generated: '2026-09-05' method: searched source: >- https://www.dol.gov/data.json (fetched 2026-09-05), the DOL API Terms of Service and Getting Started reference at https://dataportal.dol.gov/, and live probes of https://apiprod.dol.gov/v4. provider: Bureau of International Labor Affairs providerId: bureau-of-international-labor-affairs summary: >- One real domain-standard conformance, declared by the artifact itself rather than claimed in prose: DOL publishes a Project Open Data / DCAT-US v1.1 catalog at https://www.dol.gov/data.json, and three ILAB datasets appear in it with ILAB-prefixed federal identifiers. Everything else in the usual cross-cutting list is genuinely absent — the API is an unscoped-API-key tabular query surface with no OAuth, no OIDC, no RFC 9457, no hypermedia and no OGC surface. conformance: - id: project-open-data-v1.1 name: Project Open Data / DCAT-US Schema v1.1 conforms: true evidence: https://www.dol.gov/data.json evidence_detail: >- The catalog's own conformsTo field is "https://project-open-data.cio.gov/v1.1/schema". Approximately 85 datasets, of which three are ILAB and carry federal data-inventory identifiers: ILAB-12-012:037-141 (List of Goods Produced by Child Labor or Forced Labor), ILAB-12-012:037-142 (List of Products Produced by Forced or Indentured Child Labor), ILAB-12-012:037-143 (Public Submissions for Child Labor and Forced Labor Reporting). All three are accessLevel "public". domain_standard: true market: government open data (US federal) note: >- This is the domain standard for this provider's market. An integrator who already speaks DCAT-US can harvest ILAB's inventory with no bespoke connector. Fetched via a browser-class client; the same URL returns an Akamai 403 to a plain crawler User-Agent, which is an edge bot policy, not an absence. observed: '2026-09-05' - id: oauth2 name: OAuth 2.0 conforms: false evidence: https://dataportal.dol.gov/getting-started evidence_detail: >- The only documented credential is X-API-KEY. No authorization server, no token endpoint, no scopes. /.well-known/oauth-authorization-server returns the AWS API Gateway route-not-found 403 on both api.dol.gov and apiprod.dol.gov. - id: oidc name: OpenID Connect conforms: false evidence: https://apiprod.dol.gov/.well-known/openid-configuration evidence_detail: 403 (AWS API Gateway route not found), observed 2026-09-05. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: https://apiprod.dol.gov/v4/get/ilab/Child_Labor_Report__2016_to_2022/json/metadata evidence_detail: >- 401 responses are plain-text English sentences; gateway errors are {"message": "..."} JSON. No application/problem+json anywhere. - id: pagination name: Documented pagination conforms: true evidence: https://dataportal.dol.gov/getting-started evidence_detail: >- limit + offset are documented parameters with defaults (10 / 0) and a stated ceiling (10,000 records or 5 MB), with a worked 20,000-record paging example. The catalogue endpoint additionally returns a meta block with current_page, next_page, prev_page, total_pages and total_count. - id: idempotency name: Idempotency keys conforms: false not_applicable: true evidence: https://dataportal.dol.gov/getting-started evidence_detail: >- Read-only API — no mutating operation exists, so there is nothing to replay-protect. - id: openapi name: OpenAPI description conforms: false evidence: https://apiprod.dol.gov/v4/openapi.json evidence_detail: >- 403 route-not-found. Every conventional spec path was probed on apiprod.dol.gov, api.dol.gov and dataportal.dol.gov. The portal DOES bundle Swagger UI, but it builds a per-dataset document client-side from the key-gated /metadata route, so no published static description exists to harvest. - id: ogc-api name: OGC API / OWS conforms: false not_applicable: true evidence_detail: >- No geospatial service is advertised anywhere in ILAB's or the portal's surface, so no OGC path was probed. Absence by evidence-led non-probing, per the pipeline rule against blind pattern sweeps. - id: json-api name: JSON:API conforms: false evidence: https://apiprod.dol.gov/v4/datasets evidence_detail: >- Plain JSON object with `datasets` and `meta` keys; no JSON:API media type, no data/attributes/relationships envelope. - id: fhir name: HL7 FHIR conforms: false not_applicable: true - id: scim name: SCIM conforms: false not_applicable: true - id: odata name: OData conforms: false not_applicable: true evidence_detail: >- The filter surface is a proprietary `filter_object` JSON string with eq/neq/gt/lt/ in/not_in/like operators, not $filter/$metadata. compliance_programs: published: false detail: >- ILAB is a bureau of a U.S. federal cabinet department, not a commercial vendor. No SOC 2, ISO 27001, PCI or FedRAMP attestation is published for the Open Data Portal — the data it serves is already public. The department does publish a BOD 20-01 vulnerability disclosure policy; see security/. maintainers: - FN: Kin Lane email: kin@apievangelist.com