generated: '2026-07-25' method: derived source: openapi/*.yml plus the 3GPP specifications the documents cite summary: >- 3GPP is a standards body, so "conformance" runs in the unusual direction here: 3GPP is the authority other parties conform to. What this artifact records is which external, cross-cutting standards the 3GPP API documents themselves adopt, evidenced from the specifications in this repo. standards: - id: openapi-3.0 conforms: true evidence: every document in openapi/ declares openapi 3.0.0 - id: oauth2 conforms: true evidence: >- 64 documents declare an oAuth2ClientCredentials securityScheme with a clientCredentials flow; token issuance is specified in TS 29.510 (NRF Nnrf_AccessToken) and TS 33.501 - id: oauth2-client-credentials conforms: true evidence: securitySchemes flows.clientCredentials across openapi/*.yml - id: rfc7807-problem-details conforms: true evidence: application/problem+json responses with the ProblemDetails schema in 15 documents; error handling specified in TS 29.500 and TS 29.571 - id: rfc9457-problem-details conforms: false evidence: the specifications reference RFC 7807, which RFC 9457 obsoletes; the wire format is compatible - id: rfc7396-json-merge-patch conforms: true evidence: application/merge-patch+json request bodies in 46 documents - id: rfc6902-json-patch conforms: true evidence: application/json-patch+json request bodies in 6 documents - id: http2 conforms: true evidence: TS 29.500 mandates HTTP/2 for Service Based Interfaces - id: tls conforms: true evidence: TS 33.501 requires TLS protection of the Service Based Interface - id: json conforms: true evidence: application/json is the request and response media type throughout - id: openidconnect conforms: false evidence: no openIdConnect securityScheme appears in any document - id: mutual-tls conforms: partial evidence: >- not expressed as a mutualTLS securityScheme in the OpenAPI documents, but TS 33.501 and TS 33.122 specify certificate based mutual authentication between network functions and for CAPIF-1e/CAPIF-2e - id: fhir-r4 conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: json-api conforms: false - id: asyncapi conforms: false evidence: no AsyncAPI document is published; the event surface is expressed as OpenAPI callbacks - id: pagination conforms: false evidence: no cursor or offset parameters are defined in any document - id: idempotency-key conforms: false evidence: no Idempotency-Key header or equivalent appears in any document frameworks_3gpp_defines: - id: capif role: 3GPP is the author specification: 3GPP TS 29.222 note: >- The Common API Framework is 3GPP's own API management standard: onboarding, discovery, security, auditing and logging for northbound APIs. It is what GSMA Open Gateway and CAMARA deployments profile. - id: nef-scef-northbound role: 3GPP is the author specification: 3GPP TS 29.122 and TS 29.522 - id: sba role: 3GPP is the author specification: 3GPP TS 29.500 and TS 29.501 - id: management-services role: 3GPP is the author specification: 3GPP TS 28.532 and the 28-series network resource models certifications: published: false note: >- 3GPP is not a legal entity (it is a collaboration between ARIB, ATIS, CCSA, ETSI, TSDSI, TTA and TTC) and publishes no SOC 2, ISO 27001, PCI DSS or similar organisational certification, and operates no trust centre.