> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpcomp.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Grading

> Why the letter counts requirement violations only

**The grade counts requirement violations only.** A letter has to mean something a reader can check, and "violates a stated MUST" is observable and citable; a weighted blend of requirements and recommendations is a taste judgement dressed as a measurement.

Recommendations a server does not follow are still reported — as advisories — and do not decide the letter.

## The scale

The worst unresolved MUST violation decides the grade:

| Grade | Meaning                            |
| ----- | ---------------------------------- |
| A     | No requirement violations          |
| B     | Worst violation is low severity    |
| C     | Worst violation is medium severity |
| D     | Worst violation is high severity   |
| F     | A critical requirement violation   |

## Ungraded findings

Some findings are deliberately ungraded, because no document is violated to earn them: an authorization or token endpoint that answers nothing, a listed authorization server beyond the first that does not resolve, and an Entra credential that has expired. There is no MUST anywhere that a server be up.

They are reported at the severity the outage deserves — an endpoint that answers nothing is `critical` — but severity describes the outage and the grade describes conformance, and those are different claims.

## Heuristics say so

A small number of checks are heuristics — scope minimization matches scope names against a conventional list, for example. Each one says so in the message it emits, so a heuristic is never mistaken for a cited requirement.
