generated: '2026-08-15' method: searched source: Derived from openapi/benchling-v3-openapi.yaml (securitySchemes, components.responses media types, pagination parameters, webhooks block) and openapi/_original/benchling-openapi.yaml, then checked against Benchling's own documentation — https://docs.benchling.com/docs/authentication, /docs/rate-limiting, /docs/stability-guidelines, /docs/webhook-verification — and live probes recorded in well-known/benchling-well-known.yml. description: 'What cross-cutting and industry standards the Benchling platform actually conforms to, with the evidence for each. The headline: v3 adopted RFC 9457 problem details, which is still uncommon in this catalog, while the platform publishes no /.well-known/ discovery of any kind and offers no idempotency key. Life-sciences regulatory posture, by contrast, is genuinely published: SOC 2 Type 2, ISO 27001:2022, FDA 21 CFR Part 11 and EU Annex 11 are all named on a public trust center, with the underlying reports behind a gated trust portal.' standards: - id: openapi conforms: true evidence: Two public specs served unauthenticated from Benchling's own host — https://benchling.com/api/v2/openapi.yaml (OpenAPI 3.0.1, 326 paths) and https://benchling.com/api/v3/openapi.yaml (OpenAPI 3.1.0, 805 paths, 874 operations, plus a top-level webhooks object). Both carry info.title "Benchling API" and an Apache-2.0 licence. - id: rfc9457 conforms: true scope: v3 only evidence: Every v3 error response is application/problem+json against the GeneralError schema, whose required members are exactly type, title, detail, status and instance. Shared via components.responses (BadRequest, Forbidden, NotFound, Conflict, PaymentRequired, TooManyRequests, InternalServerError). note: The v2 API does NOT conform — it returns a proprietary {"error":{"message","type","userMessage"}} envelope. See errors/benchling-problem-types.yml. - id: oauth2 conforms: true evidence: securitySchemes.oAuth declares an OAuth 2.0 clientCredentials flow with tokenUrl /oauth/token in v3 (and /api/v2/token in the documented app flow). Benchling Apps authenticate as service principals with client_id / client_secret. - id: oauth2-scopes conforms: false evidence: The clientCredentials flow declares an EMPTY scopes object in both v2 and v3. Authorization is by organization/team/project membership, not scopes — see scopes/benchling-scopes.yml. - id: oidc conforms: partial evidence: Benchling ACCEPTS OpenID Connect id tokens from a customer's IdP (Okta, Entra ID) as bearer credentials, verifying the signature against the customer's own /.well-known/openid-configuration and matching the `email` claim to an existing user. Benchling does not itself PUBLISH an OIDC discovery document — /.well-known/openid-configuration 404s on every Benchling host probed. It is an OIDC relying party, not an OIDC provider. docs: https://docs.benchling.com/docs/authentication - id: http-basic-auth conforms: true evidence: securitySchemes.basicApiKeyAuth (type http, scheme basic) — API key as username with an empty password; basicClientIdSecretAuth for the token exchange. - id: well-known-discovery conforms: false evidence: Every /.well-known/ path probed on benchling.com, www.benchling.com and docs.benchling.com either 404s or returns the HTML sign-in shell. No security.txt, no api-catalog, no openid-configuration, no oauth-authorization-server. See well-known/benchling-well-known.yml. - id: rfc9728-protected-resource conforms: unknown evidence: The MCP host (https://{tenant}.mcp.benchling.com) returns HTTP 403 JSON for /.well-known/oauth-protected-resource, so an anonymous client cannot confirm whether RFC 9728 metadata is served to authenticated callers. - id: idempotency conforms: false evidence: No Idempotency-Key header, parameter or documentation anywhere in the 874 v3 operations, the v2 spec, or docs.benchling.com/llms.txt. Safe retry is left to the caller. See conventions/benchling-conventions.yml. - id: pagination conforms: true style: token evidence: Uniform across every list endpoint — pageSize (default 50, max 100) plus an opaque nextToken cursor, declared as shared components.parameters. - id: rate-limit-headers conforms: partial evidence: Benchling returns x-rate-limit-limit, x-rate-limit-remaining and x-rate-limit-reset — informative, but a vendor-prefixed set rather than the IETF draft RateLimit-* fields, and no Retry-After on 429. - id: rfc8594-sunset conforms: false evidence: Benchling publishes a strong written deprecation policy (90 days for v3 stable, 6-12 months for v2 stable) but ships no Sunset or Deprecation response headers, so the policy is not detectable at runtime. See lifecycle/benchling-lifecycle.yml. - id: webhook-signature-verification conforms: true evidence: ECDSA signatures over `{Webhook-Id}.