generated: '2026-08-05' method: searched source: https://auth.share.vendia.com/.well-known/oauth-authorization-server docs: - https://www.vendia.com/legal/security-policy/ - https://docs.vendia.com/platform/vendia-mcp-server/authentication/ standards: - id: oauth2 conforms: true evidence: >- Live authorization server at https://auth.share.vendia.com with /authorize, /token, /revoke and /register endpoints; authorization_code, refresh_token and client_credentials grants advertised. source: well-known/vendia-oauth-authorization-server.json - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: '/.well-known/oauth-authorization-server returns 200 application/json with issuer, authorization_endpoint, token_endpoint, jwks_uri.' source: well-known/vendia-oauth-authorization-server.json - id: oidc-discovery conforms: true evidence: '/.well-known/openid-configuration returns 200; id_token_signing_alg_values_supported RS256; scopes_supported openid, profile, email.' source: well-known/vendia-openid-configuration.json - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: ["S256"]' source: well-known/vendia-oauth-authorization-server.json - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://auth.share.vendia.com/register advertised in discovery.' source: well-known/vendia-oauth-authorization-server.json - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint: https://auth.share.vendia.com/revoke advertised in discovery.' source: well-known/vendia-oauth-authorization-server.json - id: rfc7517-jwks conforms: true evidence: '/.well-known/jwks.json returns 200 with an RS256 signing key.' source: well-known/vendia-jwks.json - id: mcp-authorization conforms: true evidence: >- Vendia states the MCP Gateway "fully supports the MCP authorization specification for interoperable, secure access control", and ships the OAuth server that backs it. source: https://docs.vendia.com/platform/vendia-mcp-server/overview/ - id: model-context-protocol conforms: true evidence: >- Managed remote MCP server; documented for Claude Desktop/Web custom connectors, ChatGPT connectors and Mistral Le Chat, with an mcp-remote legacy proxy path. source: https://docs.vendia.com/platform/vendia-mcp-server/getting-started/ - id: graphql conforms: true evidence: 'Per-project generated GraphQL API with queries, mutations and WebSocket subscriptions.' source: https://docs.vendia.com/platform/operational/scalar-data/graphql/ - id: openapi conforms: false evidence: >- Vendia CONSUMES OpenAPI 3.x and Swagger 2.0 (API Catalogs ingest customer specs) but publishes no OpenAPI for its own APIs. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on api.share.vendia.com (all 403) and on docs.vendia.com (all 404). - id: asyncapi conforms: false evidence: 'No AsyncAPI document published; the event surface is documented prose (see asyncapi/vendia-notifications-webhooks.yml).' - id: rfc9457-problem-details conforms: false evidence: 'Errors surface as the GraphQL errors array; no application/problem+json.' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on www.vendia.com and docs.vendia.com, 403 on auth.share.vendia.com.' - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on every Vendia host; 404 on www.vendia.com and docs.vendia.com, 403 on auth.share.vendia.com, and SPA catch-all HTML (rejected) on share.vendia.net. - id: rfc8594-sunset-header conforms: false evidence: 'No deprecation policy or Sunset/Deprecation header support documented.' compliance: published: true page: https://www.vendia.com/legal/security-policy/ certifications: - name: SOC 2 url: https://www.vendia.com/security/soc2 status: 200 - name: SOC 3 url: https://www.vendia.com/security/soc3 status: 200 note: >- SOC 2 and SOC 3 are the only certifications Vendia names on its public security policy. ISO 27001, PCI DSS, HIPAA and FedRAMP are NOT claimed. The security policy references a Data Processing Agreement and data-privacy-law compliance without naming a certification. No trust center (trust.vendia.com / security.vendia.com) was found — the probe returned no hit, so no trust-center artifact was written. x-evidence: fetched: '2026-08-05' probes: - url: https://auth.share.vendia.com/.well-known/oauth-authorization-server status: 200 - url: https://www.vendia.com/security/soc2 status: 200 - url: https://www.vendia.com/security/soc3 status: 200 - url: https://api.share.vendia.com/openapi.json status: 403 - url: https://docs.vendia.com/openapi.json status: 404