generated: '2026-09-02' method: probed source: >- live probes of APHIS-operated hosts on 2026-09-02; OIDC discovery documents on efile/acir/aphis.my.site.com, ArcGIS REST service directory at https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services specification: API Commons Conformance specificationVersion: '0.1' provider: Animal and Plant Health Inspection Service providerId: animal-and-plant-health-inspection-service note: >- Every entry below is asserted against something fetched, not against a marketing claim. APHIS makes no published conformance or certification statement of its own; the standards it does satisfy are satisfied by the platforms it runs on (Salesforce Experience Cloud for identity, Esri ArcGIS Online for geospatial), and that is recorded as such. standards: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: - url: https://efile.aphis.usda.gov/.well-known/openid-configuration status: 200 detail: >- Document carries issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri, response_types_supported, subject_types_supported and id_token_signing_alg_values_supported - all required OIDC Discovery fields. - url: https://acir.aphis.usda.gov/.well-known/openid-configuration status: 200 - url: https://aphis.my.site.com/.well-known/openid-configuration status: 200 note: Satisfied by the Salesforce Experience Cloud platform, served from APHIS-controlled issuers. - id: oauth2 name: OAuth 2.0 (RFC 6749) authorization code + implicit conforms: true evidence: - url: https://efile.aphis.usda.gov/.well-known/openid-configuration status: 200 detail: response_types_supported [code, token, token id_token]; token_endpoint_auth_methods_supported includes private_key_jwt (RFC 7523). - id: rfc7662 name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: - url: https://efile.aphis.usda.gov/.well-known/openid-configuration status: 200 detail: introspection_endpoint https://efile.aphis.usda.gov/services/oauth2/introspect - id: rfc7009 name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: - url: https://efile.aphis.usda.gov/.well-known/openid-configuration status: 200 detail: revocation_endpoint https://efile.aphis.usda.gov/services/oauth2/revoke - id: rfc9449 name: OAuth 2.0 Demonstrating Proof of Possession (DPoP, RFC 9449) conforms: true evidence: - url: https://efile.aphis.usda.gov/.well-known/openid-configuration status: 200 detail: dpop_signing_alg_values_supported [RS256, RS384, RS512, ES256, ES384, ES512, EdDSA] - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: - url: https://efile.aphis.usda.gov/.well-known/security.txt status: 401 - url: https://acir.aphis.usda.gov/.well-known/security.txt status: 401 - url: https://aphis.my.site.com/.well-known/security.txt status: 401 - url: https://www.usda.gov/.well-known/security.txt status: 403 detail: Akamai "Access Denied" to non-browser clients; could not be read, so absence is unconfirmed on the parent domain. - id: rfc9727 name: /.well-known/api-catalog (RFC 9727) conforms: false evidence: - url: https://efile.aphis.usda.gov/.well-known/api-catalog status: 401 - url: https://acir.aphis.usda.gov/.well-known/api-catalog status: 401 - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: - url: https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services/Federal_Citrus_Quarantine_Data/FeatureServer/0?f=json status: 200 detail: >- Errors are returned as the ArcGIS envelope {"error":{"code":400,"message":"","details":[...]}} with HTTP 200, not application/problem+json. - id: openapi name: OpenAPI conforms: false evidence: - url: https://efile.aphis.usda.gov/openapi.json status: 401 - url: https://acir.aphis.usda.gov/openapi.json status: 401 - url: https://pcit.aphis.usda.gov/openapi.json status: 404 - url: https://vehcs.aphis.usda.gov/openapi.json status: 404 domain_standards: - id: geoservices-rest name: Esri GeoServices REST / ArcGIS REST API (Feature Service) market: geospatial conforms: true evidence: - url: https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services?f=json status: 200 detail: >- Service directory returns currentVersion 12 and 93 FeatureServer services. Individual services expose the standard Feature Service contract - layers[], fields[] with esriFieldType types, geometryType (esriGeometryPolygon/esriGeometryPoint), capabilities, maxRecordCount, and /query with supportedQueryFormats JSON. - url: https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services/PPQ_GIS_Federal_Quarantine_Feature_Layer/FeatureServer?f=json status: 200 detail: capabilities "Query,Extract"; supportedExportFormats includes geojson, csv, kml, shapefile, geoPackage. note: >- This is the one real domain-standard contract APHIS ships. It is the de-facto geospatial web-service standard for the sector, and a consumer who already speaks ArcGIS REST can read APHIS quarantine, disease-detection and surveillance layers with no bespoke connector. - id: ogcapi-features name: OGC API - Features market: geospatial conforms: false evidence: - url: https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services/Federal_Citrus_Quarantine_Data/OGCFeatureServer?f=json status: 200 detail: >- Body is {"error":{"code":400,"message":"Invalid URL"}} - the OGC Feature Server view is not enabled on any probed service, so no OGC API - Features landing page or its OpenAPI document is served. Probed on four services; all identical. note: >- Enabling the OGC Feature Server view on these existing services would give APHIS an OGC-conformant surface AND a real OpenAPI 3.0 document at /OGCFeatureServer/api, at no data-migration cost. This is the single highest-leverage change available to APHIS. - id: geojson name: GeoJSON (RFC 7946) market: geospatial conforms: true evidence: - url: https://services7.arcgis.com/2C1NQ7u6M6SXoa8p/arcgis/rest/services/PPQ_GIS_Federal_Quarantine_Feature_Layer/FeatureServer?f=json status: 200 detail: supportedExportFormats declares geojson; layer /query accepts f=geojson. - id: dcat-us name: DCAT-US (Project Open Data) catalog market: government open data conforms: false evidence: - url: https://catalog.data.gov/organization/aphis-usda-gov status: 404 detail: The APHIS-specific data.gov organization no longer resolves; APHIS datasets now sit under the department-wide /organization/usda. compliance_program: published: false note: >- APHIS publishes no trust center, no SOC 2 / ISO 27001 / FedRAMP attestation of its own, and no named certification page. As a federal agency its systems are governed by FISMA and USDA ATO processes, but no public artifact asserting that was found on any APHIS host, so nothing is claimed here. maintainers: - FN: Kin Lane email: info@apievangelist.com