Check your compatibility with CK SAaS
No request needed. Enter your public endpoints and press Check. We fetch your public metadata without keys (GET only) and show pass or fail against our published requirements.
What we publish
Our MCP Server
https://mcp.braas.dev/mcpOAuth 2.1 · PKCE S256 · scope
mcpmetadata
https://mcp.braas.dev/.well-known/oauth-protected-resourceOur Authorization Server
https://as.braas.devclient_id: CIMD URL or DCR
private_key_jwt (ES256 or RS256)
none + PKCE S256
Our MCP Client
https://mcp.braas.dev/client/metadata.jsonprivate_key_jwt · redirect
https://mcp.braas.dev/client/callbackJWKS
https://mcp.braas.dev/client/jwks.json1 · Check compatibility
A seal fixes the content and time of a result. It is not a certificate from CK SAaS. Anyone can ask whether this intake issued a given seal: GET /api/seal/<act_hash>.
We only GET fixed metadata paths (or your CIMD URL and its jwks_uri): https, public addresses only, no redirects followed, 5 s and 64 KB per fetch (16 KB for a CIMD document), at most 8 fetches. We never POST to a URL you type. We keep an anonymous count, nothing else.
2 · Request to partner (optional)
This opens a request with us: your details and proposed times. You get a private status page for questions and the agreed slot. Slack and email stay the official channels.
Who reads your contact details: only the CK SAaS operator, to arrange this session. We will confirm the request with you on Slack or email before any admission step. To have your record deleted, ask on your status page or by email; the operator deletes it by hand.
Your public endpoints (only the parts that apply; they are checked on submit)
Schedule
Logs
CK SAaS · Trothward. Governance is the product: this page grants nothing; admission is a signed act by CK SAaS.