generated: '2026-09-05' method: searched source: >- openapi/cloudbees-unify-openapi.yml, openapi/cloudbees-unify-beta-openapi.yml, well-known/cloudbees-well-known.yml, well-known/cloudbees-mcp-oauth-protected-resource.json, well-known/cloudbees-id-openid-configuration.json, well-known/cloudbees-api-openid-configuration.json, security/cloudbees-trust-center.yml, packages/cloudbees-packages.yml standards: - id: openapi-3.0 conforms: true evidence: >- Both first-party specifications declare openapi 3.0.3 and are served from https://apidocs.cloudbees.io/docs/openapi-classic.yaml and .../openapi-public.yaml. - id: oauth2 conforms: true evidence: >- https://mcp.cloudbees.io/v1/mcp answers an unauthenticated request with an RFC 6750 Bearer challenge; the authorization server is https://id.cloudbees.io/realms/cloudbees. - id: oidc conforms: true evidence: >- https://id.cloudbees.io/realms/cloudbees/.well-known/openid-configuration returns a complete OIDC discovery document (saved as well-known/cloudbees-id-openid-configuration.json). - id: rfc9728-oauth-protected-resource conforms: true evidence: >- https://mcp.cloudbees.io/.well-known/oauth-protected-resource returns authorization_servers, bearer_methods_supported, resource and scopes_supported, and the same URL is advertised in the WWW-Authenticate header of a 401 from /v1/mcp. - id: rfc9116-security-txt conforms: true evidence: >- https://www.cloudbees.com/.well-known/security.txt returns a PGP-signed document with Contact, Encryption, Preferred-Languages, Canonical and Policy fields. - id: rfc6750-bearer conforms: true evidence: BearerAuth (http/bearer) is the global security scheme on both Unify specifications. - id: mcp conforms: true evidence: >- A published remote Model Context Protocol server at https://mcp.cloudbees.io/v1/mcp with 131 documented tools organised into nine toolsets selected by the X-MCP-Toolsets header. - id: oidc-workload-identity conforms: true evidence: >- https://api.cloudbees.io/.well-known/openid-configuration issues id_tokens whose claims include repository, run_id, run_number and run_attempt — a workflow-run identity issuer for federating CloudBees Unify runs into cloud providers without static credentials. - id: rfc9457-problem-details conforms: false evidence: >- The error envelope is google.rpc.Status over application/json, not application/problem+json. See errors/cloudbees-problem-types.yml. - id: idempotency-key conforms: false evidence: No Idempotency-Key parameter or header on any of the 65 published operations. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false evidence: >- User and team management is a bespoke REST surface (/v4/users, /v4/teams, /v4/teams/{id}/memberships) with no SCIM schema URNs and no /scim/v2 path. SAML SSO is supported (saml_connections_list, saml_email_domains_list) but user provisioning is not offered over SCIM in the public contract. - id: asyncapi conforms: false evidence: >- CloudBees ships outbound webhooks (see asyncapi/cloudbees-webhooks.yml) but publishes no AsyncAPI document for them. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json returned 404 on every non-catch-all host probed. See well-known/cloudbees-well-known.yml. - id: aauth conforms: false evidence: /.well-known/aauth-resource.json returned 404 on every non-catch-all host probed. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json returned 404 on every non-catch-all host probed. - id: rfc8594-sunset-header conforms: unknown evidence: >- A written maintenance-lifecycle policy exists, but Sunset/Deprecation response headers are not documented and no authenticated call could be made to observe them. domain_standards: - id: openfeature conforms: true market: feature flag management body: CNCF / OpenFeature evidence: >- CloudBees publishes first-party OpenFeature providers for CloudBees Feature Management in six ecosystems, from the cloudbees-oss GitHub organization and under CloudBees-owned package coordinates: Maven com.cloudbees.openfeature:cloudbees-openfeature-provider 1.0.1, NuGet CloudBees.OpenFeature.Provider 2.0.1, PyPI cloudbees-openfeature-provider-python 0.1.7, npm cloudbees-openfeature-provider-node 1.0.1 and cloudbees-openfeature-provider-browser 1.1.0, Packagist open-feature/cloudbees-provider 1.1.0, and Go github.com/cloudbees-oss/cloudbees-openfeature-provider-go v1.8.1. See packages/cloudbees-packages.yml. buyer_impact: >- A team already writing against the OpenFeature SDK can adopt CloudBees Feature Management by swapping the provider, with no bespoke connector and no rewrite of flag-evaluation call sites — and can leave the same way. That portability is the whole point of the standard. caveat: >- Conformance is at the SDK/provider layer, not declared inside the REST contract itself. The Unify OpenAPI documents carry no OpenFeature vocabulary; this entry is evidenced by published, registry- resolvable first-party provider packages, which is the strongest evidence this market's standard produces. currency_note: >- Five of the seven provider packages last released in the first half of 2025; only the browser provider shipped in 2026. Recorded as a currency observation, not a conformance failure. - id: jenkins-remote-api conforms: true market: continuous integration evidence: >- CloudBees CI is a hardened distribution of Jenkins and exposes the Jenkins remote access API (/api/json, /api/xml, /api/python with tree and depth parameters) on every controller. Any tool written against Jenkins works against CloudBees CI unchanged. See openapi/_original/cloudbees-openapi.yml and https://docs.cloudbees.com/docs/cloudbees-ci-kb/latest/best-practices/best-practice-for-using-jenkins-rest-api. - id: aip-158-pagination conforms: true market: cross-cutting evidence: >- The v4 beta specification paginates with pageSize / pageToken / orderBy and returns nextPageToken — the Google API Improvement Proposals list-pagination shape, consistent with the API being generated from protobuf service definitions (google.rpc.Status, google.protobuf.Any and google.protobuf.Value all appear in components.schemas). compliance: published: true trust_center: https://www.cloudbees.com/company/trust-center trust_portal: https://trust.cloudbees.com/ certifications: - SOC 2 - ISO 27001 - ISO 27017 - ISO 27018 privacy: GDPR cross_ref: security/cloudbees-trust-center.yml note: >- Certifications are read from the CloudBees trust portal probe (security/cloudbees-trust-center.yml). The probe's keyword scan also matched HIPAA and FedRAMP on that page; those two are recorded in the trust-center artifact but are not repeated as CloudBees certifications here, because the keyword hit does not establish which of them are CloudBees' own attestations rather than page context.