generated: '2026-08-06' method: derived source: openapi/barogo-gorela-openapi.yml + https://developer.gorelas.com/api-docs-md/common-doc.md note: >- Derived from the Gorela reference and the OpenAPI transcribed from it. Barogo publishes no certification, no compliance program page and no trust centre, so nothing here is a claim the provider makes — these are observations about the contract itself. standards: - id: openapi conforms: false evidence: >- Barogo publishes no OpenAPI document. The spec in openapi/ was derived by API Evangelist from the provider's published markdown reference. - id: asyncapi conforms: false evidence: No AsyncAPI document, despite a 20-event webhook surface that would map cleanly onto one. - id: oauth2 conforms: false evidence: Static bearer API key only; no authorization server, no flows, no scopes. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc9457-problem-details conforms: false evidence: >- Custom error envelope {statusCode, error:{category, errorCode, message}}; responses are application/json, not application/problem+json. - id: rfc7807 conforms: false evidence: Same — no problem+json media type. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on barogo.com and the SPA shell on developer.gorelas.com. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published. - id: rfc6750-bearer-token conforms: true evidence: 'Authorization: Bearer {API_Key} — the documented and only auth mechanism.' - id: json-api conforms: false evidence: Custom envelope, not JSON:API document structure. - id: iso8601 conforms: false evidence: >- Timestamps are epoch milliseconds at GMT+00:00, not ISO 8601 strings — a deliberate, documented choice, but it means dates are not self-describing on the wire. - id: wgs84 conforms: true evidence: 좌표 체계 WGS84, 소수점 이하 6 자릿수 이상 — published in the common reference. - id: rfc7231-status-semantics conforms: partial evidence: >- HTTP status use is largely conventional (200/201/204/207/4xx/5xx, including a correct 207 Multi-Status for delivery-agency fan-out), but several business rejections are returned as 200 with data.isSuccess=false rather than a 4xx. - id: webhooks conforms: true evidence: 20 documented POST callbacks with typed payloads, a stated 3s response deadline and a 2s/18s/50s retry schedule. - id: mcp conforms: partial evidence: >- A first-party MCP server exists (gorela-developer-mcp-server, stdio, @modelcontextprotocol/sdk), but it serves documentation only and binds to no API operation. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. compliance_program: published: false certifications: [] trust_center: null detail: >- No SOC 2, ISO 27001, PCI DSS or equivalent certification is published on barogo.com or developer.gorelas.com. Korean statutory pages exist on the corporate site — a location-based services policy (위치기반서비스 이용약관), a delivery service policy and a privacy policy — which is what a Korean location-data operator is required to publish, but they are consumer terms, not a security-compliance posture. statutory_pages: - name: 위치기반서비스 이용약관 (location-based services terms) url: https://www.barogo.com/policy/locationbased - name: 배달대행 서비스 이용약관 (delivery service terms) url: https://www.barogo.com/policy/delivery - name: 개인정보처리방침 (privacy policy) url: https://www.barogo.com/policy/privacy x-evidence: fetched: '2026-08-06' url: https://developer.gorelas.com/api-docs-md/common-doc.md http_status: 200