generated: '2026-07-25' method: derived source: >- openapi/ (four harvested specifications) plus the evidence trail recorded in review.yml; searched against Airtel's public developer surface for explicit conformance claims standards: - id: openapi-3.0 conforms: true evidence: >- openapi/bharti-airtel-iot-openapi.yml is OpenAPI 3.0.1 (43 operations); openapi/bharti-airtel-locate-openapi.yml is OpenAPI 3.0.0, API version 1.4.8 (19 operations). - id: swagger-2.0 conforms: true evidence: >- openapi/bharti-airtel-iq-sms-openapi.yml and openapi/bharti-airtel-iq-reporting-openapi.yml are Swagger 2.0, served live from openapi.airtel.in/gateway/*/v2/api-docs (HTTP 200). - id: oauth2 conforms: true evidence: >- Client-credentials token endpoints in two specifications (openapi/bharti-airtel-iot-openapi.yml#generateAccessTokenUsingPOST, openapi/bharti-airtel-locate-openapi.yml#getOrCreateOauthTokenUsingPOST_2) plus documented authorization-code and implicit flows in the legacy Smart API programme. caveat: >- Not declared as an OpenAPI securityScheme anywhere, and Locate transports the token in a custom `access_token` header rather than RFC 6750 `Authorization: Bearer`. - id: rfc6750-bearer-token conforms: false evidence: >- Airtel Locate requires the token in a bespoke `access_token` header parameter on every operation, not in an Authorization header. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404 on www.airtel.in, openapi.airtel.in and m2m.airteliot.co.in. developers.airtel.in returns 200 but serves its SPA HTML shell. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on every Airtel API host. - id: ciba conforms: false evidence: >- No CIBA backchannel authentication endpoint or documentation on any Airtel host — the authorization pattern CAMARA specifies for network APIs is absent. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json media type in any specification; see errors/bharti-airtel-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on www.airtel.in, openapi.airtel.in and m2m.airteliot.co.in. /security.txt on www.airtel.in returns HTTP 200 but serves the Angular SPA HTML shell (text/html), not an RFC 9116 document. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented; see lifecycle/. - id: llms-txt conforms: true evidence: >- https://www.airtel.in/llms.txt returns HTTP 200, text/plain, 529,945 bytes — a genuine provider-published llms.txt. Saved verbatim to llms/bharti-airtel-llms.txt. caveat: >- It is a consumer/SEO document covering airtel.in marketing pages. It does not describe the Airtel IQ, IoT or Locate API surface. - id: camara conforms: false evidence: >- No CAMARA endpoint, specification, or developer portal exists on any Airtel host. Airtel's SIM Swap API is delivered through a GSMA-certified federated Jio/Vi/Airtel channel and its wider network capability through Aduna and Nokia Network as Code — never directly from Airtel. Airtel is not listed on github.com/camaraproject. note: >- Airtel Locate is a real, consent-gated, publicly specified network location API, but it is Airtel's own product with its own path scheme — it is NOT the CAMARA DeviceLocation or LocationVerification API and must not be counted as one. - id: gsma-open-gateway conforms: partial evidence: >- Bharti Airtel was among the 21 founding carriers of GSMA Open Gateway (MWC, February 2023) and is named as a participating operator in the GSMA's October 2025 India federated network-services announcement. Membership is verified; no Open Gateway endpoint is published by Airtel. - id: tmforum-open-api conforms: false evidence: >- No TM Forum conformance certification was found and no TMF-numbered API is published on any Airtel host. The legacy Smart API router still whitelists a "/docs/Tmforum" route whose content has been removed — a dangling route, not an implementation. - id: 3gpp-nef-scef conforms: false evidence: No NEF or SCEF exposure surface is publicly documented by Airtel. - id: trai-dlt conforms: true evidence: >- openapi/bharti-airtel-iq-sms-openapi.yml requires entityId (DLT principal-entity id), dltTemplateId (DLT content-template id) and a registered sourceAddress on every DLT-scrubbed send, and enumerates the regulator's message classes PROMOTIONAL, TRANSACTIONAL, SERVICE_IMPLICIT, SERVICE_EXPLICIT, INTERNATIONAL. Indian A2P regulatory scrubbing is applied in-path. - id: subscriber-consent conforms: true evidence: >- openapi/bharti-airtel-locate-openapi.yml implements an explicit per-MSISDN consent lifecycle (initiateConsentUsingPOST_3, getConsentUsingGET_2, deleteResourceUsingDELETE_3) with states PROCESSING | INITIATED | PENDING | ALLOWED | REJECTED | FAILED, consent captured over SMS or IVR in nine Indian languages, and a 403 when a resource has not consented. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: psd2 conforms: false certifications_published: false certifications_note: >- 0-working/probe-security-programs.py returned trust=none for this provider: no trust centre, security portal or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, CSA STAR) is published on any airtel.in host reachable anonymously. Airtel publishes no compliance programme page for its API estate, so no `Compliance` pointer is emitted.