generated: '2026-09-05' method: probed source: >- https://fedlogin.cat.com/.well-known/openid-configuration ; https://fedlogin.cat.com/.well-known/oauth-authorization-server ; live 401/404 responses from https://services.cat.com and https://api.cat.com ; Cat Digital ISO 15143-3 (AEMP 2.0) developer guide note: >- Caterpillar publishes no public OpenAPI, so nothing here is derived from a spec. Every entry below is either read out of a discovery document Caterpillar's own authorization server serves, or observed in a live response from its API gateway, or stated by Cat Digital's own developer documentation. standards: - id: oauth2 conforms: true evidence: >- https://fedlogin.cat.com/.well-known/oauth-authorization-server returns 200 with issuer https://fedlogin.cat.com and a full RFC 6749 endpoint set. - id: oidc-core conforms: true evidence: >- https://fedlogin.cat.com/.well-known/openid-configuration returns 200 with userinfo_endpoint, jwks_uri, id_token signing algs and claims_supported. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server served at 200 on fedlogin.cat.com. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [plain, S256]' note: >- `plain` is still advertised alongside S256, which RFC 8252 / OAuth 2.1 guidance discourages. - id: rfc9126-pushed-authorization-requests conforms: true evidence: 'pushed_authorization_request_endpoint: https://fedlogin.cat.com/as/par.oauth2' - id: rfc8628-device-authorization-grant conforms: true evidence: 'device_authorization_endpoint: https://fedlogin.cat.com/as/device_authz.oauth2' - id: rfc8693-token-exchange conforms: true evidence: 'grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange' - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://fedlogin.cat.com/as/clients.oauth2' - id: rfc7662-token-introspection conforms: true evidence: 'introspection_endpoint: https://fedlogin.cat.com/as/introspect.oauth2' - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint: https://fedlogin.cat.com/as/revoke_token.oauth2' - id: openid-ciba conforms: true evidence: 'backchannel_authentication_endpoint: https://fedlogin.cat.com/as/bc-auth.ciba' - id: rfc8705-mtls-client-auth conforms: true evidence: 'token_endpoint_auth_methods_supported includes tls_client_auth' - id: dpop conforms: partial evidence: >- dpop_signing_alg_values_supported is advertised, but no Cat Digital documentation describes DPoP-bound tokens for API consumers. - id: rfc9728-oauth-protected-resource-metadata conforms: false evidence: >- /.well-known/oauth-protected-resource returns 404 on fedlogin.cat.com, services.cat.com and api.cat.com. - id: rfc9457-problem-details conforms: false evidence: >- Error bodies are a bespoke {"code": "401.006", "description": "..."} JSON envelope served as application/json, not application/problem+json. Observed live on https://services.cat.com/telematics/iso15143/fleet/1. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt is served on any reachable Caterpillar host; fedlogin.cat.com answers 200 with a WAF interstitial rather than a document. - id: openapi conforms: false evidence: >- Cat Digital states in its API catalog overview that catalog APIs "meet a standard Open API Specification", but no spec is published outside the subscriber portal. Every anonymous probe of /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on services.cat.com and api.cat.com returned the gateway's 404 envelope. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented for the Cat Digital APIs. - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false domain_standards: - id: iso-15143-3 label: ISO 15143-3 (AEMP 2.0) — Earth-moving machinery, worksite data exchange conforms: true declared_in: contract evidence: >- The contract declares the standard in its own routing. The production base path is https://services.cat.com/telematics/iso15143 (mirrored at https://api.cat.com/telematics/iso15143); GET https://services.cat.com/telematics/iso15143/fleet/1 returns HTTP 401 {"code":"401.006","description":"Missing Authorization header or token value"}, i.e. the AEMP-shaped resource exists and is auth-gated rather than absent. Cat Digital's developer guide names the endpoint set as Fleet Snapshot, Equipment Snapshot and Timeseries (fault code, location, switch status, cumulative operating hours, cumulative idle operating hours, cumulative fuel used, engine condition, fuel remaining ratio) — the ISO 15143-3 / AEMP 2.0 element set. why_it_matters: >- ISO 15143-3 is the mixed-fleet telematics interchange standard for earth-moving machinery. A fleet operator or telematics platform that already ingests AEMP 2.0 from other OEMs can read Caterpillar machine data with no bespoke connector; one that does not needs a bilateral integration. Caterpillar, John Deere, CASE, Trackunit and Cartrack all expose the same shape, which is precisely the point of the standard. source: https://digital.cat.com/knowledge-hub/articles/iso-15143-3-aemp-20-api-developer-guide compliance_program: published: false note: >- No Caterpillar trust center, SOC 2 / ISO 27001 attestation page or published compliance program was found for the Cat Digital API estate. trust.cat.com and trust.caterpillar.com do not resolve; the corporate site is behind an Akamai edge policy that returns 403 to non-browser clients, so absence here is "not found", not "confirmed absent".