generated: '2026-08-12' method: derived source: openapi/ciloo-cart-api-openapi.yml docs: https://api.cilooprint.com/ciloo-cart-api-documentation/ standards: - id: oauth1a-rfc5849 conforms: true evidence: >- Authorization header uses the RFC 5849 "OAuth" scheme with HMAC-SHA1, oauth_consumer_key, oauth_signature_method, oauth_timestamp, oauth_nonce, oauth_version and oauth_signature, and a documented signature base string. caveat: >- Partial. The provider documents that oauth_timestamp and oauth_nonce are accepted without validation, so RFC 5849's replay protection is not enforced. - id: http-basic-rfc7617 conforms: true evidence: generateCustomerLoginToken authenticates with consumer key/secret as HTTP Basic credentials. - id: oauth2 conforms: false evidence: No OAuth 2.0 scheme, authorization server or scope surface is published. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Ciloo host. - id: rfc9457-problem-details conforms: false evidence: Errors use a bespoke {success, error{code,message,details,timestamp}, debug{}} envelope, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Ciloo host. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy or Sunset/Deprecation header support is published. - id: openapi conforms: false evidence: >- Ciloo publishes prose documentation and a Postman collection; it publishes no OpenAPI. The spec in openapi/ was generated by API Evangelist from those provider-published sources. - id: asyncapi conforms: false evidence: A real bidirectional webhook surface is documented in prose; no AsyncAPI document is published. - id: postman-collection-v2.1 conforms: true evidence: >- First-party collection published for download, schema https://schema.getpostman.com/json/collection/v2.1.0/collection.json. - id: json-api conforms: false evidence: Responses are plain JSON with a bespoke envelope. - id: idempotency conforms: false evidence: No idempotency key or retry-safety contract is documented on any operation. - id: pagination conforms: false evidence: The cart is returned whole; no page/limit parameters are documented. compliance_program: published: false note: >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS / HIPAA claim and no certification page was found on ciloo.com or cilooprint.com. GDPR is addressed only inside the general privacy policy. No Compliance pointer is emitted. probed: - {url: 'https://ciloo.com/privacy-policy/', status: 200} - {url: 'https://ciloo.com/terms-conditions/', status: 200}