generated: '2026-08-08' method: derived source: >- Observed behaviour of https://developer.builderprime.com/api/ plus the provider's published documentation page. No OpenAPI exists for this provider, so conformance is asserted from live responses and published prose only. standards: - id: rest conforms: true evidence: >- Resource-oriented JSON over HTTPS with method-differentiated collections and a correct 405 + Allow header on method violations. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published at any probed location on the marketing host, the docs host, or the API host root (/openapi.json, /openapi.yaml, /swagger.json, /v2/api-docs, /v3/api-docs, /api-docs, /api/openapi.json, /swagger-ui.html, /redoc all returned 404 on developer.builderprime.com). - id: asyncapi conforms: false evidence: Webhooks are advertised but no AsyncAPI document is published. - id: graphql conforms: false evidence: No /graphql surface found on any host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are returned as a vendor envelope {"success":false,"errors":[{"code","message"}]} with content-type application/json — not application/problem+json, and with no type URI. - id: oauth2 conforms: false evidence: >- Authentication is a static per-tenant API key in the x-api-key header. No OAuth flows are documented and /.well-known/oauth-authorization-server returns 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on all probed hosts. - id: rfc8414-oauth-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.builderprime.com and on the API host. - id: rfc8615-well-known conforms: false evidence: >- No /.well-known/ document of any kind was served — security.txt, api-catalog, openid-configuration, oauth-authorization-server, ai-plugin.json, agent-card.json and agent.json all returned 404. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy or Sunset header support is documented. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any probed host. - id: mcp conforms: false evidence: No Model Context Protocol server is published or referenced. - id: llms-txt conforms: false evidence: /llms.txt returns 404 on www.builderprime.com and help.builderprime.com. - id: api-versioning conforms: true evidence: >- Each resource collection carries an explicit /v1 path segment, so a version is always pinned by the caller. compliance_program: published: false certifications: [] trust_center: null note: >- No trust centre, security page or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR statement) was found. trust.builderprime.com returns 410 and /security, /trust and /compliance on the marketing site all return 404. No Compliance pointer is emitted. checked: '2026-08-08'