generated: '2026-07-28' method: derived source: | Derived from artifacts harvested in this repo — the two WordPress REST discovery documents, the OPTIONS JSON Schemas, the RFC 8414 / RFC 9728 OAuth metadata, the observed error envelopes and the observed response headers — plus a search of wyndhamhotels.com, corporate.wyndhamhotels.com and wyndhambusiness.com for standards and compliance claims, 2026-07-28. note: | Wyndham Hotels & Resorts makes no API standards or certification claim anywhere on its public properties. Everything asserted true below is evidence-backed from a live probe; everything recorded false is genuinely absent rather than untested. The travel-specific rows are the point of this file: no OpenTravel/OTA, no HTNG, no NDC, no GDS connectivity contract published as anything other than chain codes printed in a marketing PDF. standards: - id: oauth2 conforms: true evidence: | Authorization code + refresh token grants, PKCE S256 required, published at https://www.wyndhambusiness.com/.well-known/oauth-authorization-server - id: oauth-2.1-public-client conforms: true evidence: | code_challenge_methods_supported=[S256], token_endpoint_auth_methods_supported=[none], client_id_metadata_document_supported=true — the OAuth 2.1 public-client profile. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns HTTP 200 JSON on www.wyndhambusiness.com. Captured at well-known/wyndham-hotels-wyndhambusiness-oauth-authorization-server.json - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: | /.well-known/oauth-protected-resource returns HTTP 200 JSON naming https://www.wyndhambusiness.com/wp-json/mcp/mcp-oauth-server, and the 401 from that resource carries a matching WWW-Authenticate: Bearer ... resource_metadata challenge. - id: mcp conforms: partial evidence: | Three WordPress MCP adapter routes are registered across two Wyndham WordPress estates and one is fully OAuth-protected with correct discovery metadata, but every anonymous JSON-RPC initialize / tools/list returns 401. Protocol support exists; it is not publicly exercisable. See mcp/wyndham-hotels-mcp.yml - id: openid-connect-discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on every Wyndham host. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 (or a non-document status) on every host probed. - id: rfc9457-problem-details conforms: false evidence: | Errors use the WordPress envelope {code, message, data.status} with content-type application/json, not application/problem+json. See errors/wyndham-hotels-problem-types.yml - id: json-schema conforms: true evidence: | HTTP OPTIONS on each wp/v2 collection returns a JSON Schema for the resource; eleven were harvested into json-schema/. - id: rfc8288-web-linking conforms: true evidence: 'Collection responses return Link: <...>; rel="next" and the discovery Link header rel="https://api.w.org/".' - id: rest-pagination-conventions conforms: true evidence: | page/per_page parameters with X-WP-Total, X-WP-TotalPages and RFC 8288 Link headers. See conventions/wyndham-hotels-conventions.yml - id: openapi conforms: false evidence: | No OpenAPI or Swagger document exists at any probed path on any host — /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs and /redoc were probed on wyndhamhotels.com, wyndhambusiness.com and mcp.wyndhamhotels.com. - id: asyncapi conforms: false evidence: no event, streaming or webhook surface exists on any Wyndham host. - id: webhooks conforms: false evidence: no webhook registration, catalogue or documentation exists. - id: graphql conforms: false evidence: /graphql and /wp-json/graphql return 404 on both WordPress estates. - id: grpc conforms: false evidence: no published .proto artifacts; the GitHub org has one unrelated Python repository. - id: rss-2.0 conforms: false evidence: /feed/ returns HTTP 500 on both WordPress estates; there is no working syndication feed. - id: sitemaps-xml conforms: true evidence: https://www.wyndhamhotels.com/sitemap.xml and https://www.wyndhambusiness.com/sitemap.xml both return 200. - id: llms-txt conforms: true evidence: | Three llms.txt documents are published and captured verbatim — the hand-authored brand document on www.wyndhamhotels.com and All in One SEO generated page indexes on development.wyndhamhotels.com and www.wyndhambusiness.com. None references an API, developer program, partner connectivity, GDS, Sabre or distribution. - id: idempotency conforms: false evidence: no idempotency key contract is documented or exhibited; no Idempotency pointer is emitted. - id: opentravel-ota conforms: false evidence: | No OpenTravel Alliance OTA message set, schema or conformance claim appears anywhere on Wyndham's public properties. - id: htng conforms: false evidence: no Hotel Technology Next Generation specification reference or certification claim is published. - id: iata-ndc conforms: false evidence: not applicable — hotel franchisor, not an airline. No NDC certification level is claimed and NDC is not referenced anywhere. - id: gds-chain-code-distribution conforms: partial evidence: | Wyndham distributes through GDS chain codes (master chain WR) and names them in its own TMC/Consortia PDF ("SEARCH IN THE GDS / CHAIN CODE: WG / MASTER CHAIN CODE: WR", "Rate is bookable through the GDS only"). This is real conformance to a shared industry identifier space, but Wyndham publishes no connectivity contract for it — the interface belongs to Sabre, Amadeus and Travelport. - id: fapi conforms: false evidence: | The MCP authorization server advertises no private_key_jwt, no PAR, no mTLS and no signed request objects — none of the FAPI security profile requirements. - id: fhir-r4 conforms: false evidence: not applicable — hotel franchisor, no health data exchange. compliance_program: published: false certifications: [] note: | No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim, no trust centre, and no vulnerability-disclosure program was found. probe-security-programs.py returned vdp=none trust=none on 2026-07-28. Because there is no published compliance program, no Compliance and no TrustCenter pointer is emitted for this provider. governance_posture: note: | Wyndham's only published governance statement about machine access is a prohibition. The Terms of Use effective 2026-03-12 forbid "any robot, spider, intelligent agent, meta-searching or other automatic device" and separately forbid accessing AI Search "through automated means (including scraping, bots, crawlers, or similar tools)". Meanwhile three MCP adapters and two anonymous WordPress REST APIs are live on the estate. The stated posture and the deployed posture do not agree, and neither is documented for partners. terms_of_use: https://www.wyndhamhotels.com/about-us/terms-of-use-more-info