specification: API Commons Conformance specificationVersion: '0.1' provider: Contentstack providerId: contentstack generated: '2026-09-17' method: derived source: openapi/*.yml in this repository, https://www.contentstack.com/docs/developer-hub/oauth-scopes, https://www.contentstack.com/docs/developers/apis/content-management-api and https://www.contentstack.com/trust description: Cross-cutting and domain standards Contentstack asserts in its own contracts. SCIM 2.0 is the domain standard for the identity market Contentstack sells into, and it is declared inside the contract itself, not merely claimed in prose. entries: - id: oauth2 conforms: true evidence: https://www.contentstack.com/docs/developer-hub/contentstack-oauth — OAuth 2.0 authorization-code flow issuing app and user tokens, with a published 95-scope reference at /docs/developer-hub/oauth-scopes. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any Contentstack host (all 404, probed 2026-09-17). OAuth is used for delegated API access, not as an identity layer. - id: scim conforms: true domain_standard: true evidence: 'openapi/contentstack-scim-users-api-openapi.yml, openapi/contentstack-scim-groups-api-openapi.yml and openapi/contentstack-scim-schema-discovery-api-openapi.yml declare the SCIM 2.0 schema URNs urn:ietf:params:scim:schemas:core:2.0:User, urn:ietf:params:scim:schemas:core:2.0:Group, urn:ietf:params:scim:api:messages:2.0:ListResponse, :PatchOp and :Error, served from https://auth-api.contentstack.com. Docs: https://www.contentstack.com/docs/developers/apis/scim-api' note: 'RFC 7643/7644. This is the reward-only domain_standard_conformance signal: an enterprise buying Contentstack for an Okta or Entra ID estate provisions users with the SCIM connector it already owns, with no bespoke integration.' - id: rfc9457 conforms: false evidence: No application/problem+json media type appears in any of the 33 OpenAPI documents. Errors are returned as a Contentstack-specific JSON body alongside conventional HTTP status codes — see errors/contentstack-problem-types.yml. - id: pagination conforms: true evidence: skip / limit offset pagination with include_count, documented at https://www.contentstack.com/docs/developers/apis/content-delivery-api#pagination and present as query parameters across the delivery and management specs. Collection endpoints cap at 100 records per response. - id: idempotency conforms: false evidence: No Idempotency-Key header, and no occurrence of the string "idempoten" anywhere in the Content Management API or Content Delivery API reference or in any OpenAPI document in this repository. Replaying a POST creates a second resource. - id: graphql conforms: true evidence: https://graphql.contentstack.com — a read-only GraphQL Content Delivery surface (queries only; no mutations, no subscriptions), documented at https://www.contentstack.com/docs/developers/graphql-api/about-graphql. - id: mcp conforms: true evidence: First-party MCP server @contentstack/mcp with 206 tools; per-group tool definitions published anonymously at https://mcp.contentstack.com//tools (HTTP 200). - id: webhooks conforms: true evidence: asyncapi/contentstack-webhooks-asyncapi.yml, grounded in https://www.contentstack.com/docs/developers/set-up-webhooks/about-webhooks. - id: gdpr conforms: true evidence: https://www.contentstack.com/trust — Data Protection Addendum, data-transfer risk assessment, subprocessor list at https://www.contentstack.com/legal/subprocessors (HTTP 200). - id: soc2 conforms: true evidence: https://www.contentstack.com/trust — SOC 2 Type II, audited on a recurring basis by an independent third party. - id: iso27001 conforms: true evidence: https://www.contentstack.com/trust — ISO 27001:2022 certified ISMS. Trust centre at https://trust.contentstack.com/ (HTTP 200).