generated: '2026-09-06' method: searched source: >- https://developer.autopay.io/ (authentication + API reference pages), https://api-auth.autopay.io/.well-known/openid-configuration (live probe), https://solutions.autopay.io/about-us/iso-certifications description: >- Standards and cross-cutting conformance for the Autopay API surface. Each entry is either a live probe result or a claim transcribed from a page the provider publishes; nothing is asserted from the shape of the API alone. conformance: - id: oauth2 name: OAuth 2.0 (RFC 6749) — client credentials grant conforms: true evidence: >- https://developer.autopay.io/authentication/ documents POST https://api-auth.autopay.io/oauth/token with client_id, client_secret, audience and grant_type=client_credentials, returning access_token / expires_in / token_type=Bearer, and the RFC 6749 error shape {"error":"access_denied","error_description":"Unauthorized"} on failure. - id: oidc-discovery name: OpenID Connect Discovery 1.0 (/.well-known/openid-configuration) conforms: partial evidence: >- https://api-auth.autopay.io/.well-known/openid-configuration returned HTTP 200 application/json on 2026-09-06 carrying issuer, token_endpoint, jwks_uri and id_token_signing_alg_values_supported. Saved verbatim to well-known/autopay-openid-configuration.json. deviations: - >- The document omits authorization_endpoint, response_types_supported, subject_types_supported and scopes_supported, which OIDC Discovery requires of a full OP. It is the reduced machine-to-machine discovery document an Auth0 tenant serves for a client-credentials-only API, not a complete OpenID Provider configuration. - id: oauth2-authorization-server-metadata name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: false evidence: 'https://api-auth.autopay.io/.well-known/oauth-authorization-server returned HTTP 403 on 2026-09-06.' - id: oauth2-protected-resource-metadata name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: false evidence: >- /.well-known/oauth-protected-resource returned 401 on api.autopay.io, 403 on api-auth.autopay.io and an SPA HTML shell on autopay.io, on 2026-09-06. - id: bearer-token-usage name: RFC 6750 Bearer Token Usage conforms: true evidence: >- "Your application must send this token in the HTTP Authorization header as a Bearer token" — https://developer.autopay.io/authentication/. A live unauthenticated GET to https://api.autopay.io/ returned 401 on 2026-09-06. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: true evidence: >- https://autopay.io/.well-known/security.txt returned HTTP 200 text/plain on 2026-09-06 with Contact, Preferred-Languages, Canonical and an unexpired Expires (2026-10-16). Saved to well-known/autopay-security.txt. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Autopay uses a custom flat envelope {error_id, message, description?} with no `type`, `title`, `status` or `instance` member and no application/problem+json media type — see the error tables on every page of https://developer.autopay.io/ and errors/autopay-problem-types.yml. - id: rfc8594-sunset-header name: RFC 8594 Sunset HTTP Header conforms: false evidence: >- Deprecation is announced only out-of-band, on https://developer.autopay.io/api_deprecation/ and by email to the registered Technical Contact Person. No Sunset or Deprecation response header is documented. - id: idempotency-key name: Idempotency-Key header (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: >- No idempotency key is documented on any Autopay write operation. The only idempotency guidance in the docs asks the INTEGRATOR to de-duplicate Autopay's callbacks using parking_id — https://developer.autopay.io/payment_api/. - id: ratelimit-headers name: RateLimit header fields for HTTP (RFC 9239 / draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: >- No RateLimit-*, X-RateLimit-* or Retry-After header is documented, and no 429 appears in the reference. Exhaustion surfaces as the error_id query_limit_error in an ordinary error body. - id: pagination-cursor name: Opaque cursor pagination conforms: true evidence: >- A `cursor` query parameter is documented on the Fleet services endpoints and the Statistics export, with cursor_decoding_error returned for a cursor the client constructed — https://developer.autopay.io/fleet-api/. - id: iso8601 name: ISO 8601 date-time representation conforms: true evidence: >- Every timestamp parameter in the reference is typed "datetime (ISO 8601)"; since Booking v3 all response timestamps are returned in UTC (e.g. "2023-03-17T00:00:00+0000"). - id: iso3166-1 name: ISO 3166-1 country codes conforms: true evidence: >- Plate country is carried as ISO 3166-1 alpha-2 on the Parking and Fleet webhooks (country_alpha2_code / country_code) and as alpha-3 on the Payment API (plate_issuer, documented as "Country code of the plate issuer (ISO 3166-1 alpha-3)"). note: >- The surface is internally inconsistent — alpha-2 on the event surface, alpha-3 on the payment surface — which an agent must handle explicitly. - id: iana-tz name: IANA time zone database identifiers conforms: true evidence: 'The Parking API entry webhook carries facility.time_zone "in the format Europe/Oslo" — https://developer.autopay.io/parking_api/.' - id: iso-27001 name: ISO/IEC 27001 Information Security Management conforms: true evidence: >- "At Autopay Technologies AS, we are proud to be ISO 9001, ISO 14001, and ISO 27001 certified" — https://solutions.autopay.io/about-us/iso-certifications (HTTP 200, 2026-09-06). note: The page names the certification but publishes no certificate number, certification body or scope statement. - id: iso-9001 name: ISO 9001 Quality Management conforms: true evidence: https://solutions.autopay.io/about-us/iso-certifications — quality policy at /about-us/iso-certifications/quality-policy - id: iso-14001 name: ISO 14001 Environmental Management conforms: true evidence: https://solutions.autopay.io/about-us/iso-certifications — environmental policy at /about-us/iso-certifications/environmental-policy - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: >- "Yes. Autopay is committed to processing personal data in accordance with the General Data Protection Regulation (GDPR) and applicable privacy legislation." — https://solutions.autopay.io/about-us/iso-certifications; privacy notice at https://solutions.autopay.io/privacy-policy. note: >- Material for this API specifically: the surface carries vehicle registration numbers and, on the Customer Club API, end-user phone numbers — personal data under GDPR in the EEA. - id: psd2 name: PSD2 / Open Banking conforms: false evidence: >- Autopay is a parking operator that bills for parking, not a payment institution exposing account or payment-initiation APIs. The Payment API hands billing responsibility to a third-party payment provider; Autopay never takes the card. No PSD2, SCA or Berlin Group claim appears anywhere on developer.autopay.io. - id: pci-dss name: PCI DSS conforms: unknown evidence: >- Not claimed on the ISO certifications page or anywhere else on solutions.autopay.io. No cardholder data flows through the documented API surface — the external payment provider "charges the customer using whatever payment method the customer has on file in the external payment provider's system". domain_standard: assessed: true declared: false note: >- The Autopay contract declares no domain standard for its market. Parking and kerbside mobility do have candidate interchange standards (APDS, the Alliance for Parking Data Standards data model; OCPI/OCPP on the EV-charging side Autopay also operates; DATEX II for European roadside data), but none of them appear anywhere in the Autopay reference, in the OpenAPI, or in the payload field names — Autopay's parking, permit and pricing payloads are entirely bespoke. This is recorded as an honest absence, not a failure: domain_standard_conformance is reward-only and nothing here is invented to fill the slot. candidates_probed: - {standard: APDS (Alliance for Parking Data Standards), found: false, where: developer.autopay.io full-text} - {standard: OCPI / OCPP, found: false, where: developer.autopay.io full-text} - {standard: DATEX II, found: false, where: developer.autopay.io full-text} summary: conformant: 10 partial: 1 not_conformant: 6 unknown: 1 certifications: [ISO 9001, ISO 14001, ISO/IEC 27001] regulatory: [GDPR]