generated: '2026-08-07' method: derived source: openapi/bezero-carbon-ratings-openapi.yml searched: https://api-docs.bezerocarbonmarkets.com/ , https://bezerocarbon.com/about/governance , https://legal.bezerocarbon.com/legal-hub/product-specific-terms-ffc0b2c9 standards: - id: openapi-3.0 conforms: true evidence: openapi 3.0.0 published at https://api-docs.bezerocarbonmarkets.com/ (inlined in the ReDoc page) - id: oauth2 conforms: true evidence: components.securitySchemes.OAuth2 type oauth2, clientCredentials flow, tokenUrl https://login.bezerocarbonmarkets.com/oauth2/token - id: oauth2-client-credentials-rfc6749 conforms: true evidence: RFC 6749 section 4.4 client credentials grant, 4 scopes declared and applied per operation - id: rfc8414-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on login.bezerocarbonmarkets.com - id: oidc conforms: false evidence: no openIdConnect security scheme; /.well-known/openid-configuration 404 on every host - id: rfc9457-problem-details conforms: false evidence: no error response declares a schema or an application/problem+json content type - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 or soft-404 on all four BeZero hosts - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation response header documented; deprecation notice is contractual only - id: rfc6585-429 conforms: true evidence: 429 responses declare a Retry-After header on all four operations - id: pagination conforms: true evidence: page query parameter with links.nextPage / links.prevPage in the response envelope, fixed 100-item pages - id: incremental-sync conforms: true evidence: changedSince query parameter over dataLastUpdatedAt plus links.queryLatestChanges watermark - id: idempotency conforms: not-applicable evidence: all four operations are GET; no write surface exists - id: iso-8601 conforms: true evidence: all datetime fields (dataLastUpdatedAt, vintages.startDate/endDate, changedSince) specified as ISO 8601 strings - id: iso-3166-1-alpha-3 conforms: true evidence: projects[].location declared as "ISO 3166-1 alpha-3 country code for where this project is located" - id: json-api conforms: false evidence: bespoke JSON envelope (ratings[]/projects[] plus a links object), not the JSON:API media type - id: asyncapi conforms: not-applicable evidence: no event, streaming or webhook surface — the API is poll-based by design - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - id: mcp conforms: partial evidence: >- BeZero publishes a first-party MCP server on npm (@bezerocarbon/metabase-mcp-server) but it wraps Metabase, not the Ratings API. No MCP surface over BeZero rating data. compliance_program: published: false certifications: [] trust_center: false probes: - {url: 'https://trust.bezerocarbon.com/', status: NXDOMAIN} - {url: 'https://bezerocarbon.com/security', status: 404} note: >- No SOC 2, ISO 27001 or equivalent certification is published on any public BeZero page, so no Compliance pointer is emitted. What BeZero does publish is ratings-agency governance rather than an infosec compliance posture — see https://bezerocarbon.com/about/governance and the ratings governance and processes PDF. sector_frameworks: note: >- BeZero's public methodology and governance material engages with carbon-market frameworks (ICVCM Core Carbon Principles, CORSIA, Article 6, EU ETS, ACCU). These are the standards its RATINGS are read against — they are not API conformance claims and are recorded here only so the distinction is explicit. see: https://bezerocarbon.com/ratings/resources