generated: '2026-09-09' method: searched source: live well-known probes (2026-09-09), https://transcriptfetch.com/docs, https://transcriptfetch.com/security, well-known/transcriptfetch-mcp-server-card.json conformance: - id: oauth2-authorization-server-metadata-rfc8414 conforms: true evidence: https://transcriptfetch.com/.well-known/oauth-authorization-server (200) and https://clerk.transcriptfetch.com/.well-known/oauth-authorization-server (200), issuer clerk.transcriptfetch.com, dynamic client registration endpoint present. - id: oauth2-protected-resource-metadata-rfc9728 conforms: true evidence: https://transcriptfetch.com/.well-known/oauth-protected-resource (200) naming resource https://transcriptfetch.com/mcp and its authorization server. - id: oidc-discovery conforms: true evidence: https://transcriptfetch.com/.well-known/openid-configuration and clerk.transcriptfetch.com equivalent (both 200), RS256, jwks_uri served. - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported [S256] in both authorization-server metadata documents. - id: security-txt-rfc9116 conforms: true evidence: https://transcriptfetch.com/.well-known/security.txt (200) with Contact, Policy, Canonical, Expires 2027-07-27. - id: mcp conforms: true evidence: >- Hosted streamable-http MCP server at https://transcriptfetch.com/mcp; public server card at /.well-known/mcp/server-card.json with typed input/output schemas and tool annotations; supports protocol revision 2025-11-25; listed active in the official MCP Registry as com.transcriptfetch/youtube-transcripts. - id: idempotency conforms: true evidence: Idempotency-Key header with 24h replay and 409 conflict semantics, documented at https://transcriptfetch.com/docs/pagination. - id: pagination-cursor conforms: true evidence: Opaque cursor/next_cursor pagination on all list endpoints, https://transcriptfetch.com/docs/pagination. - id: rate-limit-headers conforms: true evidence: X-RateLimit-Limit/Remaining/Reset and Retry-After documented at https://transcriptfetch.com/docs/rate-limits (legacy X- prefix, not the draft RateLimit- fields). - id: deprecation-header-rfc8594 conforms: true evidence: Versioning policy commits to a Deprecation response header on retired endpoints and v1 responses carry a Link successor-version header, https://transcriptfetch.com/docs/v1. - id: rfc9457 conforms: false evidence: Errors use a custom { ok, request_id, error } envelope with stable code+number, not application/problem+json (https://transcriptfetch.com/docs/errors). - id: csa-star-caiq-v4 conforms: true evidence: Level 1 CAIQ v4 self-assessment published at https://cloudsecurityalliance.org/star/registry/transcriptfetch (200); all 261 CCM questions answered. Self-assessment, not a certification. - id: soc2 conforms: false evidence: Explicitly disclaimed on https://transcriptfetch.com/security ("not currently SOC 2 or ISO 27001 certified"). - id: iso27001 conforms: false evidence: Explicitly disclaimed on https://transcriptfetch.com/security. domain_standard: note: >- No sector schema standard exists for the transcript/speech-to-text market (no equivalent of SCIM/OData/OpenRTB here). The closest domain contracts are the MCP protocol conformance and typed tool schemas recorded above; reward-only, no conformance invented.