linking / linkset (RFC 8288, RFC 9264) conforms: true evidence: The api-catalog body is a valid linkset with anchor / service-desc / service-doc. - id: llmstxt name: llms.txt conforms: true evidence: >- https://developers.taboola.com/backstage-api/llms.txt (200, 55 KB, 415 links) plus per-section files for taboolasdk and dynamic-creative, and a site-wide https://www.taboola.com/llms.txt. Every docs page also serves a .md twin. note: >- The root https://developers.taboola.com/llms.txt returns 404 — the file lives one path segment down, per ReadMe child project. - id: openapi name: OpenAPI conforms: partial evidence: >- Taboola publishes no downloadable OpenAPI for the Backstage API. The only first-party OpenAPI fragment found is a single-operation 3.1.0 document embedded in the client-credentials-flow docs page describing the token endpoint. The 16 specs in openapi/ are API Evangelist's, built from the published reference. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- Error bodies are {"http_status": , "message": ""} with Content-Type application/json; no type URI, no application/problem+json. Unauthenticated calls and the token endpoint return XML faults instead. - id: idempotency name: Idempotency keys (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: No Idempotency-Key header or replay window documented anywhere in the reference. - id: ratelimit-headers name: RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: No RateLimit-* or X-RateLimit-* headers documented; no 429 contract published. - id: rfc8594 name: 'Sunset HTTP Header (RFC 8594)' conforms: false evidence: >- Deprecations are announced in the docs and changelog only. No Sunset, Deprecation or Link header, and no deprecation dates. - id: pagination name: Consistent pagination conforms: partial evidence: >- page/page_size/sort were added to the campaigns endpoint on 2026-02-04; other collection endpoints still return full lists. - id: json-patch name: 'JSON Patch (RFC 6902) / JSON Merge Patch (RFC 7386)' conforms: false evidence: >- Collection edits use a Taboola-specific PATCH body with a patch_operation discriminator (ADD/REMOVE/REPLACE), not either IETF patch format. - id: graphql name: GraphQL conforms: false evidence: No /graphql surface found on any Taboola host. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No event, webhook, callback or streaming surface documented in the Backstage reference. Conversion tracking is inbound to Taboola (pixel / server-to-server), not an event feed Taboola emits. Not penalized — there is no event surface to describe. - id: grpc name: gRPC / Protobuf conforms: false evidence: No .proto published in the github.com/taboola organization or in the docs. compliance_programs: trust_center: https://www.taboola.com/trust-center canonical_url: https://realize.com/help/en/articles/3878192-taboola-s-trust-center privacy_policy: https://www.taboola.com/policies/privacy-policy certifications: - ISO/IEC 27001:2022 - ISO/IEC 27701:2019 regulatory: - GDPR - CCPA - IAB Europe Transparency and Consent Framework industry: - DAA Self-Regulatory Principles - IAB OBA Framework - NAI Code of Conduct - IAB UK Gold Standard - TAG independent verification detail: ../security/taboola-trust-center.yml note: >- Certifications are named in Taboola's own Trust Center, fetched 2026-08-13. The trust.taboola.com host referenced by earlier catalog data does not resolve; the live document is served from the Realize help center.