generated: '2026-09-12' method: derived source: openapi/agendapro-connect-v3-openapi.yml + https://developers.agendapro.com/docs/getting-started conformance: - id: openapi-3.0.3 conforms: true evidence: 'openapi/agendapro-connect-v3-openapi.yml (openapi: 3.0.3, 23 paths, 28 operations, 43 component schemas, 1 securityScheme applied globally)' - id: oauth2 conforms: false evidence: No oauth2 securityScheme in the OpenAPI and no authorization endpoint in the docs; authentication is a static per-company bearer API key. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any AgendaPro host (agendapro.com 404, developers.agendapro.com 404, connect.agendapro.com 401 gateway catch-all). - id: rfc9457 conforms: false evidence: Errors are application/json {error, detail}; no application/problem+json media type appears in the spec. See errors/agendapro-problem-types.yml. - id: rfc9331-ratelimit-headers conforms: false evidence: Uses legacy X-RateLimit-* vendor headers (X-RateLimit-Limit/Remaining/Reset plus X-RateLimit-Burst-*), not the standard RateLimit / RateLimit-Policy fields. - id: rfc6585-429 conforms: true evidence: 429 Too Many Requests with a Retry-After header on limit exhaustion; declared on all 28 operations. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation response header is declared or documented; a prior API generation was retired without one (lifecycle/agendapro-lifecycle.yml). - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on agendapro.com and developers.agendapro.com; app.agendapro.com answers 200 with the SPA shell for every path. - id: rfc8615-well-known conforms: false evidence: No /.well-known document of any kind is served. See well-known/agendapro-well-known.yml. - id: pagination conforms: true evidence: Uniform page/per_page paging with a pagination{} envelope (current_page, per_page, next_page, prev_page, total_records, total_pages) on all eight list operations. - id: idempotency conforms: false evidence: No idempotency key or replay-protection mechanism on any of the 9 write operations. See conventions/agendapro-conventions.yml. - id: json-schema conforms: true evidence: 43 reusable component schemas with $ref reuse across request bodies and responses. - id: e164-phone conforms: true evidence: createClient requires phone in E.164 format (ITU-T E.164). - id: iso8601-datetime conforms: true evidence: All booking start_time/end_time and webhook timestamps are ISO 8601 with offset. - id: hmac-sha256-webhook-signature conforms: true evidence: X-Webhook-Signature carries an HMAC-SHA256 hexdigest of the raw body, keyed on a per-webhook secret; https://developers.agendapro.com/docs/webhooks - id: tls-1.3 conforms: true evidence: security/agendapro-domain-security.yml — TLSv1.3 on agendapro.com, developers.agendapro.com and connect.agendapro.com. - id: hsts conforms: true evidence: HSTS max-age 31536000 on agendapro.com and developers.agendapro.com; absent on connect.agendapro.com (the API host). - id: dnssec conforms: true evidence: security/agendapro-domain-security.yml — DNSSEC signed on agendapro.com. domain_standard: declared: false candidate_standards_probed: - schema.org/Reservation - schema.org/Service - OpenActive (activity booking) - HL7 FHIR Appointment note: The scheduling / appointment-booking market AgendaPro serves has no standard the contract declares. Nothing in the OpenAPI carries a schema.org @type, an OpenActive context, an ICS/iCalendar surface or a FHIR Appointment resource shape; the booking, client and service models are entirely proprietary. This is a reward-only dimension and no penalty is implied — the finding is recorded so a later round does not re-probe it, and so that an integrator knows a bespoke connector is required. Note that the aesthetic and medical-clinic segment AgendaPro sells into is where a FHIR Appointment mapping would matter most, and none is offered. certifications: published: [] note: No SOC 2, ISO 27001, PCI DSS, HIPAA or GDPR/LGPD compliance page, certification badge or audit report is published on any AgendaPro property. trust.agendapro.com resolves but is wildcard DNS serving the marketing homepage, not a trust center. evidence: - url: https://trust.agendapro.com status: 200 note: 200 but serves the agendapro.com marketing homepage (title "Software de Agendamiento de Citas - AgendaPro") — wildcard DNS, not a trust center. - url: https://agendapro.com/security status: 404 - url: https://agendapro.com/seguridad status: 404