api.dashboard.plaid.com
Generated by the Conformant public-subset battery and anchored to the Sigstore/Rekor transparency log. The grade below is tamper-evident: recompute the report’s canonical hash and compare it with the Rekor entry.
Spec 2026-07-28 readiness
Not determinable from the public probe. Credential-gated endpoints do not complete an unauthenticated handshake, so the negotiated revision cannot be read. This is a coverage limit, not a finding.
- RDY-01Transport generationcurrentStreamable HTTP: the transport the 2026-07-28 stateless core is built on.
- RDY-02Protocol revisionn/aRevision negotiation could not be observed.
- RDY-03Stateless corecurrentOperates without a session header, matching the 2026-07-28 stateless core.
- RDY-04Client registrationpartialExposes a Dynamic Client Registration endpoint and does not advertise CIMD support. DCR is deprecated with a window closing 2027-07-28, but CIMD advertisement is not yet consistently published, so this is reported as a migration item rather than a removal finding.
- RDY-05Cacheable tool catalogn/aTool catalog cache posture not observable.
- RDY-06Deprecated capabilitiesn/aCapability set not observable.
Readiness measures migration posture against the specification finalized 2026-07-28. It is reported separately because a well-authenticated server on deprecated transport is a migration risk, not a security defect — scoring both on one axis would misprice both. Signals that could not be evaluated are excluded from the score rather than counted as passing.
- Missing WWW-Authenticate challenge. The endpoint rejects anonymous calls but does not return a WWW-Authenticate header, so MCP clients cannot discover how to authenticate (MCP authorization spec requires it).
- No OAuth protected-resource metadata. /.well-known/oauth-protected-resource is not served. Clients cannot discover the authorization server per RFC 9728, forcing out-of-band setup.