generated: '2026-06-20' method: derived source: openapi/*.json + developers.cash.app technical guides standards: - id: oauth2 conforms: false evidence: Cash App Pay uses signed scoped API keys, not OAuth2; Afterpay uses HTTP Basic. - id: http-basic-rfc7617 conforms: true evidence: Afterpay Global API securityScheme sec0 is http/basic (RFC 7617). - id: hmac-request-signing conforms: true evidence: Network/Management APIs require an HMAC-SHA256 X-Signature header (V1 scheme). - id: idempotency-keys conforms: true evidence: idempotency_key required on all write endpoints; region-scoped; IDEMPOTENCY_KEY_REUSED enforcement. - id: cursor-pagination conforms: true evidence: list/search endpoints use cursor pagination with INVALID_CURSOR handling. - id: rfc9457-problem-details conforms: false evidence: errors returned as a custom errors[] array with category/code/detail/field, not application/problem+json. - id: webhooks conforms: true evidence: 11 documented webhook event types with signed delivery (Management API webhook endpoints). - id: rfc8594-sunset-deprecation-headers conforms: false evidence: versioning uses published support windows; no documented Sunset/Deprecation response headers. - id: pci-dss conforms: unknown evidence: | Cash App Pay Kit is loaded only from the Cash App CDN specifically to help partners avoid PCI scope, implying Block operates under PCI DSS, but no certification artifact is published in the developer portal - not asserted as a published compliance program. compliance_note: | No SOC 2 / ISO 27001 / PCI DSS certification documents are published in the developer portal, so no type: Compliance pointer is emitted (would require a published compliance program per the rubric).