generated: '2026-07-18' method: derived source: derived from openapi/*.json + docs review standards: - id: openapi-3.0 conforms: true evidence: 11 OpenAPI 3.0.x specifications published via ReadMe - id: oauth2 conforms: false evidence: API uses API-key + HMAC-SHA256 signature auth, not OAuth2 - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: errors use a code/msg JSON envelope, not application/problem+json - id: hmac-request-signing conforms: true evidence: all authenticated requests signed with HMAC-SHA256 over the query/body (X-COINS-APIKEY + Timestamp + Signature headers) - id: idempotency conforms: true evidence: partner-assigned requestId provides idempotency validation on Payment API operations - id: binance-spot-api-compat conforms: true evidence: Coins Pro spot/markets/wallet endpoints mirror the Binance REST API surface (exchangeInfo, order, klines, depth, userDataStream) - id: websocket-user-data-stream conforms: true evidence: listenKey userDataStream endpoints back a WebSocket real-time stream - id: pci-dss conforms: false evidence: not published - id: soc2 conforms: false evidence: not published