generated: '2026-09-04' method: derived source: >- openapi/_original/apivault-openapi.yml (harvested from https://api.apivault.dev/api/schema/) plus the live probes recorded in well-known/apivault-well-known.yml, errors/apivault-problem-types.yml and conventions/apivault-conventions.yml โ€” all 2026-09-04. note: >- Assertions only. ApiVault publishes no compliance programme, no certifications and no trust centre, so NO `Compliance` and NO `TrustCenter` pointer is emitted from this file. standards: - id: openapi-3.0.3 conforms: true evidence: >- openapi: 3.0.3 served live at https://api.apivault.dev/api/schema/, generated by drf-spectacular. 17 paths, 18 operations, 11 component schemas, unique operationIds throughout. - id: rfc6750-bearer-token conforms: true evidence: >- components.securitySchemes.jwtAuth is http/bearer; live 401s confirm the Authorization: Bearer requirement. deviation: >- The 401 carries no WWW-Authenticate header, which RFC 6750 ยง3 requires for a bearer challenge. - id: rfc7519-jwt conforms: true evidence: bearerFormat JWT (djangorestframework-simplejwt). - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme is declared. Google sign-in happens in the browser and only the resulting token is exchanged at POST /api/auth/google/; ApiVault is not itself an OAuth authorization server and publishes no /.well-known/oauth-authorization-server (404). - id: oidc conforms: false evidence: '/.well-known/openid-configuration returned 404 on both hosts.' - id: rfc9457-problem-details conforms: false evidence: >- Errors are the Django REST Framework {"detail": "..."} envelope with Content-Type application/json โ€” not application/problem+json, and with none of type/title/status/instance. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support; no deprecation policy. - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returned 404 on both hosts.' - id: rfc8615-well-known conforms: false evidence: >- No /.well-known/ document of any kind is served; sixteen named paths returned 404 on each of apivault.dev and api.apivault.dev. - id: rfc9727-api-catalog conforms: false evidence: '/.well-known/api-catalog and api-catalog.json both 404.' - id: json-api conforms: false evidence: >- Responses are bare JSON arrays/objects with no data/attributes envelope and no application/vnd.api+json media type. - id: pagination conforms: false evidence: >- GET /api/all returns all 1,454 records in one unpaginated array. No limit/offset/cursor parameters, no pagination envelope, no Link header. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent on any of the four mutating operations. See conventions/apivault-conventions.yml. - id: a2a conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json both 404.' - id: mcp conforms: false evidence: >- No MCP server is published by the provider on any host or in any registry. See mcp/apivault-mcp.yml. - id: llms-txt conforms: false evidence: 'https://apivault.dev/llms.txt returned 404.' domain_standards: note: >- ApiVault's market is API discovery and cataloguing. The domain standard for that market is APIs.json (specificationVersion / apis[]) โ€” the format this very repository is written in. ApiVault does not publish one, which is the single most consequential domain-standard gap available to it: an API directory that is not itself machine-discoverable. standards: - id: apis-json conforms: false evidence: >- Probed https://apivault.dev/apis.json (404), https://apivault.dev/.well-known/apis.json (404), https://apivault.dev/apis.yml (404) and the same three on api.apivault.dev (404) on 2026-09-04. Nothing carrying `apis` or `specificationVersion` is served. opportunity: >- The catalogue is already exposed as JSON at https://api.apivault.dev/api/all; rendering the same records as an APIs.json index at https://apivault.dev/apis.json would make 1,454 entries discoverable to every APIs.json-aware crawler. - id: openapi-index conforms: false evidence: >- The directory records only a name, category, auth type, CORS flag, HTTPS flag and a URL per API. It does not record or link an OpenAPI, AsyncAPI or any other machine-readable contract for the APIs it lists, so the catalogue cannot be traversed by a machine past the landing URL.