generated: '2026-09-04' method: searched source: >- BrowserStack product API reference pages, live probes of each API base URL and of /.well-known/ on every known host, https://www.browserstack.com/security, and the OpenAPI definitions in openapi/. Fetched 2026-09-04. provider: BrowserStack providerId: browserstack summary: conforms: 4 does_not_conform: 6 domain_standard: none-applicable conformance: - id: oauth2 conforms: true evidence: https://www.browserstack.com/.well-known/oauth-authorization-server detail: >- HTTP 200 JSON authorization-server metadata. Issuer https://auth.browserstack.com; grant types authorization_code, client_credentials, refresh_token; PKCE S256 and plain; token_endpoint_auth_methods client_secret_basic and client_secret_post; ten named scopes. The same document is served from api.browserstack.com and api-enterprise.browserstack.com. caveat: >- The metadata is real and complete, but no BrowserStack product API reference documents OAuth as a way to call it — all six document HTTP Basic with a long-lived access key. - id: oidc conforms: true evidence: https://auth.browserstack.com/.well-known/openid-configuration detail: >- HTTP 200 OpenID Provider metadata with userinfo_endpoint, jwks_uri, id_token_signing_alg_values_supported RS256, subject_types public, and claims iss/sub/aud/ exp/iat. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: https://mcp.browserstack.com/.well-known/oauth-protected-resource detail: >- HTTP 200 declaring resource https://mcp.browserstack.com/mcp, authorization_servers [https://mcp.browserstack.com], scopes_supported [read, write, admin], bearer_methods [header, body]. The MCP endpoint's 401 carries a matching WWW-Authenticate challenge pointing at this document — the full RFC 9728 discovery loop, correctly implemented. - id: json:api conforms: true evidence: https://www.browserstack.com/docs/percy/api-reference/authentication detail: >- The Percy API reference states "The Percy API is based on the JSON API standard and organized around the REST design." Confirmed at runtime: an unauthenticated GET to https://percy.io/api/v1/projects returns HTTP 401 with a JSON:API error object — {"errors":[{"status":"unauthorized","detail":"Percy::Errors::AuthenticationRequired"}]}. Scoped to Percy and App Percy only; no other BrowserStack API follows it. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: https://api.browserstack.com/automate/plan.json detail: >- No BrowserStack API returns application/problem+json. An unauthenticated Automate call returns HTTP 401 with content-type text/html and the body "HTTP Basic: Access denied." See errors/browserstack-problem-types.yml. - id: idempotency conforms: false evidence: https://www.browserstack.com/docs/automate/api-reference/selenium/introduction detail: No Idempotency-Key header or replay-protection mechanism is documented on any BrowserStack product API. - id: pagination conforms: false evidence: https://www.browserstack.com/docs/test-management/api-reference/introduction detail: >- Test Management docs state some endpoints "support pagination" but name no parameters, defaults or link fields. No other product API documents pagination at all, and no captured OpenAPI operation declares a page, offset or cursor parameter. - id: rfc8594 name: Deprecation and Sunset HTTP headers conforms: false evidence: https://www.browserstack.com/docs/automate/api-reference/selenium/introduction detail: No Deprecation or Sunset header, and no published deprecation policy. - id: openapi conforms: false evidence: https://api.browserstack.com/openapi.json detail: >- BrowserStack publishes no OpenAPI, Swagger or Postman contract for any of its six product APIs. Probed on the API host root and the docs host: /openapi.json, /openapi.yaml, /swagger.json, /api-docs all returned 404 on api.browserstack.com, and the docs host returns its HTML 404 shell for the same paths. Every API reference is HTML only. The specs in openapi/ are API Evangelist reconstructions of the Automate API from those docs, not provider-published contracts. - id: graphql conforms: false evidence: https://api.browserstack.com/graphql detail: >- No GraphQL surface. POST of an introspection query returned 404 on api.browserstack.com and www.browserstack.com; percy.io/graphql returned 405 from the marketing SPA, not a GraphQL response. compliance: published: true source: https://www.browserstack.com/security certifications: - SOC 2 - GDPR detail: See security/browserstack-trust-center.yml. domain_standard: applicable: false detail: >- Software test infrastructure has no cross-vendor interchange standard that a test-cloud API could declare — there is no SCIM, OData, FHIR, OpenRTB or ISO-20022 equivalent for cross-browser test execution. BrowserStack's contracts instead speak the de facto client protocols of the domain (W3C WebDriver for Automate, the Appium protocol for App Automate), but those are consumed by the test client against the grid endpoint, not declared by the REST management APIs profiled here. Recorded as not-applicable rather than as a failure. maintainers: - FN: Kin Lane email: kin@apievangelist.com