generated: '2026-07-25' method: searched source: live probes of https://apis.vitality.co.uk on 2026-07-25 plus the published OpenID Connect discovery document note: >- Conformance here is asserted only from what Vitality exposes anonymously. The identity layer is unusually well evidenced for a partner-gated carrier; the API contract layer is entirely absent. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: live token endpoint at https://apis.vitality.co.uk/oauth2/token returning RFC 6749 error bodies (invalid_client, invalid_request); authorization endpoint returns a 302 to the WSO2 OAuth error page for malformed requests - id: oidc-core name: OpenID Connect Core 1.0 conforms: true evidence: id_token_signing_alg_values_supported RS256, userinfo endpoint, claims_supported, subject_types public - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: 200 at /oauth2/token/.well-known/openid-configuration and /oauth2/oidcdiscovery/.well-known/openid-configuration caveat: served at the WSO2 Identity Server path, not at the RFC 8615 host root - id: oidc-session-management name: OpenID Connect Session Management / Back-Channel Logout conforms: true evidence: check_session_iframe (200) and end_session_endpoint (302) are live; backchannel_logout_supported true - id: rfc7517-jwks name: JSON Web Key Set (RFC 7517) conforms: true evidence: 200 at https://apis.vitality.co.uk/oauth2/jwks with one RS256 key - id: rfc7636-pkce name: Proof Key for Code Exchange (RFC 7636) conforms: true evidence: code_challenge_methods_supported [S256, plain] - id: rfc7662-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint advertised; gateway route returns 401 to unauthenticated callers - id: rfc7009-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: revocation_endpoint advertised; gateway route returns 405 on GET - id: rfc8628-device-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: device_authorization_endpoint advertised and urn:ietf:params:oauth:grant-type:device_code in grant_types_supported - id: rfc7523-jwt-bearer name: JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants conforms: true evidence: urn:ietf:params:oauth:grant-type:jwt-bearer in grant_types_supported - id: rfc7522-saml2-bearer name: SAML 2.0 Profile for OAuth 2.0 Authorization Grants conforms: true evidence: urn:ietf:params:oauth:grant-type:saml2-bearer in grant_types_supported - id: rfc7591-dcr name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: false evidence: registration_endpoint is advertised in discovery but /api/identity/oauth2/dcr/v1.1/register returns the WSO2 404 fault through the public gateway — registration is not reachable anonymously - id: rfc8414-as-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: /.well-known/oauth-authorization-server returns 404 - id: rfc9728-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: false evidence: /.well-known/oauth-protected-resource returns 404 - id: fapi name: Financial-grade API (FAPI 1.0/2.0) conforms: false evidence: token_endpoint_auth_methods_supported is limited to client_secret_basic and client_secret_post — no private_key_jwt, no tls_client_auth, no mTLS-bound tokens, and the legacy password grant is still enabled - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: 404 on the gateway; the corporate host is Cloudflare-gated (403) so absence there is unconfirmed - id: rfc9727-api-catalog name: /.well-known/api-catalog (RFC 9727) conforms: false evidence: 404 on the gateway - id: openapi name: OpenAPI Specification conforms: false evidence: no OpenAPI/Swagger document is published on any reachable host - id: asyncapi name: AsyncAPI conforms: false evidence: no event catalogue, webhook documentation or AsyncAPI definition - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: gateway errors are the vendor WSO2 XML document and WSO2 JSON error envelopes, not application/problem+json - id: graphql name: GraphQL conforms: partial evidence: https://cd.wc.vitality.co.uk/sitecore/api/graph/edge is a live Sitecore Experience Edge GraphQL endpoint referenced by Vitality's own Workplace Connect application; introspection is gated ("SSC API key is required. Pass with 'sc_apikey' query string or HTTP header."). This is a CMS content-delivery surface, not an insurance API. - id: acord name: ACORD standards (AL3, ACORD XML, NGDS) conforms: false evidence: no ACORD reference found on any reachable Vitality surface; consistent with UK retail health-and-protection distribution, where ACORD adoption is concentrated in the London subscription market compliance_program: published: false note: No trust centre, no SOC 2 / ISO 27001 / PCI DSS certification page and no named certifications could be retrieved. www.vitality.co.uk/legal/ is titled "Legal and Security" but is behind Cloudflare bot protection (403), so its contents could not be verified. No Compliance pointer is emitted.