generated: '2026-09-05' method: probed source: https://oauth.31huiyi.com/.well-known/openid-configuration name: 31huiyi standards conformance description: >- Cross-cutting and domain standards asserted for 31huiyi, each with the evidence it was read from. Positive entries come from the anonymously-served OpenID Connect discovery document and from the developer center; negatives are recorded because their absence is data. entries: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- https://oauth.31huiyi.com/.well-known/openid-configuration (HTTP 200) advertises the authorization, token, revocation and introspection endpoints and the standard grant types; the developer center documents the token exchange at /connect/token. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://oauth.31huiyi.com/.well-known/openid-configuration returns a complete discovery document with issuer, jwks_uri, userinfo_endpoint, end_session_endpoint, RS256 id_token signing and front/back-channel logout support. JWKS served at https://oauth.31huiyi.com/.well-known/openid-configuration/jwks (HTTP 200). - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: [plain, S256] in the discovery document.' - id: rfc8628-device-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: >- device_authorization_endpoint and urn:ietf:params:oauth:grant-type:device_code advertised in the discovery document. - id: rfc7662-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint https://oauth.31huiyi.com/connect/introspect in the discovery document. - id: rfc7009-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: revocation_endpoint https://oauth.31huiyi.com/connect/revocation in the discovery document. - id: rfc8414-as-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: >- https://oauth.31huiyi.com/.well-known/oauth-authorization-server returned HTTP 404 on 2026-09-05. Only the OIDC discovery path is served. - id: openapi name: OpenAPI Specification conforms: false evidence: >- No OpenAPI/Swagger document is published. Probed https://31api.31huiyi.com/openapi.json, /swagger.json, /swagger/v1/swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc (all HTTP 404) and https://api-help.31huiyi.com/openapi.json, /swagger.json (HTTP 404). The contract exists only as HTML documentation. - id: asyncapi name: AsyncAPI conforms: false evidence: >- An outbound push/webhook surface of 8 event types is documented, but no AsyncAPI document is published. See asyncapi/31huiyi-webhooks.yml. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- Errors are returned inside a 200 JSON envelope as businessCode/businessMessage or sysCode/sysMessage; no application/problem+json appears anywhere in the developer center. - id: rfc8594-sunset name: Sunset HTTP Header (RFC 8594) conforms: false evidence: No deprecation or sunset headers or policy are documented. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: >- /.well-known/security.txt returned 404 on 31huiyi.com (301), www.31huiyi.com (404), api-help.31huiyi.com (404), 31api.31huiyi.com (404) and oauth.31huiyi.com (404) on 2026-09-05. - id: rfc9421-api-catalog name: RFC 9727 /.well-known/api-catalog conforms: false evidence: Probed on all six known hosts; no host served a catalog document. - id: idempotency-key name: Idempotency-Key HTTP header (draft-ietf-httpapi-idempotency-key) conforms: false evidence: >- No idempotency header or replay-protection mechanism appears in the 93-page developer center. See conventions/31huiyi-conventions.yml idempotency.coverage — none. - id: pagination name: Documented pagination conforms: true evidence: >- Page-number pagination is documented with an explicit ceiling (pageSize maximum 100, default 50) at https://api-help.31huiyi.com/zh/getAttendeeList and a pager envelope at https://api-help.31huiyi.com/zh/new-pagebventlist — but with two incompatible parameter spellings. - id: rest name: Resource-oriented REST conforms: false evidence: >- RPC-over-HTTP: 85 of 86 documented operations are POST to verb-named paths, including reads. domain_standards: market: events, conferences and exhibitions (MICE) entries: [] note: >- REWARD-ONLY, and nothing to reward here. The events/MICE market has no widely adopted machine-readable interchange standard that 31 could declare, and the contract declares none — no schema URN, no OData $metadata, no industry message type. This is recorded as an honest empty set, not a failure. regulatory: jurisdiction: China (PRC) icp_filing: 沪ICP备10004253号-2 public_security_filing: 沪公网安备 31011502002823号 applicable_regimes: - PIPL (Personal Information Protection Law) — the API carries attendee personal data, national ID verification and face recognition. published_compliance_claims: [] note: >- No SOC 2, ISO 27001, PCI DSS or equivalent certification is published on the public site, and no trust center exists. The site advertises "100+ 资质" (100+ qualifications/credentials) on the pricing page but names none, so nothing is verifiable and no Compliance pointer is emitted.