generated: '2026-07-28' method: searched source: >- https://ndc.aircanada.com/api/documentation/ndcapis, https://ndc.aircanada.com/api/gettingstarted/apisetup, https://www.aircanada.com/ca/en/aco/home/ndc.html and the published sample XML in examples/ description: >- Which industry and cross-cutting standards the Air Canada NDC API actually conforms to. Air Canada is a genuinely standards-based surface - IATA NDC 17.2 EDIST end to end, with IATA and ISO code lists on the wire - and a genuinely non-web-standard one: no OpenAPI, no REST, no OAuth on the inbound path, no RFC 9457, no /.well-known/. Each entry is evidenced or explicitly marked as not conforming. standards: - id: iata-ndc-17.2 name: IATA New Distribution Capability 17.2 (EDIST) conforms: true evidence: >- Namespace http://www.iata.org/IATA/EDIST/2017.2 on every published sample message; SchemaVersion YY.2017.2 in the aggregation header; ten documented NDC 17.2 message pairs. Air Canada states verbatim: "We support version 2017.2 API schema and have achieved NDC@Scale certification from IATA." reference: https://www.iata.org/en/programs/airline-distribution/retailing/ndc/ - id: iata-ndc-at-scale name: IATA NDC@Scale certification conforms: true evidence: Claimed verbatim by Air Canada on https://www.aircanada.com/ca/en/aco/home/ndc.html note: >- Self-published claim of an IATA programme certification. No certificate, registry entry or audit date is published on the developer surface. - id: iata-resolution-762 name: IATA airline designators conforms: true evidence: AirlineID / Owner carry the two-character designator (AC) per IATA Resolution 762. - id: iata-resolution-763 name: IATA location identifiers (airport/city codes) conforms: true evidence: AirportCode / CityCode elements use IATA three-letter codes (YYZ, YUL) per IATA Resolution 763. - id: iata-padis name: IATA PADIS code lists conforms: true evidence: Data elements documented against PADIS lists 1001, 1153, 4405, 9888 and 9972. - id: iso-3166-1 name: ISO 3166-1 country codes conforms: true evidence: PointOfSale/Location/CountryCode, e.g. US, CA. - id: iso-4217 name: ISO 4217 currency codes conforms: true evidence: CurrCodes/FilledInCurrency/CurrCode, e.g. CAD. - id: iso-8601 name: ISO 8601 dates and timestamps conforms: true evidence: 'TimeStamp="2021-04-08T10:18:42.087-04:00" and Date elements such as 2022-12-30 in the published samples.' - id: soap-1.1 name: SOAP 1.1 messaging conforms: true evidence: >- soapenv:Envelope with namespace http://schemas.xmlsoap.org/soap/envelope/ wrapping an NDCMSG_Envelope; the IATA message is carried inside a CDATA section of NDCMSG_Payload. - id: atpco-ndc-exchange name: ATPCO NDC Exchange aggregation envelope conforms: true evidence: >- Published samples use the aggregation namespace https://prod.services.atpco.net/ndcexchange/NDC/schema/v1 (and an ACNDC variant) with Document.Name values such as "ATPCO AGG NDCx 2.0" and "ACNDC AGG NDCx 2.0". - id: pci-dss name: PCI DSS conforms: unknown evidence: >- Air Canada routes the two payment-bearing messages (OrderCreate, OrderChange) through a separate gateway it labels "Uses PCI gateway" (aps-gw), which is a strong operational signal. No PCI DSS attestation, AOC or compliance statement is published on the developer surface, so this is recorded as unknown rather than asserted. - id: openapi name: OpenAPI conforms: false evidence: No OpenAPI, Swagger, WSDL or downloadable XSD is published. See review.yml specHarvest. - id: rest name: REST / resource-oriented HTTP conforms: false evidence: Single POST endpoint per message service; all semantics in the XML payload. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: >- Errors are returned in-payload in the NDC Errors element with numeric codes, not as application/problem+json. See errors/air-canada-error-codes.yml. - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- Not used for inbound authentication (a single apikey header is). OAuth is supported only on the outbound OrderChangeNotification webhook, where the seller supplies OAuthTokenURL and OAuthScope for Air Canada to call them. - id: openid-connect name: OpenID Connect conforms: false evidence: No /.well-known/openid-configuration on any host; see well-known/air-canada-well-known.yml. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: Probed on all three hosts, none served. See well-known/air-canada-well-known.yml. - id: rfc8594-sunset-header name: RFC 8594 Sunset header conforms: false evidence: No deprecation or sunset policy or header is published. See lifecycle/air-canada-lifecycle.yml. - id: idempotency-key name: Idempotency keys conforms: false evidence: No idempotency contract is published. See conventions/air-canada-conventions.yml. - id: asyncapi name: AsyncAPI conforms: false evidence: >- A real webhook surface exists (OrderChangeNotification) but no AsyncAPI document is published. See asyncapi/air-canada-ocn-webhooks.yml. regulatory: note: >- Air Canada's published legal surface is consumer-facing (terms of use, privacy policy, cookie policy). No SOC 2, ISO 27001, PCI DSS attestation, GDPR/PIPEDA partner data-processing addendum or trust centre is published on the developer surface - probes for a trust centre and a vulnerability disclosure programme both returned nothing. No Compliance pointer is wired in apis.yml for that reason. probes: trust_center: none vulnerability_disclosure: none security_txt: none