Third-party verification
Independently checked.
In August 2026 the OpenID Foundation conformance suite ran against this provider. Not a self-assessment: the official test rig, pointed at the live deployment.
38 of 39 passed
The discovery profile (Config OP) validated the provider's metadata and published keys, including that the key set exposes no private material and that every advertised endpoint resolves.
The one miss: RS256
The suite expects RS256 to be offered. This provider signs with ES256 only; that's a deliberate choice recorded in the project docs, not a defect. RSA is FIPS-approved, so it can change if a deployment ever needs it.
The profile that couldn't run
Basic OP sends no PKCE challenge, and this provider requires PKCE on every flow, per modern security guidance. Too strict to test against a profile written before PKCE was mandatory.
This was a test run, not certification. Formal certification is a paid submission to the OpenID Foundation, and nothing here claims it. The full log and methodology are in the project repository for engineers who want receipts.