generated: '2026-08-13' method: derived source: openapi/_original/apollo-io-apollo-rest-api-openapi.json + https://trust.apollo.io/ standards: - id: openapi-3.1 conforms: true evidence: Apollo publishes OpenAPI 3.1.0 at https://docs.apollo.io/openapi/apollo-rest-api.json (80 operations). - id: oauth2-authorization-code conforms: true evidence: >- Partner OAuth 2.0 authorization-code flow with refresh tokens, documented at docs.apollo.io/docs/use-oauth-20-authorization-flow-to-access-apollo-user-information-partners; token endpoint https://app.apollo.io/api/v1/oauth/token. - id: rfc8414-authorization-server-metadata conforms: true evidence: 200 at https://mcp.apollo.io/.well-known/oauth-authorization-server (issuer, endpoints, 70 scopes, S256 PKCE). - id: rfc9728-protected-resource-metadata conforms: true evidence: 200 at https://mcp.apollo.io/.well-known/oauth-protected-resource; the MCP 401 also returns a WWW-Authenticate resource_metadata pointer. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://mcp.apollo.io/api/v1/oauth/applications/register_oauth_client. - id: openid-connect-discovery conforms: partial evidence: >- /.well-known/openid-configuration returns 200 with jwks_uri, subject_types_supported and id_token_signing_alg_values_supported, but Apollo documents the surface as OAuth 2.0 authorization for MCP rather than as an OIDC identity provider. - id: mcp-streamable-http conforms: true evidence: Remote MCP server at https://mcp.apollo.io/mcp over Streamable HTTP with OAuth 2.0; registry manifest io.github.apolloio/apollo-mcp. - id: rfc9457-problem-details conforms: false evidence: Error bodies are vendor JSON (error / error_code); no application/problem+json anywhere in the spec. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response header is documented; deprecation is marked in-spec only. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.apollo.io and api.apollo.io. - id: rfc8615-agent-card conforms: false evidence: No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Apollo host. - id: asyncapi conforms: false evidence: Apollo documents an async enrichment callback but publishes no AsyncAPI document. - id: graphql conforms: false evidence: No GraphQL endpoint is published or documented. - id: scim2 conforms: false - id: odata conforms: false - id: json-api conforms: false compliance_program: published: true url: https://trust.apollo.io/ certifications: [SOC 2, ISO 27001, GDPR] detail: security/apollo-io-trust-center.yml privacy: - {name: GDPR, url: 'https://www.apollo.io/privacy-policy'} - {name: API terms of service, url: 'https://www.apollo.io/terms/api'}