{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-RFC9700-04-v1",
  "record_kind": "external_reference",
  "title": "OAuth: Server metadata scope",
  "system": "OAuth 2.0 Security",
  "evidence_family": "identity_access",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does OAuth server metadata prove the deployment is correctly configured?",
  "near_questions": [
    "What does OAuth authorization server metadata provide?",
    "Can advertised features differ from enforced behavior?",
    "Why retain the issuer when reviewing metadata?",
    "Does automatic configuration eliminate all misconfiguration?",
    "What evidence connects metadata to the intended server?",
    "Should an agent recheck cached OAuth metadata?",
    "Can a metadata document certify a login flow?",
    "How should a receipt identify a metadata snapshot?",
    "Does publishing endpoints establish permission to use them?",
    "Which client behavior matters when metadata changes?",
    "What remains unverified after discovering an OAuth server?",
    "Can metadata availability replace integration checks?"
  ],
  "supported_claims": [
    {
      "claim": "RFC 9700 recommends publishing authorization server metadata and using it where available. Metadata supports configuration but does not prove that advertised controls are correctly enforced.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "correct enforcement of advertised features",
    "trusted configuration without issuer checks",
    "complete deployment validation"
  ],
  "public_summary": "RFC 9700 recommends publishing authorization server metadata and using it where available. Metadata supports configuration but does not prove that advertised controls are correctly enforced.",
  "related_record_ids": [
    "VXI-EXT-RFC9700-01-v1",
    "VXI-EXT-RFC9700-02-v1",
    "VXI-EXT-RFC9700-03-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "RFC 9700: Other Recommendations",
    "source_url": "https://www.rfc-editor.org/rfc/rfc9700.html#section-2.6",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-RFC9700-04-v1",
    "candidate_record_sha256": "5d7abb0389654d6d9f4aad1785f22acbf932bbc70c5cf1a2ec29379877b1a399",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "RFC 9700 recommends publishing authorization server metadata and using it where available. Metadata supports configuration but does not prove that advertised controls are correctly enforced.",
    "required_buyer_context": "The intended issuer, metadata version or retrieval date and the client's configuration behavior.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#oauth-server-metadata",
  "machine_readable_record": "/varexis-index/records/oauth-server-metadata.json"
}
