Manifest position 712 · CrUX rank bucket 1000
https://login.account.rakuten.com
Coverage complete
Coverage-complete audit of the root redirect and its sole representative resource, the OIDC discovery document.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | pass | high | Chromium renders the JSON representation with an injected color-scheme light dark declaration; preference screenshots and DOM inspection show a browser-adaptive native representation. |
respect-user-preferencesrespects-reduced-motion | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
respect-user-preferencesrespects-contrast | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
implement-natural-interactionsview-transitions | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
implement-natural-interactionsscroll-driven-animations | pass | high | The endpoint has no authored scroll-linked motion, scroll listeners, or main-thread animation work, so scrolling the native representation does not use the prohibited custom pattern. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
provide-guided-navigationanchored-positioning | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
provide-guided-navigationdirects-attention | pass | high | The standard OIDC key/value document presents the issuer and capability endpoints in a stable, linear native JSON representation without moving focus or hidden navigation state. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | Load screenshots show only the requested JSON document, with no popup, banner, interstitial, or content obstruction. |
maximize-content-reduce-noisesemantic-dismissible-primitives | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
maximize-content-reduce-noisereduced-chrome | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Layout metrics at the narrow capture report zero horizontal overflow; the browser-owned JSON representation remains reachable by native scrolling. |
adapt-to-the-form-factorcomponent-level-responsiveness | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
adapt-to-the-form-factorinput-modality-aware | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
support-core-task-successclear-purpose-and-primary-action | pass | high | A GET to the root redirects to the standard /.well-known/openid-configuration path, whose valid JSON clearly identifies issuer, authorization, token, userinfo, keys, registration, revocation, and logout endpoints. |
support-core-task-successprimary-flow-completion | pass | high | Five repeated root requests followed the single 302 and completed with HTTP 200 and a valid 1,779-byte OIDC configuration. |
support-core-task-successclear-system-state-and-recovery | pass | high | The discovery route returns 200 application/json; an unknown /sitemap.xml request returns an explicit HTTP 404 rather than a broken shell or misleading success. |
be-fast-and-stablegood-core-web-vitals | pass | high | The static representation has no layout shift or long tasks; five HTTP samples completed in 0.74-2.00 s and transfer only 1,779 decoded bytes. |
be-fast-and-stablevisual-stability | pass | high | Layout observers at 360x800 and 1440x1000 recorded CLS 0 with no shifts. |
be-fast-and-stableefficient-main-thread | pass | high | Both layout captures recorded zero long tasks; the endpoint ships no authored JavaScript. |
be-fast-and-stableefficient-resource-delivery | pass | high | The final response is HTTP/2, gzip encoded in-browser, cacheable for 86,400 seconds, and transfers about 984 encoded bytes in the navigation timing. |
be-fast-and-stabletrim-unused-and-duplicate-code | pass | high | The application/json response ships no authored JavaScript or CSS; the only incidental request is the browser favicon lookup. |
be-inclusivenames-roles-labels | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
be-inclusivesufficient-contrast | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
be-inclusivestructure-and-focus | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
be-inclusivelegible-text | pass | high | Desktop and mobile screenshots show the complete native monospace JSON text without authored clipping, overlap, or mixed-font instability. |
be-inclusivezoom-reflow-targets-and-media | not-applicable | high | The audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test. |
follow-best-practicesno-console-errors | pass | high | The static JSON loaded and was parsed successfully by repeated Runtime.evaluate probes; there is no authored script or uncaught application exception. |
follow-best-practicessound-document-and-assets | not-applicable | high | The audited resource is application/json, not an authored HTML document, and ships no images, CSS, or HTML assets. |
follow-best-practicesbrowser-platform-hygiene | pass | high | The response has no authored script, deprecated API use, prompt calls, input handlers, or client library surface. |
be-discoverabletitle-and-description | not-applicable | high | This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery. |
be-discoverablecrawlable-and-mobile-friendly | not-applicable | high | This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery. |
be-discoverablecanonical-and-indexing-signals | pass | high | The well-known OIDC resource has a stable standards-defined URL, returns HTTP 200, and robots.txt deliberately disallows this private authentication-infrastructure host rather than accidentally exposing it for indexing. |
