generated: '2026-08-09' method: derived source: openapi/ (13 definitions, 46 operations) + live /.well-known probes + ChargeAfter documentation standards: - id: openapi-3.0 conforms: true evidence: All 13 published definitions declare openapi 3.0.1. - id: rfc9727-api-catalog conforms: true evidence: >- https://docs.chargeafter.com/.well-known/api-catalog returns 200 application/linkset+json with 62 entries carrying service-desc and service-doc links. Served by the ReadMe documentation platform. - id: rfc8414-oauth-authorization-server-metadata conforms: true scope: marketing site MCP endpoint only, not the payments API evidence: https://chargeafter.com/.well-known/oauth-authorization-server returns 200. - id: rfc9728-oauth-protected-resource-metadata conforms: true scope: marketing site MCP endpoint only, not the payments API evidence: https://chargeafter.com/.well-known/oauth-protected-resource returns 200. - id: oauth2 conforms: false evidence: >- No OpenAPI definition declares an oauth2 securityScheme. The payments API uses a static bearer credential. The only OAuth surface on any ChargeAfter host fronts the WordPress MCP endpoint. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every probed host. - id: rfc9457-problem-details conforms: false evidence: >- No operation returns application/problem+json. Errors use a proprietary { requestId, errors[] } envelope. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on chargeafter.com, www, docs and api hosts. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented in the API change guidelines. - id: idempotency-key-header conforms: false evidence: >- No Idempotency-Key header appears in any of the 46 operations. Idempotency exists only as a business key (lenderDisputeId) on dispute creation. - id: pagination conforms: false evidence: No cursor, offset, page, or limit parameter is declared on any operation. - id: rate-limit-headers conforms: false evidence: No 429 response and no RateLimit-* header is declared or documented. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: fapi conforms: false evidence: >- Relevant to a consumer-credit API, but ChargeAfter declares no FAPI profile, no mTLS, no proof-of-possession, and no OAuth surface on the payments API. - id: psd2 conforms: false evidence: ChargeAfter is a US-centric point-of-sale financing network; no PSD2/open-banking claim is made. - id: asyncapi conforms: false evidence: >- A webhook surface exists (10 documented events) but no AsyncAPI document is published. See asyncapi/chargeafter-notifications-webhooks.yml. compliance_program: published: false detail: >- No trust center, no security page, no compliance page, and no named certification (SOC 2, ISO 27001, PCI DSS, GDPR) is published on any ChargeAfter host. trust.chargeafter.com does not resolve; chargeafter.com/security, /compliance and /legal all return 404. This is a notable absence for a platform that transports consumer credit applications, PII and card data between merchants and 40+ lenders — no Compliance or TrustCenter pointer is asserted in apis.yml because there is nothing published to point at. probes: - url: https://trust.chargeafter.com/ status: 0 - url: https://chargeafter.com/security status: 404 - url: https://chargeafter.com/compliance status: 404 - url: https://chargeafter.com/legal status: 404 - url: https://chargeafter.com/.well-known/security.txt status: 404 x-evidence: fetched: '2026-08-09'