{Webhook-Timestamp}.{body}`, public keys distributed as a per-app JWKS at https://apps.benchling.com/api/v1/apps/{app_definition_id}/jwks with frequent rotation and a recommended 5-minute timestamp tolerance. Follows the Standard Webhooks header convention (Webhook-Id / Webhook-Timestamp / Webhook-Signature). docs: https://docs.benchling.com/docs/webhook-verification - id: jwks-rfc7517 conforms: true evidence: Per-app JSON Web Key Set published for webhook signature verification. - id: asyncapi conforms: false evidence: No AsyncAPI document published for either the webhook surface or the EventBridge event stream, despite 14 declared v3 webhooks and 23 v2 events. See asyncapi/benchling-webhooks.yml. - id: mcp conforms: true evidence: 'Official first-party remote MCP server at https://{tenant}.mcp.benchling.com/mcp; Benchling''s own stability guidelines commit the MCP to SemVer. Probed 2026-08-15: HTTP 403 JSON to an anonymous tools/list, i.e. a real gated MCP endpoint.' docs: https://help.benchling.com/hc/en-us/articles/40342713479437-Benchling-MCP-Server - id: a2a conforms: false evidence: No agent card. /.well-known/agent-card.json and /.well-known/agent.json 404 on www.benchling.com and docs.benchling.com; benchling.com answers 200 with its HTML sign-in shell, which is not a card. - id: llmstxt conforms: true evidence: https://docs.benchling.com/llms.txt — HTTP 200, real llms.txt format, indexing guides, recipes and changelog with .md twins for every page. Saved verbatim to llms/benchling-llms.txt. - id: graphql conforms: false evidence: No GraphQL endpoint is published. The schema in graphql/ is a derived conceptual model built from the REST API, not a live Benchling surface. - id: json-schema conforms: true evidence: v3 is OpenAPI 3.1.0, which uses JSON Schema 2020-12 for its component schemas; json-schema/ in this repo holds the extracted models. - id: fhir conforms: false evidence: Not applicable. Benchling is R&D/lab informatics (ELN, LIMS, registry), not clinical interoperability; no FHIR resources appear in either spec. - id: scim conforms: false evidence: No SCIM endpoints in either spec. User, Team, Organization and GroupMembership are managed through Benchling's own v3 resources, and enterprise SSO is handled at the IdP. - id: odata conforms: false evidence: Not an OData service. The analytic surface is a Postgres Data Warehouse queried with SQL. - id: json-api conforms: false evidence: Plain JSON resource representations; no JSON:API document structure. regulatory: - id: 21-cfr-part-11 conforms: true evidence: Named on Benchling's public trust center (https://www.benchling.com/trust, HTTP 200) alongside EU Annex 11. The v3 API exposes a first-class AuditLog resource with list/get operations, the technical substrate a Part 11 audit trail requires, and GxP validation support is an Enterprise-tier line item in plans/benchling-plans-pricing.yml. Underlying evidence sits behind the gated Trust Portal at https://securitytrust.benchling.com/. - id: gxp conforms: true evidence: Named on https://www.benchling.com/trust; validation support sold at the Enterprise tier. - id: soc2-type2 conforms: true evidence: SOC 2 Type 2 attestation named on https://www.benchling.com/trust, with AI features stated in scope. Report itself is gated behind the Trust Portal. - id: iso-27001 conforms: true evidence: ISO/IEC 27001:2022 certification named on https://www.benchling.com/trust (AI in scope); ISO/IEC 27017:2015 and 27018:2025 listed as alignments. - id: gdpr conforms: true evidence: GDPR compliance and EU-US Data Privacy Framework participation named on https://www.benchling.com/trust; privacy center at https://www.benchling.com/privacy. - id: ccpa conforms: true evidence: Named on https://www.benchling.com/trust. - id: hipaa conforms: false evidence: Not claimed. Benchling is R&D/preclinical informatics; no HIPAA attestation appears on the trust center. - id: fedramp conforms: false evidence: Not claimed on the trust center; no FedRAMP listing found. - id: audit-trail conforms: true evidence: AuditLog resource in v3 (Audit tag in v2) with list/get operations. - id: vulnerability-disclosure conforms: false evidence: No security.txt, no published disclosure policy and no bug bounty found; probe-security-programs.py returned vdp=none on 2026-08-15. See security/benchling-trust-center.yml. summary: conforms: 11 partial: 2 does_not_conform: 11 unknown: 1 regulatory_verified: 8 regulatory_absent: 3 trust_center: security/benchling-trust-center.yml