generated: '2026-08-11' method: derived source: openapi/_original/btc-war-live-market-data-api-openapi.json + live response headers standards: - id: openapi-3.1 conforms: true evidence: "openapi: 3.1.0 served at https://btcwar.net/api/openapi.json as application/vnd.oai.openapi+json;version=3.1, plus a self-contained bundle." - id: arazzo-1.1 conforms: true evidence: "https://btcwar.net/api/arazzo.json declares arazzo 1.1.0 with one workflow bound to the OpenAPI operationId getLiveMarketObservation." - id: json-schema-2020-12 conforms: true evidence: "jsonSchemaDialect https://json-schema.org/draft/2020-12/schema; two published schema documents served as application/schema+json." - id: rfc9457-problem-details conforms: partial evidence: "404 and 502 responses are served as application/problem+json, but the body is a bare {error, supportedSymbols} object rather than an RFC 9457 member set (no type/title/status/detail)." - id: rfc9727-api-catalog conforms: true evidence: "/.well-known/api-catalog returns 200 as application/linkset+json with the RFC 9727 profile and 22 anchors." - id: rfc9264-linkset conforms: true evidence: "The API catalog is an RFC 9264 JSON linkset." - id: rfc9116-security-txt conforms: true evidence: "/.well-known/security.txt returns 200 with Contact, Expires, Preferred-Languages and Canonical." - id: rfc9530-content-digest conforms: true evidence: "Live responses carry Content-Digest: sha-256=:...: and expose it via access-control-expose-headers." - id: rfc8288-web-linking conforms: true evidence: "Every response carries a Link header with canonical, cite-as, alternate, describedby, service-desc, api-catalog and license relations." - id: rfc9110-conditional-requests conforms: true evidence: "ETag + Last-Modified emitted; If-None-Match and If-Modified-Since are declared components.parameters and 304 is a documented response on every GET." - id: schema-org-json-ld conforms: true evidence: "JSON-LD alternates typed as Schema.org DataFeed with a published context document." - id: w3c-dcat-3 conforms: true evidence: "/.well-known/dcat.jsonld describes a dcat:Catalog, dcat:Dataset, dcat:Distribution set and dcat:DataService." - id: mcp-2025-06-18 conforms: true evidence: "Streamable HTTP MCP server answered initialize with protocolVersion 2025-06-18 and tools/list with a typed inputSchema and outputSchema." - id: llms-txt conforms: true evidence: "/llms.txt and /llms-full.txt both return 200 as text/plain." - id: content-signals conforms: true evidence: "robots.txt and every API response carry Content-Signal: search=yes,ai-input=yes,ai-train=no,use=reference." - id: oauth2 conforms: false evidence: "No securitySchemes; the API is keyless by design." - id: rfc8594-sunset conforms: false evidence: "No Sunset or Deprecation headers observed and no deprecation policy published." compliance_program: published: false note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP certification is claimed anywhere on the site. This is a single-maintainer public read-only data project, so no Compliance pointer is emitted.