generated: '2026-08-06' method: derived source: openapi/arkestro-api-v2-openapi.yml searched: - https://arkestro.com/security/ - https://api.arkestro.com/.well-known/oauth-authorization-server standards: - id: openapi-3.1 conforms: true evidence: >- Published contract declares openapi: 3.1.1 and is served as a multi-file $ref bundle from https://api.arkestro.com/api-docs/v2/openapi.yaml - id: oauth2 conforms: true evidence: >- Authorization code grant with refresh_token, advertised at /.well-known/oauth-authorization-server - id: oauth2.1-pkce conforms: true evidence: >- code_challenge_methods_supported is ["S256"] and the authorization endpoint rejects a request without PKCE (HTTP 400 "code_challenge with code_challenge_method=S256 is required"), which is the OAuth 2.1 requirement rather than merely the OAuth 2.0 option. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 200 at /.well-known/oauth-authorization-server with issuer and endpoint metadata - id: rfc9728-oauth-protected-resource-metadata conforms: false evidence: >- 404 at /.well-known/oauth-protected-resource despite a protected MCP resource existing at /api/v2/mcp - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://api.arkestro.com/oauth/revoke - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://api.arkestro.com/oauth/introspect - id: openid-connect conforms: false evidence: >- No /.well-known/openid-configuration (404) and userinfo_endpoint is explicitly null in the authorization-server metadata. OAuth only, not OIDC. - id: mcp conforms: true evidence: >- Live remote MCP server at https://api.arkestro.com/api/v2/mcp with an mcp-prefixed OAuth scope namespace; authorization-gated (401) so protocol version was not negotiated - id: rfc9457-problem-details conforms: false evidence: >- All 4xx/5xx responses use a custom flat {"error": ""} object with additionalProperties false, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: 404 at /.well-known/security.txt on arkestro.com and api.arkestro.com - id: rfc9727-api-catalog conforms: false evidence: 404 at /.well-known/api-catalog - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header support documented, and no deprecated operations in the spec - id: a2a conforms: false evidence: >- 404 at /.well-known/agent-card.json and /.well-known/agent.json on arkestro.com, api.arkestro.com, docs.arkestro.com, developer.arkestro.com and mcp.arkestro.com - id: asyncapi conforms: false evidence: >- A real webhook contract is published (HMAC-SHA256 signing, retry schedule) but only as prose inside an OpenAPI x-traitTag; no AsyncAPI document and no OpenAPI 3.1 webhooks object - id: llmstxt conforms: false evidence: 404 at /llms.txt on arkestro.com, api.arkestro.com and docs.arkestro.com - id: hmac-webhook-signing conforms: true evidence: >- X-Arkestro-Signature sha256= over "{timestamp}.{raw_body}", with documented secret rotation via multiple comma-joined signatures and a 300s replay tolerance - id: iso-27001 conforms: true evidence: 'ISO 27001:2022 certified ISMS, stated at https://arkestro.com/security/' type: certification - id: soc2-type-ii conforms: true evidence: >- "We successfully pass SOC-2 Type II audits without exceptions", https://arkestro.com/security/ type: certification - id: hsts-preload conforms: true evidence: >- api.arkestro.com returns strict-transport-security: max-age=15552000; includeSubDomains; preload scope: api.arkestro.com only; arkestro.com sends no HSTS - id: dnssec conforms: false evidence: arkestro.com is not DNSSEC signed - id: caa conforms: false evidence: no CAA records on arkestro.com - id: dmarc conforms: true evidence: DMARC published with policy p=quarantine x-evidence: - url: https://api.arkestro.com/api-docs/v2/openapi.yaml http_status: 200 fetched: '2026-08-06' - url: https://api.arkestro.com/.well-known/oauth-authorization-server http_status: 200 fetched: '2026-08-06' - url: https://arkestro.com/security/ http_status: 200 fetched: '2026-08-06' - url: https://api.arkestro.com/api/v2/mcp http_status: 401 fetched: '2026-08-06'