{
  "url": "https://login.account.rakuten.com",
  "auditedAt": "2026-07-26T19:40:27.641Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Coverage-complete audit of the root redirect and its sole representative resource, the OIDC discovery document.",
  "page": {
    "appType": "unknown",
    "framework": "none",
    "notes": "The requested root redirects to /.well-known/openid-configuration (application/json). This is a protocol endpoint, not the Rakuten human sign-in form."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "discoverability",
    "evaluate-probe",
    "direct-http",
    "cookie-audit",
    "header-audit",
    "image-audit",
    "heap-summary",
    "Lighthouse (MIME-inapplicable)",
    "Modern Web Guidance 0.0.172"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Browser rendering of the OIDC JSON at 1440x1000.",
      "condition": "viewport: 1440x1000"
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Browser rendering at a narrow 360x800 capture.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Browser JSON viewer under a dark color-scheme preference; presentation is browser-owned.",
      "condition": "prefers-color-scheme: dark"
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered browser DOM confirming the final URL and application/json content."
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Narrow layout metrics: CLS 0 and no long tasks.",
      "condition": "viewport: 360x800"
    },
    {
      "type": "layout",
      "path": "evidence/layout-desktop.json",
      "caption": "Desktop layout metrics: CLS 0 and no long tasks.",
      "condition": "viewport: 1440x1000"
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw-crawler comparison; interpreted cautiously because content negotiation returned 406 while curl returned 200."
    },
    {
      "type": "other",
      "path": "evidence/http-recon.txt",
      "caption": "Direct HTTP headers, robots.txt, OIDC response headers, and 404 route evidence."
    },
    {
      "type": "other",
      "path": "evidence/http-timings.txt",
      "caption": "Five direct HTTP timing samples."
    },
    {
      "type": "other",
      "path": "evidence/performance-probe.json",
      "caption": "Navigation timing, transfer size, DOM size, and parsed OIDC fields."
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "DOM and authored-feature inventory."
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.json",
      "caption": "Single-state V8 heap summary for the static endpoint."
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Header primitive output for the initial redirect; final-response headers are in http-recon.txt."
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit identifying ODID as Secure/HttpOnly, SameSite=None, and long lived."
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image audit confirming zero images."
    },
    {
      "type": "other",
      "path": "evidence/guidance-list.json",
      "caption": "Pinned Modern Web Guidance catalog listing."
    },
    {
      "type": "other",
      "path": "evidence/guidance-consulted.ndjson",
      "caption": "Search/retrieve cache for every mapped check guidance pointer."
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse navigation record; category audits were unavailable because the final MIME type is application/json."
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Chromium renders the JSON representation with an injected color-scheme light dark declaration; preference screenshots and DOM inspection show a browser-adaptive native representation.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The endpoint has no authored scroll-linked motion, scroll listeners, or main-thread animation work, so scrolling the native representation does not use the prohibited custom pattern.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The standard OIDC key/value document presents the issuer and capability endpoints in a stable, linear native JSON representation without moving focus or hidden navigation state.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Load screenshots show only the requested JSON document, with no popup, banner, interstitial, or content obstruction.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Layout metrics at the narrow capture report zero horizontal overflow; the browser-owned JSON representation remains reachable by native scrolling.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "A GET to the root redirects to the standard /.well-known/openid-configuration path, whose valid JSON clearly identifies issuer, authorization, token, userinfo, keys, registration, revocation, and logout endpoints.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Five repeated root requests followed the single 302 and completed with HTTP 200 and a valid 1,779-byte OIDC configuration.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The discovery route returns 200 application/json; an unknown /sitemap.xml request returns an explicit HTTP 404 rather than a broken shell or misleading success.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The static representation has no layout shift or long tasks; five HTTP samples completed in 0.74-2.00 s and transfer only 1,779 decoded bytes.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Layout observers at 360x800 and 1440x1000 recorded CLS 0 with no shifts.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Both layout captures recorded zero long tasks; the endpoint ships no authored JavaScript.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The final response is HTTP/2, gzip encoded in-browser, cacheable for 86,400 seconds, and transfers about 984 encoded bytes in the navigation timing.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The application/json response ships no authored JavaScript or CSS; the only incidental request is the browser favicon lookup.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Desktop and mobile screenshots show the complete native monospace JSON text without authored clipping, overlap, or mixed-font instability.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.",
      "status": "not-applicable",
      "reason": "The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test."
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The static JSON loaded and was parsed successfully by repeated Runtime.evaluate probes; there is no authored script or uncaught application exception.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The audited resource is application/json, not an authored HTML document, and ships no images, CSS, or HTML assets.",
      "status": "not-applicable",
      "reason": "The audited resource is application/json, not an authored HTML document, and ships no images, CSS, or HTML assets."
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The response has no authored script, deprecated API use, prompt calls, input handlers, or client library surface.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.",
      "status": "not-applicable",
      "reason": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.",
      "status": "not-applicable",
      "reason": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The well-known OIDC resource has a stable standards-defined URL, returns HTTP 200, and robots.txt deliberately disallows this private authentication-infrastructure host rather than accidentally exposing it for indexing.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.",
      "status": "not-applicable",
      "reason": "This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "HTTPS and final-response HSTS/nosniff protections are present, but the public discovery response also sets a long-lived SameSite=None ODID cookie.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "issues",
      "findingIds": [
        "privacy-odid-cookie"
      ],
      "artifacts": [
        "evidence/http-recon.txt",
        "evidence/cookies.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Direct response headers set ODID with Secure, HttpOnly, SameSite=None and Max-Age=63072000 (about two years); the CDP cookie audit independently observed the cookie as SameSite=None and at least 400 days. The endpoint is public static metadata and the evidence does not show why a durable browser identifier is required.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "issues",
      "findingIds": [
        "privacy-odid-cookie"
      ],
      "artifacts": [
        "evidence/http-recon.txt",
        "evidence/cookies.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The metadata advertises authorization-code flow, PKCE S256, ES256/RS256 ID-token signing, and DPoP EdDSA; no browser permission is requested on load.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The final JSON response sends HSTS includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, and Referrer-Policy strict-origin. CSP is not materially needed for a nosniff application/json representation.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The core machine-readable content is the raw 200 application/json response and requires no JavaScript; curl parsed it directly.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The resource is static JSON with no authored browser runtime, menus, overlays, or asynchronous UI state.",
      "status": "not-applicable",
      "reason": "The resource is static JSON with no authored browser runtime, menus, overlays, or asynchronous UI state."
