generated: '2026-08-17' method: probed source: >- openapi/carbonfarm-cms-openapi.json + graphql/carbonfarm-cms-schema.graphql + well-known/carbonfarm-openid-configuration.json + well-known/carbonfarm-oauth-authorization-server.json summary: >- Standards posture split across two systems. The identity layer is strong because it is Auth0 (OIDC + RFC 8414 discovery, PKCE, DPoP algs advertised). The content API is weak on API-hygiene standards: no RFC 9457 errors, no RFC 9116 security.txt, no RFC 8594 deprecation signalling, no standard rate-limit headers. No compliance certification of any kind is published, so no `Compliance` pointer is emitted. standards: - id: openapi-3.0 conforms: true evidence: >- openapi/carbonfarm-cms-openapi.json declares openapi 3.0.1 with 14 operations, unique operationIds and declared securitySchemes. Auto-generated by Directus 10.10.7 at /server/specs/oas, not authored as a published contract. - id: graphql conforms: true evidence: >- Full SDL served anonymously at https://cms.int.carbonfarm.app/server/specs/graphql, including a Subscription root. - id: oidc conforms: true evidence: >- OpenID Connect discovery document at https://auth.carbonfarm.tech/.well-known/openid-configuration (HTTP 200) — issuer, authorization/token/userinfo/jwks endpoints, id_token signing algs, claims_supported. - id: oauth2 conforms: true evidence: >- Nine grant types advertised including authorization_code, client_credentials, refresh_token, device_code and token-exchange. - id: rfc8414-oauth-as-metadata conforms: true evidence: >- https://auth.carbonfarm.tech/.well-known/oauth-authorization-server returns 200 with authorization server metadata. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256, plain]' - id: rfc9449-dpop conforms: partial evidence: >- dpop_signing_alg_values_supported [ES256] is advertised by the authorization server. Whether any CarbonFarm resource server enforces DPoP is not observable — the CMS API uses static tokens, not DPoP-bound tokens. - id: rfc9101-request-object conforms: false evidence: 'request_parameter_supported: false and request_uri_parameter_supported: false' - id: rfc9728-oauth-protected-resource conforms: false evidence: >- /.well-known/oauth-protected-resource returns 404 on auth.carbonfarm.tech, carbonfarm.eu.auth0.com and cms.int.carbonfarm.app. No resource server advertises its authorization servers, so an agent cannot discover how to get a token for the API. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the Directus `{"errors":[{"message","extensions":{"code"}}]}` envelope. No application/problem+json, no type URI. See errors/carbonfarm-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every CarbonFarm host probed. - id: rfc8594-sunset-header conforms: false evidence: >- No deprecation policy, no Sunset or Deprecation header, and no API versioning scheme at all. See lifecycle/carbonfarm-lifecycle.yml. - id: rfc9110-conditional-requests conforms: partial evidence: >- Weak ETags ARE returned at runtime — observed `etag: W/"4657-5MLeDUDW4qIPXvtorcIqtAAVVAI"` on /server/specs/oas and `W/"1d4-..."` on /server/info — but the generated spec declares no ETag response header and no If-None-Match parameter on any operation. The capability exists and the contract does not mention it, so a consumer reading the spec would never use it. - id: ratelimit-headers-draft conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers observed on any anonymous response, and no limits documented. - id: json-api conforms: false evidence: >- Directus response envelope is {data, meta}, not the JSON:API document structure. - id: odata conforms: false - id: scim2 conforms: false - id: pagination-conventions conforms: true evidence: >- limit/offset/page query parameters plus an opt-in `meta` object carrying total_count and filter_count. See conventions/carbonfarm-conventions.yml. - id: idempotency-conventions conforms: false evidence: >- Zero matches for "idempoten" in the spec; no Idempotency-Key on any of the 14 operations. compliance: published: false certifications: [] note: >- No SOC 2, ISO 27001, GDPR statement page, trust center or compliance page exists on carbonfarm.tech — probe-security-programs.py returned trust=none. The company is French (SIREN 912160389, Nanterre) and therefore in GDPR scope, and it does publish a privacy policy, but a privacy policy is not a compliance program. No `Compliance` and no `TrustCenter` pointer is emitted. sector_standards: note: >- CarbonFarm's marketing and press describe work against carbon/MRV methodologies — Gold Standard dMRV for rice, the Sustainable Rice Platform (SRP) standard, and LSRS traceability guidance. Those are METHODOLOGY conformance claims about carbon projects, not API standards, and none of them is expressed in any machine-readable artifact the company publishes. They are recorded here as context and deliberately NOT asserted as API conformance. claims: - {standard: Gold Standard dMRV (rice), source: 'https://carbonfarm.tech/posts/Partners-in-Prosperity-CarbonFarm-to-Pilot-the-First-Gold-Standard-Rice-Project', machine_readable: false} - {standard: Sustainable Rice Platform (SRP), source: 'https://carbonfarm.tech/posts/carbonfarm-srp-lcam-phase-2-scope-3', machine_readable: false}