generated: '2026-08-09' method: derived source: openapi/appsmax-rest-api-v1-openapi-original.json corroborated_by: https://appsmax.ru/developers/ standards: - id: openapi-3.0.3 conforms: true evidence: 'openapi: 3.0.3 published at https://appsmax.ru/developers/openapi.json; 17 paths, 21 operations, all with operationId and summary' - id: apis-json-0.21 conforms: true evidence: 'provider-published APIs.json index at https://appsmax.ru/apis.json (specificationVersion 0.21)' - id: llms-txt conforms: true evidence: 'https://appsmax.ru/llms.txt returns 200 text/plain' - id: api-onboarding-descriptor-0.1 conforms: true evidence: 'https://appsmax.ru/.well-known/api-onboarding returns an AOD 0.1 document declaring maturity console-only' - id: bearer-token-rfc6750 conforms: true evidence: 'securityScheme bearerAuth: type http, scheme bearer; Authorization: Bearer is the documented primary method' - id: idempotency-key conforms: partial evidence: >- Idempotency-Key request header (1-128 chars) on createApplication and createCampaign, with an Idempotency-Replayed response header and 409 on key reuse with a different body. Follows the de-facto Stripe-style convention rather than the IETF draft (draft-ietf-httpapi-idempotency-key-header) — the header name matches but no draft conformance is claimed and the other four write operations are not covered. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary application/json { error: { code, message, details, meta } } envelope, not application/problem+json. - id: ratelimit-headers conforms: partial evidence: >- X-RateLimit-Limit, X-RateLimit-Remaining and Retry-After are declared on 429 responses. These are the legacy X- headers, not the IETF RateLimit-* fields (draft-ietf-httpapi-ratelimit-headers); no RateLimit-Reset is published. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response headers are declared in the OpenAPI. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme; no authorization/token endpoint; /.well-known/oauth-authorization-server 404. Scopes exist but are attached to console-issued API tokens, not to an OAuth grant. - id: openid-connect conforms: false evidence: '/.well-known/openid-configuration returns 404 on both hosts' - id: json-api conforms: false evidence: >- Responses use a Laravel { data, links, meta } resource-collection envelope. It resembles JSON:API's top-level members but carries no type/id resource objects and the media type is application/json, not application/vnd.api+json. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt is 404 on both hosts, although a real disclosure policy is published as SECURITY.md at https://gitverse.ru/appsmax/appsmax-api-reference - id: asyncapi conforms: false evidence: >- x-appsmax-webhooks-covered is false in the OpenAPI; the provider states the outbound webhook payload/retry/security contract is not part of the public reference. - id: fhir-r4 conforms: false - id: scim-2.0 conforms: false - id: odata conforms: false - id: fapi conforms: false - id: psd2 conforms: false regulatory_context: jurisdiction: Russian Federation operator: IP Ainyukova Ayuna Purboevna infrastructure: Saint Petersburg, Russia personal_data: policy: https://appsmax.ru/documents/politika-obrabotki-personalnyh-dannyh/ note: >- The developer documentation instructs integrators to transmit only necessary fields and to define controller/processor roles, retention periods and deletion procedure. Russian Federal Law 152-FZ on personal data is the governing regime; AppsMax publishes a personal data processing policy but no independent certification. messaging: >- The docs state explicitly that the existence of a campaign endpoint does not override the law, recipient consent, or the messenger's own rules — bulk marketing messages into MAX private chats require separate platform permission. certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP certification is published, and no trust center exists. Do NOT read this as a compliance failure — it is a small Russian SaaS operator with no published third-party audit program. x-evidence: fetched: '2026-08-09' urls: - url: https://appsmax.ru/developers/openapi.json http_status: 200 - url: https://appsmax.ru/apis.json http_status: 200 - url: https://appsmax.ru/llms.txt http_status: 200 - url: https://appsmax.ru/.well-known/api-onboarding http_status: 200