generated: '2026-08-06' method: searched source: >- openapi/airtm-enterprise-v2-openapi.json, openapi/airtm-enterprise-v1-openapi.json, well-known/airtm-openid-configuration.json, well-known/airtm-security.txt, and the Authentication / OIDC / Wallet Resource guides in the Enterprise API docs docs: https://docs.airtm.com/ standards: - id: openapi-3.0 conforms: true evidence: openapi/airtm-enterprise-v2-openapi.json declares openapi 3.0.0 with 36 paths and 51 operations. - id: openapi-3.1 conforms: true evidence: openapi/airtm-enterprise-v1-openapi.json declares openapi 3.1.0. - id: oauth2 conforms: true evidence: >- Authorization Code, Refresh Token and Client Credentials grants documented and advertised at https://api.enterprise.airtm.com/oidc/.well-known/openid-configuration (grant_types_supported). - id: oidc-core conforms: true evidence: >- OpenID Provider issuing RS256 id_tokens with sub/email/name/given_name/family_name/preferred_username/ updated_at/sid/auth_time/iss claims; userinfo, end_session and PAR endpoints advertised. - id: oidc-discovery conforms: true partial: true evidence: >- Discovery document served at the /oidc issuer path, NOT at the host root — a client probing https://api.enterprise.airtm.com/.well-known/openid-configuration gets 404. It also advertises only openid/email/profile in scopes_supported, omitting the four wallet:*/kyc:status resource scopes the API actually enforces. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256]; authorization code flows without PKCE are rejected with invalid_request.' - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://api.enterprise.airtm.com/oidc/token/introspection — access tokens are opaque and MUST be introspected. - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://api.enterprise.airtm.com/oidc/token/revocation. - id: rfc9126-pushed-authorization-requests conforms: true evidence: pushed_authorization_request_endpoint https://api.enterprise.airtm.com/oidc/request. - id: rfc9449-dpop conforms: true partial: true evidence: 'dpop_signing_alg_values_supported: [ES256, Ed25519, EdDSA] advertised in discovery; not documented in the prose guides.' - id: rfc7517-jwks conforms: true evidence: https://api.enterprise.airtm.com/oidc/jwks returns application/jwk-set+json with an RS256 signing key. - id: rfc7617-http-basic-auth conforms: true evidence: securitySchemes.basicAuth (type http, scheme basic) in both Enterprise specs. - id: rfc6750-bearer-token conforms: true evidence: >- Wallet Resource API returns WWW-Authenticate Bearer error="invalid_token" (401) and error="insufficient_scope", scope="" (403). - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on the API host; only the OIDC discovery path is served. - id: rfc9116-security-txt conforms: true partial: true evidence: >- https://www.airtm.com/.well-known/security.txt returns 200 with Contact and Expires fields, but the Expires value (2025-06-30T15:00:00Z) is in the past, and no Policy, Encryption, Preferred-Languages or Canonical field is present. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {code, message, data} JSON envelope with application/json — no application/problem+json, no type URI. See errors/airtm-error-codes.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published; the legacy V1 API has no announced end of life. - id: idempotency-key conforms: true evidence: >- Idempotency-Key header REQUIRED on POST /quotes and POST /transactions (Wallet Resource API) and declared required on CreateTransaction in the V2 OpenAPI; same-key/same-body replay returns 200, same-key/different-body returns 409. - id: cursor-pagination conforms: true evidence: before / after / perPage query parameters on 11 list operations in the V2 OpenAPI. - id: webhooks-openapi-3.1-style conforms: true partial: true evidence: >- The V2 document declares a top-level `webhooks` object with eight events and full request-body schemas, even though it is declared as OpenAPI 3.0.0 (where `webhooks` is not a 3.0 keyword). - id: asyncapi conforms: false evidence: No AsyncAPI document published; /asyncapi.json and /asyncapi.yaml return 404. - id: json-api conforms: false - id: fhir conforms: false - id: fapi conforms: false evidence: >- Not asserted by Airtm and not derivable — no mTLS/private_key_jwt requirement, no signed request objects mandated, and access tokens are opaque rather than sender-constrained by default (DPoP is advertised but not required). - id: psd2 conforms: false - id: scim conforms: false - id: odata conforms: false compliance_program: published_certifications: [] trust_center: security/airtm-trust-center.yml note: >- Airtm operates a Vanta-hosted trust center at https://trust.airtm.com/ (HTTP 200) but the certification list is rendered client-side and no named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) could be verified anonymously. No `Compliance` pointer is emitted, because no specific certification claim was observed. Airtm's verifiable regulatory posture is its FinCEN MSB registration (#31000329787639), which is a money-transmission registration, not an information-security certification.