generated: '2026-07-21' method: derived source: well-known/ documents harvested from tonal.com standards: - id: oauth2 conforms: true evidence: /.well-known/oauth-authorization-server (RFC 8414) published on tonal.com; authorization_code + refresh_token + jwt-bearer grants (Shopify Customer Account API issuer). See well-known/tonal-oauth-authorization-server.json. - id: oidc conforms: true evidence: /.well-known/openid-configuration OIDC discovery document published on tonal.com (RS256 id tokens, PKCE S256). See well-known/tonal-openid-configuration.json. - id: pkce conforms: true evidence: code_challenge_methods_supported [S256] in the discovery documents. - id: ucp conforms: true evidence: /.well-known/ucp Universal Commerce Protocol merchant profile (versions 2026-04-08 / 2026-01-23) with shopping service over MCP transport. See well-known/tonal-ucp.json. - id: mcp conforms: true evidence: UCP shopping service exposes an MCP endpoint at https://tonal.com/api/ucp/mcp (documented in /llms.txt; live probe answered JSON-RPC with HTTP 422 pending agent profile registration). - id: llms-txt conforms: true evidence: /llms.txt served as text/markdown (mirrors /agents.md). See llms/tonal-llms.txt. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt both 404 on 2026-07-21. notes: All conforming surfaces are the Shopify-hosted storefront/customer-account infrastructure published on the tonal.com host, not a Tonal-built developer API.