Manifest position 712 · CrUX rank bucket 1000

https://login.account.rakuten.com

Coverage complete

Coverage-complete audit of the root redirect and its sole representative resource, the OIDC discovery document.

Attempts
2 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
passhighChromium renders the JSON representation with an injected color-scheme light dark declaration; preference screenshots and DOM inspection show a browser-adaptive native representation.
respect-user-preferences
respects-reduced-motion
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
respect-user-preferences
respects-contrast
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
implement-natural-interactions
view-transitions
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
implement-natural-interactions
scroll-driven-animations
passhighThe endpoint has no authored scroll-linked motion, scroll listeners, or main-thread animation work, so scrolling the native representation does not use the prohibited custom pattern.
implement-natural-interactions
physical-gestures
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
provide-guided-navigation
anchored-positioning
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
provide-guided-navigation
directs-attention
passhighThe standard OIDC key/value document presents the issuer and capability endpoints in a stable, linear native JSON representation without moving focus or hidden navigation state.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighLoad screenshots show only the requested JSON document, with no popup, banner, interstitial, or content obstruction.
maximize-content-reduce-noise
semantic-dismissible-primitives
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
maximize-content-reduce-noise
reduced-chrome
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighLayout metrics at the narrow capture report zero horizontal overflow; the browser-owned JSON representation remains reachable by native scrolling.
adapt-to-the-form-factor
component-level-responsiveness
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
adapt-to-the-form-factor
input-modality-aware
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
support-core-task-success
clear-purpose-and-primary-action
passhighA GET to the root redirects to the standard /.well-known/openid-configuration path, whose valid JSON clearly identifies issuer, authorization, token, userinfo, keys, registration, revocation, and logout endpoints.
support-core-task-success
primary-flow-completion
passhighFive repeated root requests followed the single 302 and completed with HTTP 200 and a valid 1,779-byte OIDC configuration.
support-core-task-success
clear-system-state-and-recovery
passhighThe discovery route returns 200 application/json; an unknown /sitemap.xml request returns an explicit HTTP 404 rather than a broken shell or misleading success.
be-fast-and-stable
good-core-web-vitals
passhighThe static representation has no layout shift or long tasks; five HTTP samples completed in 0.74-2.00 s and transfer only 1,779 decoded bytes.
be-fast-and-stable
visual-stability
passhighLayout observers at 360x800 and 1440x1000 recorded CLS 0 with no shifts.
be-fast-and-stable
efficient-main-thread
passhighBoth layout captures recorded zero long tasks; the endpoint ships no authored JavaScript.
be-fast-and-stable
efficient-resource-delivery
passhighThe final response is HTTP/2, gzip encoded in-browser, cacheable for 86,400 seconds, and transfers about 984 encoded bytes in the navigation timing.
be-fast-and-stable
trim-unused-and-duplicate-code
passhighThe application/json response ships no authored JavaScript or CSS; the only incidental request is the browser favicon lookup.
be-inclusive
names-roles-labels
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
be-inclusive
sufficient-contrast
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
be-inclusive
structure-and-focus
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
be-inclusive
legible-text
passhighDesktop and mobile screenshots show the complete native monospace JSON text without authored clipping, overlap, or mixed-font instability.
be-inclusive
zoom-reflow-targets-and-media
not-applicablehighThe audited URL resolves to a machine-readable application/json OIDC discovery endpoint with no authored user interface; this specific human-interface check has no authored control or presentation to test.
follow-best-practices
no-console-errors
passhighThe static JSON loaded and was parsed successfully by repeated Runtime.evaluate probes; there is no authored script or uncaught application exception.
follow-best-practices
sound-document-and-assets
not-applicablehighThe audited resource is application/json, not an authored HTML document, and ships no images, CSS, or HTML assets.
follow-best-practices
browser-platform-hygiene
passhighThe response has no authored script, deprecated API use, prompt calls, input handlers, or client library surface.
be-discoverable
title-and-description
not-applicablehighThis deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.
be-discoverable
crawlable-and-mobile-friendly
not-applicablehighThis deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.
be-discoverable
canonical-and-indexing-signals
passhighThe well-known OIDC resource has a stable standards-defined URL, returns HTTP 200, and robots.txt deliberately disallows this private authentication-infrastructure host rather than accidentally exposing it for indexing.