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "OIDC discovery is intrinsically an online identity-provider protocol endpoint, not an installable application.",
      "status": "not-applicable",
      "reason": "OIDC discovery is intrinsically an online identity-provider protocol endpoint, not an installable application."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The endpoint communicates success with 200 and an unknown path with 404; discovery responses are cacheable and do not depend on a fragile client shell.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The representation is locale-neutral JSON rather than rendered language or CSS layout.",
      "status": "not-applicable",
      "reason": "The representation is locale-neutral JSON rather than rendered language or CSS layout."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The JSON contains no locale-formatted dates or numbers and advertises 35 supported UI locale tags for downstream authorization clients.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The discovery representation contains no dates, local times, events, or time-zone calculations.",
      "status": "not-applicable",
      "reason": "The discovery representation contains no dates, local times, events, or time-zone calculations."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The machine-readable endpoint has no consent, upsell, cancellation, advertising, or human-facing choice UI.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "There is no human-facing form in this machine-readable discovery representation.",
      "status": "not-applicable",
      "reason": "There is no human-facing form in this machine-readable discovery representation."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "There are no human-facing inputs in this machine-readable discovery representation.",
      "status": "not-applicable",
      "reason": "There are no human-facing inputs in this machine-readable discovery representation."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "Published account protocol capabilities include end-session and revocation endpoints plus PKCE S256 and DPoP, supporting explicit termination and modern authorization safeguards.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The endpoint has zero images and only a small compressed JSON payload.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The load performs one redirect, one small first-party JSON request, and no background application work or fetch loop.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "No third-party script, font, image, audio, video, animation, or authored media is loaded.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "This is standardized OIDC metadata for authentication clients, not an AI-agent task surface where WebMCP tools or agentic forms are appropriate.",
      "status": "not-applicable",
      "reason": "This is standardized OIDC metadata for authentication clients, not an AI-agent task surface where WebMCP tools or agentic forms are appropriate."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The endpoint only publishes static OIDC metadata; there is no inference task for which an on-device model would improve the experience.",
      "status": "not-applicable",
      "reason": "The endpoint only publishes static OIDC metadata; there is no inference task for which an on-device model would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The endpoint has no authored interaction to repeat; fabricating one would not test a representative user action.",
      "status": "not-applicable",
      "reason": "The endpoint has no authored interaction to repeat; fabricating one would not test a representative user action."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The heap summary reports 26,537 nodes and 798,116 bytes total self size for the browser JSON view; the authored representation has only seven DOM elements.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "confidence": "high",
      "method": "Direct HTTP/browser evidence review",
      "evidence": "The single-state heap summary has no Detached* constructor among its reported populations, and the endpoint has no authored listeners, timers, or runtime interaction.",
      "pathIds": [
        "oidc-discovery"
      ],
      "status": "pass"
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "privacy-odid-cookie"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "This is standardized OIDC metadata for authentication clients, not an AI-agent task surface where WebMCP tools or agentic forms are appropriate."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "paths": [
    {
      "id": "oidc-discovery",
      "description": "Root redirect and final OIDC discovery JSON, the only content archetype exposed by the requested URL; exercised at desktop/mobile, preference, direct HTTP, performance, security, crawler, and memory conditions. Authorization UI and credential submission were not covered because they require client_id/redirect_uri transaction context and are not reachable from this root.",
      "url": "https://login.account.rakuten.com/.well-known/openid-configuration",
      "conditions": [
        "1440x1000",
        "360x800",
        "prefers-color-scheme: dark",
        "raw HTTP/no JavaScript",
        "crawler user agent",
        "repeated GET"
      ],
      "result": "issues"
    }
  ],
  "findings": [
    {
      "id": "privacy-odid-cookie",
      "pathId": "oidc-discovery",
      "url": "https://login.account.rakuten.com/.well-known/openid-configuration",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "The public OIDC discovery endpoint sets a persistent cross-site-capable ODID identifier on every response.",
      "evidence": "Direct response headers set ODID with Secure, HttpOnly, SameSite=None and Max-Age=63072000 (about two years); the CDP cookie audit independently observed the cookie as SameSite=None and at least 400 days. The endpoint is public static metadata and the evidence does not show why a durable browser identifier is required.",
      "artifacts": [
        "evidence/http-recon.txt",
        "evidence/cookies.json"
      ],
      "suggestedFix": "Do not set ODID on the root redirect or /.well-known/openid-configuration response. If a cookie is operationally required, document its purpose, scope it to the narrowest path and lifetime, and use Lax or Strict unless a tested federated cross-site flow requires None.",
      "effort": "small"
    }
  ],
  "taskList": [
    {
      "id": "task-cookie-minimisation",
      "title": "Remove or tightly constrain ODID on public discovery responses",
      "priority": 1,
      "findingIds": [
        "privacy-odid-cookie"
      ],
      "guidanceId": "privacy",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 1,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-26T19-31-00-837Z"
}
