generated: '2026-08-30' method: probed source: https://thepicklr.com/.well-known/ + live probes of https://thepicklr.com/wp-json/ name: The Picklr — standards conformance description: >- Cross-cutting standards this deployment demonstrably implements, each with the exact location that proves it. The OAuth/MCP metadata cluster is genuinely strong for a consumer franchise site — dynamic registration, PKCE-only, RFC 9728 resource metadata — because it ships with the Novamira WordPress plugin rather than because the company designed an API programme. Claims are only recorded where a served document establishes them. standards: - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: url: https://thepicklr.com/.well-known/oauth-authorization-server status: 200 detail: 'Serves issuer, authorization_endpoint, token_endpoint, grant_types_supported, code_challenge_methods_supported, scopes_supported.' - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: url: https://thepicklr.com/.well-known/oauth-protected-resource status: 200 detail: 'Serves resource, authorization_servers, bearer_methods_supported, scopes_supported.' - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: url: https://thepicklr.com/wp-json/novamira/v1/oauth/register status: 200 detail: registration_endpoint advertised in the authorization server metadata; route present in the public REST route index. - id: rfc7636 name: PKCE conforms: true evidence: url: https://thepicklr.com/.well-known/oauth-authorization-server status: 200 detail: 'code_challenge_methods_supported is ["S256"] only — plain is not offered.' - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: true evidence: url: https://thepicklr.com/wp-json/novamira/v1/oauth/revoke status: 200 detail: revocation_endpoint advertised; route present in the public REST route index. - id: rfc7662 name: OAuth 2.0 Token Introspection conforms: true evidence: url: https://thepicklr.com/wp-json/novamira/v1/oauth/introspect status: 200 detail: introspection_endpoint advertised; route present in the public REST route index. - id: rfc8628 name: OAuth 2.0 Device Authorization Grant conforms: true evidence: url: https://thepicklr.com/.well-known/oauth-authorization-server status: 200 detail: 'grant_types_supported includes urn:ietf:params:oauth:grant-type:device_code; device_authorization_endpoint published.' - id: mcp name: Model Context Protocol conforms: true evidence: url: https://thepicklr.com/wp-json/mcp status: 200 detail: >- Three MCP server endpoints registered under the mcp REST namespace; the OAuth-gated one is named as the protected resource. Server software identifies as Novamira 1.11.4 with the WordPress MCP adapter. tools/list is 401-gated so the tool set was not enumerated. - id: llmstxt name: llms.txt conforms: true evidence: url: https://thepicklr.com/llms.txt status: 200 detail: 'Well-formed llms.txt: H1 title, blockquote summary, sectioned link lists with descriptions, an Optional section.' - id: rfc8288 name: Web Linking conforms: true evidence: url: https://thepicklr.com/wp-json/wp/v2/posts?per_page=1 status: 200 detail: 'Link header carries rel="next" for collection pagination.' - id: oidc name: OpenID Connect Discovery conforms: false evidence: url: https://thepicklr.com/.well-known/openid-configuration status: 200 detail: >- The path is served but the body is byte-identical to the OAuth 2.0 metadata document. It omits jwks_uri, userinfo_endpoint, subject_types_supported and id_token_signing_alg_values_supported, all REQUIRED by OpenID Connect Discovery 1.0. This is OAuth metadata at the OIDC path, not an OpenID Provider. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: url: https://thepicklr.com/wp-json/mcp/novamira status: 401 detail: 'Errors use the WordPress envelope {code,message,data.status}, not application/problem+json.' - id: rfc9116 name: security.txt conforms: false evidence: url: https://thepicklr.com/.well-known/security.txt status: 404 detail: Not served. - id: rfc9727 name: API Catalog well-known URI conforms: false evidence: url: https://thepicklr.com/.well-known/api-catalog status: 404 detail: Not served. - id: a2a name: A2A Agent Card conforms: false evidence: url: https://thepicklr.com/.well-known/agent-card.json status: 404 detail: Not served at the canonical path, and /.well-known/agent.json is also 404. domain_standard: applicable: false note: >- Indoor pickleball club franchising has no machine-readable domain interchange standard. DUPR ratings are referenced in Picklr league material as a player-rating service, but no DUPR identifier scheme, schema or endpoint appears anywhere in this deployment's contract, so no domain-standard conformance is asserted. Reward-only: the absence is not a defect. compliance_certifications: [] compliance_note: >- No trust center, SOC 2, ISO 27001, PCI or HIPAA attestation is published on thepicklr.com. trust.thepicklr.com does not resolve and /security/ returns 404.