generated: '2026-09-02' method: derived source: >- openapi/_original/api-league-openapi.json, https://apileague.com/docs/authentication/, https://apileague.com/docs/quotas-and-rate-limiting/, https://apileague.com/terms/, https://apileague.com/about, security/api-league-domain-security.yml, and the well-known/api-league-well-known.yml probe. provider: API League providerId: api-league description: >- Cross-cutting standards conformance for API League, derived from the contract itself rather than from marketing claims. The provider makes NO compliance claims of any kind — there is no trust center, no certification badge, no SOC 2 / ISO 27001 / PCI / HIPAA reference, and no security or responsible-disclosure page. No `Compliance` pointer is emitted in apis.yml, and no `Security` pointer either: both would assert a published program that does not exist. standards: - id: openapi-3.0 conforms: true evidence: >- openapi/_original/api-league-openapi.json declares openapi 3.0.0 with 55 paths, and the provider links it from its own SDK page as "our OpenAPI 3 Specification JSON". - id: rest conforms: true evidence: Resource-per-operation HTTP GET surface over https://api.apileague.com with JSON responses. - id: rfc9457-problem-details conforms: false evidence: >- Error responses are a flat vendor envelope {"status","code","message"} served as application/json;charset=UTF-8. No application/problem+json, no type URI, no title/instance. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in the spec and no OAuth documented anywhere on the site. - id: oidc conforms: false evidence: '/.well-known/openid-configuration returns the site catch-all on apileague.com and 401 on api.apileague.com.' - id: api-key-auth conforms: true evidence: >- Two apiKey securitySchemes applied globally — `api-key` in query and `x-api-key` in header; documented at https://apileague.com/docs/authentication/. - id: rfc9116-security-txt conforms: false evidence: 'No /.well-known/security.txt on any host — see well-known/api-league-well-known.yml.' - id: rfc8615-well-known conforms: false evidence: >- No .well-known document is served. apileague.com answers 200 with a catch-all homepage for every path including a control that cannot exist; api.apileague.com answers 401 for every path including the control. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header and no deprecation policy — see lifecycle/api-league-lifecycle.yml. - id: ietf-ratelimit-headers conforms: false evidence: >- Quota is signalled with vendor headers X-API-Quota-Request / X-API-Quota-Used / X-API-Quota-Left. No RateLimit-Limit/Remaining/Reset, no X-RateLimit-*, no Retry-After. - id: pagination-offset-limit conforms: true evidence: >- `number` + `offset` request parameters and `total_results`/`number`/`offset` response fields across the 13 search-shaped operations. - id: idempotency-key conforms: false evidence: >- No idempotency-key contract. All 55 operations are GET, so HTTP idempotency holds by method; there is no provider-designed mechanism. See conventions/api-league-conventions.yml. - id: json-api conforms: false evidence: Plain JSON, not JSON:API document structure. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface of any kind exists. - id: mcp conforms: false evidence: 'No MCP server — mcp.apileague.com does not resolve. See mcp/api-league-mcp.yml.' - id: a2a conforms: false evidence: 'No agent card at /.well-known/agent-card.json or /.well-known/agent.json on either host.' - id: llms-txt conforms: false evidence: 'https://apileague.com/llms.txt returns HTTP 200 serving the catch-all homepage HTML, not an llms.txt.' - id: tls-1.3 conforms: true evidence: 'Both apileague.com and api.apileague.com negotiate TLSv1.3 — security/api-league-domain-security.yml.' - id: hsts conforms: false evidence: No Strict-Transport-Security header on apileague.com; none observed on api.apileague.com. - id: dnssec conforms: false evidence: apileague.com is not DNSSEC-signed. - id: caa conforms: false evidence: No CAA record on apileague.com. - id: spf conforms: true evidence: SPF record present on apileague.com. - id: dmarc conforms: true partial: true evidence: 'DMARC record present with policy p=none — published but not enforcing.' domain_standard: applicable: false note: >- REWARD-ONLY, and correctly empty here. API League is a general-purpose multi-category utility marketplace — books, news, humor, food, text NLP, media, web, games. There is no single vertical standard that governs that mix, so there is no domain standard for the contract to declare and none has been invented to fill the slot. Checked specifically for the shapes worth checking against this surface and found NONE of them: no SCIM schema URNs, no OData $metadata, no OpenRTB, no ActivityPub actor, no OAI-PMH verbs, no ORCID/DataCite/ Crossref identifier scheme on the books or art endpoints, no schema.org/JSON-LD typing in responses, no IPTC/NewsML vocabulary on the news endpoints, no FDC/USDA nutrient identifiers on the nutrition endpoints. The Books endpoints do surface Open Library cover URLs (covers.openlibrary.org) in their examples, which is a data-source lineage signal, not a conformance claim. candidates_checked: [scim2, odata, openrtb, activitypub, oai-pmh, orcid, datacite, crossref, schema-org, iptc-newsml, usda-fdc] compliance_program: published: false trust_center: false certifications: [] bug_bounty: false security_page: false note: >- Probed and absent: https://apileague.com/security/ returns the catch-all homepage, no security.txt on any host, and probe-security-programs.py found neither a vulnerability disclosure program nor a trust center. The operating company is skycraft GmbH of Dresden, Germany (https://apileague.com/about), and the terms of use place jurisdiction in Dresden — so the service sits inside the EU/GDPR regime by establishment. That is a legal fact about where the company is, NOT a published compliance certification, and it is recorded here rather than as a Compliance pointer for exactly that reason. privacy_disclosure: url: https://apileague.com/terms/ note: >- A Privacy Policy is published as a section of the combined Terms and Privacy page. It names Plausible Analytics as the analytics processor and describes cookie use. There is no separate /privacy page — that path returns the catch-all homepage. maintainers: - FN: Kin Lane email: info@apievangelist.com