generated: '2026-08-13' method: probed source: >- https://webloyalty.co.uk/.well-known/oauth-authorization-server, https://webloyalty.co.uk/.well-known/oauth-protected-resource, https://webloyalty.co.uk/wp-json/mcp note: >- Assertions here are read off documents Webloyalty actually serves, not off claims — the company makes no standards or compliance claims anywhere on its public site. Nothing is derived from an OpenAPI because none is published. standards: - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- https://webloyalty.co.uk/.well-known/oauth-authorization-server returns HTTP 200 application/json with issuer, authorization_endpoint, token_endpoint, revocation_endpoint, response_types_supported, grant_types_supported and scopes_supported. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://webloyalty.co.uk/.well-known/oauth-protected-resource returns HTTP 200 with resource, authorization_servers, bearer_methods_supported and scopes_supported. - id: rfc7636 name: PKCE (Proof Key for Code Exchange) conforms: true evidence: code_challenge_methods_supported = ["S256"] in the authorization-server metadata. - id: oauth2 name: OAuth 2.0 / 2.1 authorization code flow conforms: true evidence: >- grant_types_supported = [authorization_code, refresh_token], response_types_supported = [code], token_endpoint_auth_methods_supported = [none] (public clients) with PKCE mandatory — the OAuth 2.1 public-client shape. - id: mcp-authorization name: MCP Authorization (protected-resource discovery + OAuth public client) conforms: true evidence: >- Protected-resource metadata names an MCP resource and an authorization server; the resource returns HTTP 401 mcp_unauthorized to an unauthenticated tools/list, which is the specified challenge behaviour. - id: mcp name: Model Context Protocol (JSON-RPC transport) conforms: partial evidence: >- Two MCP servers are routed at /wp-json/mcp/* and answer JSON-RPC POSTs, but tools/list is auth-gated (HTTP 401), so protocol version, capabilities and tool schemas could not be verified anonymously. - id: openid-connect name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns HTTP 404 on every host. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Error bodies observed on the REST/MCP surface use the WordPress envelope {code, message, data.status}, not application/problem+json. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returns HTTP 404 on webloyalty.com and webloyalty.co.uk. certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published. The only regulatory content on the site is UK statutory: company registration (England No. 05922626), VAT GB 125 4954 08, a Modern Slavery Act anti-slavery statement and a Companies Act s.172 statement, at https://webloyalty.co.uk/regulatory/. These are statutory filings, not a compliance program, so no Compliance pointer is emitted.