generated: '2026-08-13' method: searched source: >- live probes of my.yoast.com and yoast.com plus developer.yoast.com feature documentation, reconciled against the OpenAPIs in openapi/ note: >- Yoast's conformance profile is lopsided in an interesting way. Its identity stack on my.yoast.com is genuinely modern — OIDC with PKCE, dynamic client registration and DPoP sender-constrained tokens, all verifiable from the discovery document. Its content stack conforms hard to the web/search standards that are Yoast's actual product: Schema.org, JSON-LD, sitemaps, IndexNow, llms.txt. What is missing is the API layer in between: no published OpenAPI, no RFC 9457 problem details, no AsyncAPI, no MCP, no A2A agent card. standards: # --- identity / authorization --- - id: oidc-core name: OpenID Connect Core 1.0 conforms: true evidence: >- https://my.yoast.com/.well-known/openid-configuration returns 200 with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri and id_token_signing_alg_values_supported - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: discovery document served at the standard /.well-known/openid-configuration path - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: 'grant_types_supported: authorization_code, refresh_token, client_credentials' - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: [S256]; `wp yoast auth authorize` documents authorization code flow with PKCE' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: 'registration_endpoint https://my.yoast.com/api/oauth/reg; `wp yoast auth register` documented as DCR' - id: rfc9449-dpop name: OAuth 2.0 DPoP (RFC 9449) conforms: true evidence: 'dpop_signing_alg_values_supported: [ES256, EdDSA]; `wp yoast auth rotate-keys` rotates DPoP proof keys' - id: rfc7662-token-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint https://my.yoast.com/api/oauth/token/introspection - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: revocation_endpoint https://my.yoast.com/api/oauth/token/revocation - id: rfc8414-oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: >- /.well-known/oauth-authorization-server returns 404 on my.yoast.com; only the OIDC discovery path is served - id: rfc7617-basic-auth name: HTTP Basic authentication (RFC 7617) conforms: true evidence: MyYoast Provisioning API securityScheme type http scheme basic # --- security disclosure --- - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: true evidence: >- https://yoast.com/.well-known/security.txt returns 200 with Contact, Expires, Policy, Preferred-Languages and Canonical fields # --- content / search standards (Yoast's core product) --- - id: schema-org name: Schema.org structured data conforms: true evidence: >- Yoast emits a Schema.org @graph per page and documents 20+ schema pieces; the Schema Aggregator API serves a whole site's graph as JSON-L - id: json-ld name: JSON-LD 1.1 conforms: true evidence: Schema output is JSON-LD; json-ld/yoast-context.jsonld in this repo - id: sitemaps-xml name: sitemaps.org XML sitemap protocol conforms: true evidence: Yoast SEO generates XML sitemaps and an XML "schemamap" on the same pattern - id: indexnow name: IndexNow conforms: true evidence: >- https://developer.yoast.com/features/integrations/indexnow/ documents pinging an IndexNow endpoint on content create/update; the endpoint, payload and key-file mechanics are marked Pending in Yoast's own docs - id: llms-txt name: llms.txt conforms: true evidence: https://yoast.com/llms.txt returns 200 with a structured llms.txt document - id: robots-x-robots-tag name: X-Robots-Tag response header conforms: true evidence: >- Yoast sends x-robots-tag "noindex, follow" on XML sitemaps and XMLRPC, and x-redirected-by on redirects it performs # --- API-layer standards that are absent --- - id: openapi name: OpenAPI conforms: false evidence: >- Yoast publishes no OpenAPI on any host; every spec in openapi/ is derived by API Evangelist from Yoast's docs or from Yoast's own generated API client - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- errors use the WordPress REST envelope {code, message, data:{status}}, not application/problem+json - id: rfc8594-sunset-header name: Sunset HTTP header (RFC 8594) conforms: false evidence: no Sunset or Deprecation header documented; deprecations are announced in release notes - id: asyncapi name: AsyncAPI conforms: false evidence: Yoast documents no webhook or event surface, so there is nothing to describe - id: mcp name: Model Context Protocol conforms: false evidence: >- no first-party MCP server; Yoast's agent bet is the WordPress Abilities API, which third-party MCP bridges then expose - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on yoast.com, developer.yoast.com and my.yoast.com - id: wordpress-abilities-api name: WordPress Abilities API (WordPress 6.9) conforms: true evidence: >- Yoast SEO registers yoast-seo/get-seo-scores, yoast-seo/get-readability-scores and yoast-seo/get-inclusive-language-scores, discoverable at /wp-json/wp-abilities/v1/abilities?category=yoast-seo certifications: published: false note: >- Yoast publishes no trust center and names no certifications (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP). The security program page documents a bug bounty but no audit or attestation. No `Compliance` pointer is emitted for this provider, because there is no published compliance program to point at. counts: asserted: 22 conforming: 16 not_conforming: 6