generated: '2026-08-05' method: derived source: well-known/tegus-openid-configuration.json note: >- Every assertion below is derived from the live discovery documents at auth.tegus.com. No product API contract is published, so no REST/GraphQL/event conformance can be asserted either way — those entries are recorded as unknown rather than false. standards: - id: openid-connect-discovery-1.0 conforms: true evidence: >- /.well-known/openid-configuration returns 200 with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint and jwks_uri. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with RFC 8414 metadata. - id: oauth2 conforms: true evidence: >- authorization_endpoint + token_endpoint published; grant_types_supported includes authorization_code, client_credentials and refresh_token. - id: rfc7517-jwks conforms: true evidence: /.well-known/jwks.json returns 200 with a JSON Web Key Set. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = [S256, plain] caveat: >- "plain" is advertised alongside S256; OAuth 2.1 requires S256 for public clients. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint = https://auth.tegus.com/oidc/register - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint published; device_code grant advertised. - id: rfc8693-token-exchange conforms: true evidence: grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported = [ES256] - id: oidc-backchannel-logout-1.0 conforms: true evidence: backchannel_logout_supported = true, backchannel_logout_session_supported = true - id: ciba-client-initiated-backchannel-authentication conforms: true evidence: backchannel_authentication_endpoint published; delivery mode "poll" - id: oauth-2.1 conforms: false evidence: >- The implicit grant and the resource-owner password grant are still advertised in grant_types_supported, and "plain" PKCE is still allowed. OAuth 2.1 removes all three. - id: fapi-2.0 conforms: false evidence: >- No mTLS / certificate-bound tokens, no PAR (pushed authorization requests), and request_parameter_supported = false. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every tegus.com host probed. - id: rfc8615-well-known-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: openapi conforms: unknown evidence: >- No OpenAPI document found at any tegus.com host. The former developer hub tegus.readme.io 302s to /inactive and api.tegus.com does not resolve. - id: asyncapi conforms: unknown evidence: No event, webhook or streaming surface is published under the tegus.com brand. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 on auth.tegus.com, www.tegus.com and tegus.com. x-evidence: fetched: '2026-08-05' probes: - url: https://auth.tegus.com/.well-known/openid-configuration status: 200 - url: https://auth.tegus.com/.well-known/oauth-authorization-server status: 200 - url: https://auth.tegus.com/.well-known/jwks.json status: 200 - url: https://auth.tegus.com/.well-known/security.txt status: 404 - url: https://auth.tegus.com/.well-known/api-catalog status: 404