generated: '2026-08-09' method: derived source: >- openapi/caplight-rest-api-openapi-original.json + well-known/caplight-oauth-authorization-server.json + well-known/caplight-oauth-protected-resource.json standards: - id: openapi-3.1 conforms: true evidence: >- openapi/caplight-rest-api-openapi-original.json declares openapi 3.1.0 with 26 operations and 68 component schemas, served publicly at https://us-central1-caplight-prod.cloudfunctions.net/api/v2/spec and rendered in Redoc. - id: mcp conforms: true evidence: >- Hosted remote MCP server at https://platform.caplight.com/mcp; JSON-RPC endpoint answers a tools/list POST with a 401 OAuth challenge rather than a transport error. - id: oauth2 conforms: true evidence: >- MCP surface only. authorization_code + refresh_token grants, code challenge S256 (PKCE), per well-known/caplight-oauth-authorization-server.json. The REST API uses a static api_key header and has no OAuth surface. - id: rfc8414-authorization-server-metadata conforms: true evidence: 'GET https://platform.caplight.com/.well-known/oauth-authorization-server -> 200 application/json' - id: rfc9728-protected-resource-metadata conforms: true evidence: >- GET https://platform.caplight.com/.well-known/oauth-protected-resource -> 200, and the /mcp sub-path variant also returns 200 - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://platform.caplight.com/mcp/register advertised in the AS metadata - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] - id: oidc conforms: false evidence: '/.well-known/openid-configuration returns 404 on both platform.caplight.com and www.caplight.com' - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a {status,error} or {message} body; no application/problem+json media type appears anywhere in the spec - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on every Caplight host' - id: rfc9727-api-catalog conforms: false evidence: '/.well-known/api-catalog returns 404 on every Caplight host' - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header observed; no deprecation policy published - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.caplight.com, platform.caplight.com and the production API host - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is published. The spec declares no webhooks and no callbacks; all 26 operations are GET. - id: json-api conforms: false evidence: responses are bespoke JSON objects, not JSON:API documents - id: pagination conforms: true evidence: >- Shared Pagination component (pageNumber/numPages/totalRecords) with pageNumber/pageSize query params across list endpoints - id: idempotency conforms: false evidence: read-only GET API; no idempotency key header or parameter in the spec compliance_program: published: false certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published on any public Caplight page; trust.caplight.com does not resolve and /trust, /security and /compliance return 404. No Compliance pointer is emitted. regulatory: note: >- Caplight is regulated as a broker-dealer rather than certified against an infosec standard. Securities are offered through Caplight Markets LLC, member FINRA/SIPC, and the company publishes a FINRA BrokerCheck link and a Form CRS. This is a regulatory registration, not an API conformance claim. finra_brokercheck: https://brokercheck.finra.org/firm/summary/103970 form_crs: https://www.caplight.com/Caplight-Markets-Form-CRS.pdf