generated: '2026-09-24' method: derived generator: derive-conformance.py source: openapi/ (1 document(s), 25 mutating operations) standards: - id: openapi-3.1 conforms: true evidence: the document declares 3.1.0 - id: oauth2 conforms: false evidence: 'securitySchemes: ApiKey (apiKey), BookingScopedCredential (http), HttpMessageSignature (http), MutualTLS (mutualTLS), OAuth2Bearer (http), PlatformKeyPop (apiKey)' - id: rfc9457 conforms: true evidence: application/problem+json on 253 response(s), e.g. POST /services/list 400 - id: idempotency conforms: true evidence: Idempotency-Key declared on 18 of 25 mutating operations (partial) - id: pagination conforms: true evidence: list operations take cursor, limit - id: ratelimit-headers conforms: true evidence: responses declare Retry-After note: 'Derived from the provider''s own OpenAPI only: what the contract declares. Claims the contract cannot carry (PCI DSS, SOC 2, FAPI, ISO 20022) come from the documentation reader and are merged below when found.'