Discovery

✗ C101 Discovers the server from an HTML link The sign-in did not complete.
✗ C102 Discovers the server from a Link header Your client did not finish a valid sign-in.
✗ C103 Prefers the Link header over HTML Your client did not finish a valid sign-in.
· C104 Uses the first HTML link
· C105 Resolves a relative metadata URL
· C106 Follows redirects during discovery
· C107 Handles multiple rel values
· C108 Supports legacy endpoint discovery
✗ C109 Prefers metadata over legacy links Your client did not finish a valid sign-in.
· C110 Uses endpoints on another host
· C111 Accepts a URL typed without a scheme
· C112 Ignores a metadata link in the page body

Authorization requests

✓ C201 Requests an authorization code response_type is "code".
✓ C202 Sends a valid client_id client_id is valid.
✓ C203 Uses an allowed redirect_uri redirect_uri is allowed for the client_id.
✓ C204 Sends an unguessable state state is present and unique.
✓ C205 Uses PKCE with S256 PKCE with S256 is used.
✓ C206 Uses a new PKCE challenge each time A new code_challenge was used.
✓ C207 Sends the me parameter me was sent.
✓ C208 Publishes client metadata A client metadata document was published for "Home Cloud - Turner".
✗ C209 client_uri is a prefix of client_id client_uri is not a prefix of client_id.
✓ C210 Requests valid scopes Scopes are valid: profile+oauth+indieauth

Authorization responses

✓ C301 Rejects a mismatched state Your client did not redeem the code.
✓ C302 Rejects a response without iss Your client did not redeem the code.
✓ C303 Rejects iss from another issuer Your client did not redeem the code.
✓ C304 Compares iss exactly Your client did not redeem the code.
✓ C305 Handles an error response Your client handled the error response.
✓ C306 Rejects an unsolicited response Your client did not redeem the code.
✓ C307 Does not accept a replayed response Your client did not accept the replayed response.

Redemption and identity

✓ C401 Redeems the code correctly The code redemption request was correct.
✗ C402 Verifies a different me on the same domain Your client did not finish a valid sign-in.
· C403 Rejects a me that uses another server
· C404 Accepts a me on another domain that uses this server
· C405 Accepts a me seen during discovery redirects
· C406 Rejects a response without me
· C407 Rejects an invalid me
· C408 Does not trust profile information for identity
· C409 Handles a token endpoint error
· C410 Where sign-in-only codes are redeemed

Tokens

· C501 Sends access tokens in the Authorization header
· C502 Refreshes expiring tokens
· C503 Replaces rotated refresh tokens
· C504 Does not ask for more scope on refresh
· C505 Revokes tokens on sign-out