generated: '2026-08-13' method: derived source: >- openapi/_original/constant-contact-v3-openapi.yml (build 3.0.178) + https://developer.constantcontact.com/api_guide/auth_overview.html + https://developer.constantcontact.com/api_guide/scopes.html + https://developer.constantcontact.com/api_guide/rate_limits.html + live /.well-known probes provider: Constant Contact providerId: constant-contact description: >- Which industry and cross-cutting standards the Constant Contact V3 API actually conforms to, each with the evidence that decided it. Absence is recorded as plainly as presence. standards: - id: openapi conforms: true version: Swagger 2.0 evidence: >- The provider publishes a machine-readable contract at https://api.cc.email/v3/swagger.yaml (HTTP 200, 707 KB, swagger "2.0", 100 paths, 128 operations, 286 definitions). It is a genuine spec, not a docs shell. It is one major version behind current — OpenAPI 3.x is not published. - id: oauth2 conforms: true evidence: >- securityDefinitions declare oauth2 with authorizationUrl https://authz.constantcontact.com/oauth2/default/v1/authorize and tokenUrl .../v1/token. The docs document authorization-code, PKCE, device and implicit flows and a space-delimited scope parameter. - id: oauth2-pkce conforms: true evidence: >- developer.constantcontact.com/api_guide/pkce_flow.html (HTTP 200) documents the PKCE flow for public clients. - id: rfc8628-device-flow conforms: true evidence: developer.constantcontact.com/api_guide/device_flow.html (HTTP 200). - id: oauth2-implicit conforms: true deprecated_practice: true evidence: >- The spec still declares an implicit-flow securityScheme (oauth2_implicit). Implicit is discouraged by OAuth 2.1 and RFC 9700 BCP; its continued presence in the contract is a finding, not a credit. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: >- https://authz.constantcontact.com/.well-known/oauth-authorization-server returns 404, as does the /oauth2/default/ prefixed variant. No discovery document is served. - id: oidc conforms: false evidence: >- https://authz.constantcontact.com/.well-known/openid-configuration returns 404. No openIdConnect securityScheme is declared and no id_token or OIDC scope (openid, profile, email) is documented. The five documented scopes are all vendor-defined. - id: rfc9728-oauth-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource returns 403 on api.cc.email and 404 elsewhere. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a vendor {error_key, error_message} envelope — usually wrapped in an array. No application/problem+json media type appears anywhere in the contract. See errors/constant-contact-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation response header is declared on any operation, and no operation carries deprecated:true. Deprecations are prose-only on the release-notes page. - id: idempotency conforms: false evidence: >- No Idempotency-Key (or equivalent) parameter or header exists on any of the 128 operations and none is documented. The only concurrency signal is a 409 on simultaneous contact modification. - id: pagination conforms: true style: cursor (HAL _links.next.href), with one offset-paged exception evidence: >- 27 collection operations take a limit parameter and return a HAL-shaped _links envelope; findEvents and findRegistrationsUsingGET expose explicit next/prev cursors; getPartnerSiteOwners is offset-paged. Consistent in intent, inconsistent in shape — the contract carries nine distinct link-wrapper definitions. - id: rate-limit-headers conforms: false evidence: >- The rate-limits guide documents 4 req/sec and 10,000 req/day and a 429 on exhaustion, and explicitly returns no X-RateLimit-*, RateLimit-* or Retry-After header. The client learns which ceiling it hit only from the error_key value. - id: hal conforms: partial evidence: >- Collections and asynchronous activities return _links with self/next/prev/results hrefs and the spec calls them "HATEOS-style". Individual resources do not. Links are path-relative, omitting scheme and origin. - id: json-schema conforms: partial evidence: >- Swagger 2.0 definitions are JSON Schema draft-4 subset. This repo additionally publishes hand-cut JSON Schema documents in json-schema/ and a JSON Structure document in json-structure/. - id: webhooks conforms: partial evidence: >- Four partner billing webhook topics exist, managed through /partner/webhooks/subscriptions/{topic_id}. There is NO contact- or campaign-event webhook surface in the contract, no signature/HMAC verification scheme is documented, and no AsyncAPI is published. See asyncapi/constant-contact-webhooks.yml. - id: asyncapi conforms: false evidence: No AsyncAPI document is published on any Constant Contact host. - id: mcp conforms: false evidence: >- No Model Context Protocol server. mcp.constantcontact.com and mcp.cc.email are NXDOMAIN; /mcp on the API and docs hosts returns 403. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json miss on all four hosts (403 on api.cc.email and developer.constantcontact.com, 404 on www.constantcontact.com and authz.constantcontact.com). - id: llms-txt conforms: true evidence: >- https://www.constantcontact.com/llms.txt returns 200 with a well-formed llms.txt (H1, blockquote summary, five link sections). Marketing-oriented — it does not name the API host, the spec, or the SDKs. - id: tls conforms: true evidence: >- TLSv1.3 on www.constantcontact.com, developer.constantcontact.com and api.cc.email. See security/constant-contact-domain-security.yml. - id: dnssec conforms: false evidence: Neither constantcontact.com nor cc.email is DNSSEC-signed; no CAA records on either. - id: spf-dmarc conforms: true evidence: >- constantcontact.com publishes SPF and a DMARC record with p=reject — notable for an email service provider, since its own sending domain posture is part of the product. - id: security-txt conforms: false evidence: >- RFC 9116 /.well-known/security.txt is not served on any host. No bug-bounty or vulnerability disclosure program was found by probe-security-programs.py. compliance_claims: published: unverified note: >- Constant Contact's marketing host sits behind a Cloudflare bot challenge — /trust-center, /legal/trust-center, /security and /legal/security all returned 403 "Just a moment..." to both curl and WebFetch. No certification claim (SOC 2 / ISO 27001 / HIPAA / PCI) could be verified from a machine-readable or fetchable source, so this profile emits NO Compliance pointer. That is a probe limitation on our side as much as a provider gap, and it is recorded rather than guessed. probes: - url: https://www.constantcontact.com/trust-center status: 403 - url: https://www.constantcontact.com/legal/trust-center status: 403 - url: https://www.constantcontact.com/legal/security status: 403 not_applicable: - fhir - fapi - psd2 - scim - odata - json:api - grpc