be-discoverable
structured-and-shareable-metadata
not-applicablehighThis deliberately non-indexed authentication-infrastructure endpoint is blocked by robots.txt and is intended for OIDC clients, not public search/share discovery.
be-private-and-secure
secure-transport-and-headers
issueshighHTTPS and final-response HSTS/nosniff protections are present, but the public discovery response also sets a long-lived SameSite=None ODID cookie.
privacy-odid-cookie medium: The public OIDC discovery endpoint sets a persistent cross-site-capable ODID identifier on every response.
be-private-and-secure
data-minimisation-and-third-parties
issueshighDirect response headers set ODID with Secure, HttpOnly, SameSite=None and Max-Age=63072000 (about two years); the CDP cookie audit independently observed the cookie as SameSite=None and at least 400 days. The endpoint is public static metadata and the evidence does not show why a durable browser identifier is required.
privacy-odid-cookie medium: The public OIDC discovery endpoint sets a persistent cross-site-capable ODID identifier on every response.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighThe metadata advertises authorization-code flow, PKCE S256, ES256/RS256 ID-token signing, and DPoP EdDSA; no browser permission is requested on load.
be-private-and-secure
defensive-browser-policies
passhighThe final JSON response sends HSTS includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, and Referrer-Policy strict-origin. CSP is not materially needed for a nosniff application/json representation.
be-resilient
progressive-enhancement
passhighThe core machine-readable content is the raw 200 application/json response and requires no JavaScript; curl parsed it directly.
be-resilient
resilient-runtime-behaviour
not-applicablehighThe resource is static JSON with no authored browser runtime, menus, overlays, or asynchronous UI state.
be-resilient
offline-and-installable
not-applicablehighOIDC discovery is intrinsically an online identity-provider protocol endpoint, not an installable application.
be-resilient
network-and-http-failure-states
passhighThe endpoint communicates success with 200 and an unknown path with 404; discovery responses are cacheable and do not depend on a fragile client shell.
be-internationalised
lang-dir-and-logical-properties
not-applicablehighThe representation is locale-neutral JSON rather than rendered language or CSS layout.
be-internationalised
locale-aware-data
passhighThe JSON contains no locale-formatted dates or numbers and advertises 35 supported UI locale tags for downstream authorization clients.
be-internationalised
time-zone-correctness
not-applicablehighThe discovery representation contains no dates, local times, events, or time-zone calculations.
be-trustworthy
no-dark-patterns
passhighThe machine-readable endpoint has no consent, upsell, cancellation, advertising, or human-facing choice UI.
be-trustworthy
humane-error-handling
not-applicablehighThere is no human-facing form in this machine-readable discovery representation.
be-trustworthy
trustworthy-input-assistance
not-applicablehighThere are no human-facing inputs in this machine-readable discovery representation.
be-trustworthy
safe-commercial-and-account-flows
passhighPublished account protocol capabilities include end-session and revocation endpoints plus PKCE S256 and DPoP, supporting explicit termination and modern authorization safeguards.
be-sustainable
optimised-assets
passhighThe endpoint has zero images and only a small compressed JSON payload.
be-sustainable
no-wasteful-work
passhighThe load performs one redirect, one small first-party JSON request, and no background application work or fetch loop.
be-sustainable
third-party-and-media-budget
passhighNo third-party script, font, image, audio, video, animation, or authored media is loaded.
be-agent-ready
structured-agent-capabilities
not-applicablehighThis is standardized OIDC metadata for authentication clients, not an AI-agent task surface where WebMCP tools or agentic forms are appropriate.
be-agent-ready
on-device-inference
not-applicablehighThe endpoint only publishes static OIDC metadata; there is no inference task for which an on-device model would improve the experience.
be-memory-efficient
no-leak-under-repeated-interaction
not-applicablehighThe endpoint has no authored interaction to repeat; fabricating one would not test a representative user action.
be-memory-efficient
bounded-footprint
passhighThe heap summary reports 26,537 nodes and 798,116 bytes total self size for the browser JSON view; the authored representation has only seven DOM elements.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighThe single-state heap summary has no Detached* constructor among its reported populations, and the endpoint has no authored listeners, timers, or runtime interaction.

Provenance

Canonical report: results/atomic/reports/0712-login_account_rakuten_com.json
Report SHA-256: 67db526a5c8db29866e5dbe7ffa8769ce2432a49a1cacd1de9904b8963f31a97
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_account_rakuten_com/2026-07-26T19-31-00-837Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/login_account_rakuten_com/2026-07-26T19-31-00-837Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.