generated: '2026-08-06' method: derived source: openapi/asknicely-openapi.yml + well-known/ probes + https://www.asknicely.com/security description: >- Which cross-cutting and industry standards the AskNicely surface conforms to. The REST API is a pre-standards, API-key JSON API — no OAuth, no Problem Details, no standard pagination or rate-limit headers. The MCP/Ask NiceAI surface is where AskNicely's standards conformance actually lives, and it is genuinely current: RFC 8414, RFC 9728, RFC 7591 dynamic client registration and PKCE S256. standards: - id: openapi conforms: false evidence: >- AskNicely publishes no OpenAPI or Swagger document. The spec in openapi/ was written by API Evangelist from AskNicely's own HTML API reference. - id: oauth2 conforms: true scope: MCP server only evidence: >- https://mcp.asknice.ly/.well-known/oauth-authorization-server advertises authorization_code + refresh_token grants with an authorization, token and revocation endpoint. - id: oauth2-pkce conforms: true scope: MCP server only evidence: 'code_challenge_methods_supported: ["S256"] in the authorization-server metadata.' - id: rfc8414-authorization-server-metadata conforms: true scope: MCP server only evidence: 'GET https://mcp.asknice.ly/.well-known/oauth-authorization-server returns 200 application/json.' - id: rfc9728-protected-resource-metadata conforms: true scope: MCP server only evidence: 'GET https://mcp.asknice.ly/.well-known/oauth-protected-resource returns 200 application/json.' - id: rfc7591-dynamic-client-registration conforms: true scope: MCP server only evidence: 'registration_endpoint https://mcp.asknice.ly/register with registration_endpoint_auth_methods_supported ["none"].' - id: rfc6750-bearer-token conforms: true scope: MCP server only evidence: >- An anonymous POST to https://nicely.asknice.ly/mcp returns 401 with a compliant WWW-Authenticate Bearer challenge carrying error, error_description and resource_metadata. - id: mcp conforms: true evidence: >- First-party remote MCP server documented as a Claude custom connector at https://{domain}.asknice.ly/mcp; JSON-RPC endpoint responds to POST with an OAuth challenge. - id: openidconnect conforms: false evidence: 'No /.well-known/openid-configuration on any host (404 on www.asknicely.com; 302 to login on tenant hosts).' - id: rfc9457-problem-details conforms: false evidence: 'Errors are a proprietary {success, msg} envelope; no application/problem+json anywhere.' - id: rfc9116-security-txt conforms: false evidence: 'No /.well-known/security.txt on any AskNicely host.' - id: rfc8594-sunset-header conforms: false evidence: >- Deprecations are announced only as dated changelog entries; no Sunset or Deprecation response headers and no published notice period. - id: rfc9110-retry-after conforms: true evidence: 'A 429 response carries Retry-After alongside the proprietary RateLimit-Req10s-* headers.' - id: ietf-ratelimit-headers conforms: false evidence: >- Rate-limit signalling uses proprietary RateLimit-Req10s-Limit / RateLimit-Req60s-Limit headers rather than the draft-ietf-httpapi-ratelimit-headers RateLimit / RateLimit-Policy form. - id: json-api conforms: false evidence: 'Responses are ad-hoc JSON envelopes; no JSON:API media type or document structure.' - id: a2a conforms: false evidence: 'No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host.' - id: llms-txt conforms: false evidence: 'No /llms.txt on www.asknicely.com (404) or any asknice.ly host.' - id: gdpr conforms: true evidence: >- Dedicated erasure endpoint POST /api/v1/privacy/remove documented for automated GDPR delete requests; GDPR compliance and a data processing addendum stated on https://www.asknicely.com/security. - id: soc2 conforms: true evidence: 'AskNicely states SOC-2 compliance maintained by annual independent audit (https://www.asknicely.com/security).' - id: iso27001 conforms: partial evidence: >- ISO 27001 is named on the security page as a certification of the AWS datacenters AskNicely runs on, not of AskNicely itself. - id: pci-dss conforms: partial evidence: 'Named on the security page as an AWS datacenter certification, not an AskNicely certification.' - id: csa-star-caiq conforms: true evidence: 'AskNicely states it maintains a public Cloud Security Alliance CAIQ registry entry.' - id: scim2 conforms: true scope: identity provisioning, not the public API evidence: >- AskNicely documents SCIM provisioning configuration on Okta (https://asknicely.zendesk.com/hc/en-us/articles/33201312264340--Configuring-SCIM-on-Okta-for-AskNicely). The SCIM endpoints themselves are not part of the public API reference. - id: nz-privacy-act conforms: true evidence: 'Primary jurisdiction stated on https://www.asknicely.com/security; AskNicely is headquartered in Auckland, New Zealand.'