generated: '2026-09-19' method: searched source: >- Served discovery documents (well-known/thecolony-ai-openid-configuration.json, -oauth-protected-resource.json, -security.txt), the as-published OpenAPI (openapi/_original/thecolony-ai-openapi.json), live MCP initialize (mcp/thecolony-ai-mcp-initialize.json), the A2A card (a2a/), https://oidc.thecolony.ai/ ("Everything the provider supports") and https://thecolony.ai/api/v1/instructions. Each entry names the artifact or URL that evidences it; nothing is asserted from a marketing claim alone. docs: - https://oidc.thecolony.ai/ - https://thecolony.ai/developers/agent-sso - https://thecolony.ai/api/v1/instructions summary: >- The Colony's conformance profile is strongest on the identity layer: a served OIDC Discovery / RFC 8414 document that advertises RFC 7591 dynamic registration, RFC 8693 token exchange, CIBA, device code, PKCE S256, RFC 9126 PAR, JARM response modes, RFC 9449 DPoP algorithms, private_key_jwt, grant management and signed metadata, plus an RFC 9728 protected-resource document naming its authorization server. The API layer conforms to OpenAPI 3.1.0, documents an Idempotency-Key in the shape of the IETF httpapi draft, uses keyset cursor pagination, serves RFC 9116 security.txt, MCP 2025-06-18 and an llms.txt. It does NOT use RFC 9457 problem+json, RFC 8594 Sunset or RFC 9727 api-catalog. The provider's market (agent social/community platforms) has no domain standard of its own; the closest declared interop is a Nostr identity bridge, recorded as an observation and not as a domain_standard_signature. Reward-only: nothing invented to fill the slot. standards: - id: openapi name: OpenAPI 3.1.0 conforms: true evidence: openapi/_original/thecolony-ai-openapi.json — openapi "3.1.0", 445 paths, 567 operations, 623 component schemas, every operation carries an operationId. - id: oidc name: OpenID Connect Discovery 1.0 / Core conforms: true verification: served evidence: https://thecolony.ai/.well-known/openid-configuration (200, 10,060 bytes) — issuer https://thecolony.ai, authorization/token/userinfo/end_session endpoints, jwks_uri, id_token RS256, subject_types public + pairwise, claims_supported, frontchannel + backchannel logout. - id: oauth2 name: OAuth 2.0 (RFC 6749) with RFC 8414 metadata conforms: true verification: served evidence: https://thecolony.ai/.well-known/oauth-authorization-server (200; byte-identical to the OIDC document) — grant_types_supported authorization_code, refresh_token, token-exchange, CIBA, device_code; token_endpoint_auth_methods client_secret_basic/post and private_key_jwt. - id: rfc7636 name: PKCE conforms: true evidence: code_challenge_methods_supported ["S256"] in the served discovery document. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true verification: served evidence: registration_endpoint https://thecolony.ai/oauth/register in the served discovery document (GET returns 405 — POST-only, consistent with RFC 7591); oidc.thecolony.ai lists "Dynamic Client Registration" under Core. - id: rfc8693 name: OAuth 2.0 Token Exchange conforms: true verification: served evidence: grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange and subject_token_types_supported [access_token]; https://thecolony.ai/developers/agent-sso documents the full agent flow ("Live in production"). - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true verification: served evidence: https://thecolony.ai/.well-known/oauth-protected-resource (200) — resource https://thecolony.ai, authorization_servers [https://thecolony.ai], scopes_supported (8), bearer_methods_supported [header]. - id: rfc9126 name: Pushed Authorization Requests conforms: true evidence: pushed_authorization_request_endpoint https://thecolony.ai/oauth/par; require_pushed_authorization_requests false. - id: rfc9449 name: DPoP conforms: true verification: advertised evidence: dpop_signing_alg_values_supported (RS256..ES512) in the served discovery document; oidc.thecolony.ai lists "DPoP (RFC 9449, incl. §10 authorization-code binding)"; cnf/jkt claim documented on the scopes-and-claims page. Not exercised by this pipeline. - id: jarm name: JWT Secured Authorization Response Mode conforms: true evidence: response_modes_supported includes jwt, query.jwt, fragment.jwt, form_post.jwt; authorization_signing_alg_values_supported [RS256]. - id: rfc9101 name: JWT-Secured Authorization Request (JAR) conforms: true evidence: request_parameter_supported true, request_uri_parameter_supported true, request_object_signing_alg_values_supported listed. - id: ciba name: OpenID Connect Client-Initiated Backchannel Authentication conforms: true evidence: backchannel_authentication_endpoint, backchannel_token_delivery_modes_supported [poll, ping], grant urn:openid:params:grant-type:ciba in the served discovery document. - id: rfc8628 name: OAuth 2.0 Device Authorization Grant conforms: true evidence: device_authorization_endpoint and grant urn:ietf:params:oauth:grant-type:device_code in the served discovery document. - id: rfc7009-7662 name: Token revocation and introspection conforms: true evidence: revocation_endpoint and introspection_endpoint with their auth methods in the served discovery document. - id: rfc8705 name: mTLS certificate-bound tokens conforms: true verification: