generated: '2026-08-13' method: derived source: >- openapi/_original/buttondown-openapi.json, https://docs.buttondown.com/api-authentication, https://docs.buttondown.com/api-pagination, https://docs.buttondown.com/api-idempotency-keys, https://docs.buttondown.com/api-error-codes, https://buttondown.com/.well-known/security.txt description: >- Which cross-cutting standards the Buttondown API conforms to, judged from its published contract and documentation. Buttondown is an independent SaaS newsletter platform with no regulated-industry profile to conform to; the meaningful checks here are HTTP and API-hygiene conventions. standards: - id: openapi-3.1 conforms: true evidence: >- Publishes OpenAPI 3.1.0 live at https://api.buttondown.com/v1/openapi.json and in a public repository at https://github.com/buttondown/openapi — 77 paths, 133 operations, 230 component schemas, every operation tagged with a unique operationId. - id: openapi-webhooks conforms: true evidence: >- Uses the OpenAPI 3.1 top-level `webhooks` object to declare the outbound event POST and its WebhookEvent payload schema. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in the spec; authentication is a static API key. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every host. - id: api-key-auth conforms: true evidence: >- securitySchemes.ApiKeyAuth — apiKey in header, Authorization, "Token ". Keys carry independent per-area read/write/none permissions. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a vendor envelope {code, detail, metadata}; no application/problem+json media type and no type/title/status/instance members. - id: rfc9116-security-txt conforms: true evidence: >- https://buttondown.com/.well-known/security.txt returns 200 with Contact, Expires, Preferred-Languages, Canonical and Policy fields. - id: rfc5988-web-linking conforms: true evidence: >- Paginated responses carry a Link header with rel="next" and rel="prev", documented at https://docs.buttondown.com/api-pagination. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header contract is published; the deprecation mechanism is the dated version train instead. - id: idempotency-key conforms: true evidence: >- X-Idempotency-Key header accepted on any request, up to 200 characters, with the stored response retrievable via GET /v1/api_requests/{id}. Documented at https://docs.buttondown.com/api-idempotency-keys. - id: rate-limit-headers conforms: true partial: true evidence: >- Returns X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset on every response plus Retry-After on 429 — the de-facto X-RateLimit family, not the IETF RateLimit/RateLimit-Policy draft headers. - id: pagination conforms: true evidence: >- Page-number pagination with a count/next/previous/results envelope; next is a fully-qualified URL and is null on the last page. - id: api-versioning conforms: true evidence: >- Date-based version train (current 2026-04-01) selected by X-API-Version header with a per-newsletter pin, plus a published definition of what counts as breaking. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: psd2 conforms: false - id: fapi conforms: false compliance_program: published: false trust_center: false certifications: [] note: >- No trust center, SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim was found on buttondown.com or any subdomain. Buttondown publishes a security page (https://buttondown.com/blog/security) referenced from its security.txt Policy field, and legal terms and a privacy policy at /legal/terms and /legal/privacy, but no certification attestations. No `Compliance` pointer is emitted for this provider, because there is no published compliance program to point at.