| ✓ | cimd-document-hosted | If the CIMD path was taken, the AS fetched the hosted document successfully |
| ✓ | cimd-document-shape | If the CIMD path was taken, the document carried the required properties |
| ✓ | cimd-client-id-match | If the CIMD path was taken, the document's client_id matched its URL exactly |
| ✓ | pkce | S256 code_challenge on authorize; matching code_verifier at token |
| ✓ | resource-indicator | Included RFC 8707 resource=<canonical server URI> in both requests |
| ✓ | bearer-token | All post-grant accepted MCP requests carried Authorization: Bearer; the token never appeared in a URL |
| ✓ | authorized-tool-call | Successfully called get_secret_number once authorized |