be-discoverablestructured-and-shareable-metadata | not-applicable | high | This deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery. |
be-private-and-securesecure-transport-and-headers | issues | high | HTTPS and final-response HSTS/nosniff protections are present, but the public discovery response also sets a long-lived SameSite=None ODID cookie. privacy-odid-cookie medium: The public OIDC discovery endpoint sets a persistent cross-site-capable ODID identifier on every response. |
be-private-and-securedata-minimisation-and-third-parties | issues | high | Direct response headers set ODID with Secure, HttpOnly, SameSite=None and Max-Age=63072000 (about two years); the CDP cookie audit independently observed the cookie as SameSite=None and at least 400 days. The endpoint is public static metadata and the evidence does not show why a durable browser identifier is required. privacy-odid-cookie medium: The public OIDC discovery endpoint sets a persistent cross-site-capable ODID identifier on every response. |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | The metadata advertises authorization-code flow, PKCE S256, ES256/RS256 ID-token signing, and DPoP EdDSA; no browser permission is requested on load. |
be-private-and-securedefensive-browser-policies | pass | high | The final JSON response sends HSTS includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, and Referrer-Policy strict-origin. CSP is not materially needed for a nosniff application/json representation. |
be-resilientprogressive-enhancement | pass | high | The core machine-readable content is the raw 200 application/json response and requires no JavaScript; curl parsed it directly. |
be-resilientresilient-runtime-behaviour | not-applicable | high | The resource is static JSON with no authored browser runtime, menus, overlays, or asynchronous UI state. |
be-resilientoffline-and-installable | not-applicable | high | OIDC discovery is intrinsically an online identity-provider protocol endpoint, not an installable application. |
be-resilientnetwork-and-http-failure-states | pass | high | The endpoint communicates success with 200 and an unknown path with 404; discovery responses are cacheable and do not depend on a fragile client shell. |
be-internationalisedlang-dir-and-logical-properties | not-applicable | high | The representation is locale-neutral JSON rather than rendered language or CSS layout. |
be-internationalisedlocale-aware-data | pass | high | The JSON contains no locale-formatted dates or numbers and advertises 35 supported UI locale tags for downstream authorization clients. |
be-internationalisedtime-zone-correctness | not-applicable | high | The discovery representation contains no dates, local times, events, or time-zone calculations. |
be-trustworthyno-dark-patterns | pass | high | The machine-readable endpoint has no consent, upsell, cancellation, advertising, or human-facing choice UI. |
be-trustworthyhumane-error-handling | not-applicable | high | There is no human-facing form in this machine-readable discovery representation. |
be-trustworthytrustworthy-input-assistance | not-applicable | high | There are no human-facing inputs in this machine-readable discovery representation. |
be-trustworthysafe-commercial-and-account-flows | pass | high | Published account protocol capabilities include end-session and revocation endpoints plus PKCE S256 and DPoP, supporting explicit termination and modern authorization safeguards. |
be-sustainableoptimised-assets | pass | high | The endpoint has zero images and only a small compressed JSON payload. |
be-sustainableno-wasteful-work | pass | high | The load performs one redirect, one small first-party JSON request, and no background application work or fetch loop. |
be-sustainablethird-party-and-media-budget | pass | high | No third-party script, font, image, audio, video, animation, or authored media is loaded. |
be-agent-readystructured-agent-capabilities | not-applicable | high | This is standardized OIDC metadata for authentication clients, not an AI-agent task surface where WebMCP tools or agentic forms are appropriate. |
be-agent-readyon-device-inference | not-applicable | high | The endpoint only publishes static OIDC metadata; there is no inference task for which an on-device model would improve the experience. |
be-memory-efficientno-leak-under-repeated-interaction | not-applicable | high | The endpoint has no authored interaction to repeat; fabricating one would not test a representative user action. |
be-memory-efficientbounded-footprint | pass | high | The heap summary reports 26,537 nodes and 798,116 bytes total self size for the browser JSON view; the authored representation has only seven DOM elements. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | The single-state heap summary has no Detached* constructor among its reported populations, and the endpoint has no authored listeners, timers, or runtime interaction. |
Provenance
Canonical report: results/atomic/reports/0712-login_account_rakuten_com.json
Report SHA-256: 67db526a5c8db29866e5dbe7ffa8769ce2432a49a1cacd1de9904b8963f31a97
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_account_rakuten_com/2026-07-26T19-31-00-837Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_account_rakuten_com/2026-07-26T19-31-00-837Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.