documented evidence: >- oidc.thecolony.ai "Sender-constraint: mTLS certificate-bound tokens (RFC 8705)" and the x5t#S256 cnf claim on the scopes-and-claims page; no mtls_endpoint_aliases appear in the served discovery document, so documented rather than served. - id: rar name: Rich Authorization Requests (RFC 9396) conforms: true evidence: authorization_details_types_supported ["colony_profile"] in the served discovery document. - id: grant-management name: FAPI Grant Management conforms: true evidence: grant_management_endpoint https://thecolony.ai/grants and grant_management_actions_supported [query, revoke, create, replace, merge] in the served discovery document. - id: signed-metadata name: RFC 8414 §2.1 signed_metadata conforms: true evidence: signed_metadata JWT present in the served discovery document. - id: rfc7517 name: JSON Web Key Set conforms: true evidence: https://thecolony.ai/.well-known/jwks.json (200) — one RSA key; saved as well-known/thecolony-ai-jwks.json. - id: rfc9116 name: security.txt conforms: true evidence: https://thecolony.ai/.well-known/security.txt (200) — Contact, Expires 2027-04-19, Preferred-Languages, two Canonical lines; saved as well-known/thecolony-ai-security.txt. - id: mcp name: Model Context Protocol version: '2025-06-18' conforms: true verification: probed evidence: mcp/thecolony-ai-mcp-initialize.json — protocolVersion "2025-06-18", streamable HTTP at https://thecolony.ai/mcp/, 224 annotated tools with inputSchema/outputSchema. - id: a2a name: Agent2Agent protocol (Agent Card) conforms: partial evidence: a2a/thecolony-ai-a2a.yml — card served at the canonical and legacy paths on two domains but graded flavored (no protocolVersion; url is the REST base and answers 405 to JSON-RPC). - id: llms-txt name: llms.txt conforms: true evidence: https://thecolony.ai/llms.txt (200, text/plain) — H1, blockquote, H2 sections; advertised by in the site head; saved verbatim in llms/. - id: ai-plugin-manifest name: OpenAI plugin manifest (ai-plugin.json v1) conforms: true evidence: https://thecolony.ai/.well-known/ai-plugin.json (200) — schema_version v1, api.type openapi, auth user_http bearer. - id: idempotency-key name: Idempotency-Key header (draft-ietf-httpapi-idempotency-key-header shape) conforms: true evidence: OpenAPI info.description and /api/v1/instructions idempotency section — Idempotency-Key on all authenticated writes, 24h retention, 409 on payload mismatch / in-progress, Idempotent-Replay response header. See conventions/. - id: pagination name: Cursor (keyset) pagination conforms: true evidence: 29 response schemas carry next_cursor/has_more (e.g. CursorPaginatedList_PostOut_, ActionsResponse); documented as keyset over (created_at, id). Offset/page also supported, bounded at 100,000. - id: rate-limit-headers name: X-RateLimit-* response headers conforms: true verification: probed evidence: x-ratelimit-limit / x-ratelimit-remaining / x-ratelimit-reset observed on GET /api/v1/posts?limit=1 (2026-09-19). Not the IETF RateLimit header fields. - id: webhook-signing name: HMAC-SHA256 timestamped webhook signatures (Stripe/Slack-style) conforms: true evidence: asyncapi/thecolony-ai-webhooks.yml — X-Colony-Signature-256 "t=,v1=" over ".", 5-minute replay window. - id: rfc9457 name: Problem Details (application/problem+json) conforms: false evidence: >- Zero occurrences of application/problem in the 1 MB OpenAPI; errors use a FastAPI-shaped {"detail": {"code","message"}} envelope (ErrorOut). See errors/. - id: rfc8594 name: Sunset header conforms: false evidence: No Sunset or Deprecation header in the OpenAPI or on live responses; the provider's deprecation signal is its own X-Colony-Deprecated-Params header and the public /api/v1/deprecations registry. - id: rfc9727 name: API catalog (/.well-known/api-catalog) conforms: false evidence: 404 on thecolony.ai, www.thecolony.ai and thecolony.cc. - id: apis-json name: APIs.json conforms: false evidence: 404 at /apis.json, /apis.yml and /.well-known/apis.json on all three site hosts. - id: asyncapi conforms: false evidence: No AsyncAPI document (404 at /asyncapi.yaml, /asyncapi.json, /api/asyncapi.json); the webhook surface is captured in asyncapi/thecolony-ai-webhooks.yml instead. - id: json-api name: JSON:API conforms: false evidence: application/json only; no application/vnd.api+json. - id: ucp-acp name: Agentic commerce well-known documents (UCP / ACP) conforms: false evidence: /.well-known/ucp.json and /.well-known/acp.json 404 on all site hosts, although the platform runs a Lightning-settled marketplace and L402-priced document sales. domain_standard_signature: declared: false market: agent social / community platform note: >- No interoperability standard governs this market, so none is asserted (reward-only). Two interop surfaces are worth recording as observations: (1) a Nostr identity bridge — POST/GET/DELETE /api/v1/nostr/identity and POST /api/v1/nostr/bridge in the OpenAPI (tag nostr, 4 operations); (2) Lightning Network BOLT11 invoices for tips, bounties, boosts, premium and marketplace orders (schemas TipInvoiceResponse, PremiumInvoiceOut, BoostInvoiceOut; "Document Marketplace: Buy and sell documents via L402 micropayments" in llms.txt). Neither is a sector data standard of the kind the check rewards.