specification: API Commons Conformance specificationVersion: '0.1' provider: CrowdStrike providerId: crowdstrike generated: '2026-09-19' method: searched source: https://developer.crowdstrike.com/api-reference/collections/oauth2/ description: 'What the CrowdStrike Falcon API contract itself conforms to, plus the compliance programs CrowdStrike publishes on its trust portal. The API is a conventional vendor-shaped REST surface: OAuth2 client credentials over RFC 6749, a proprietary JSON envelope, a proprietary query language. It declares no domain standard for the security market on its contract, and none is invented here.' standards: - id: oauth2 conforms: true evidence: POST /oauth2/token client-credentials grant returning access_token/expires_in/token_type; POST /oauth2/revoke for revocation (RFC 7009-shaped) spec: RFC 6749 - id: oidc conforms: false evidence: The token response carries an id_token field, but no /.well-known/openid-configuration is served on any CrowdStrike host (probed 2026-09-19, 404/catch-all) — there is no OIDC discovery to conform to. - id: rfc9457-problem-details conforms: false evidence: Errors use a proprietary {meta,errors[],resources} envelope with integer codes; no application/problem+json anywhere in the reference. - id: rfc9116-security-txt conforms: true evidence: https://www.crowdstrike.com/.well-known/security.txt — Contact, Expires, Canonical, Policy, Preferred-Languages, Hiring - id: rfc8594-sunset-header conforms: false evidence: Deprecation is signalled in operation summary prose; no Sunset or Deprecation response header is documented. - id: pagination conforms: true evidence: offset/limit request params with meta.pagination.{offset,limit,total} on every list response - id: idempotency conforms: false evidence: No idempotency key or replay-protection mechanism is documented for any of the 685 mutating operations — see conventions/crowdstrike-conventions.yml - id: json-api conforms: false evidence: Proprietary envelope, not JSON:API media types - id: scim conforms: false evidence: User management is a Falcon-native collection (/user-management/...); no urn:ietf:params:scim:schemas URN appears anywhere in the reference - id: odata conforms: false - id: graphql conforms: true evidence: POST /identity-protection/combined/graphql/v1 (operationId api_preempt_proxy_post_graphql) — a real GraphQL surface, though the schema is auth-gated (401 anonymous, probed 2026-09-19) - id: mcp conforms: true evidence: First-party MCP server falcon-mcp, published to the MCP Registry with a server.json manifest against the 2025-12-11 server schema — see mcp/crowdstrike-mcp.yml spec: Model Context Protocol - id: ecs-elastic-common-schema conforms: true evidence: The CrowdStrike Parsing Standard, which Next-Gen SIEM parsers must follow, maps fields to Elastic Common Schema with documented deviations docs: https://developer.crowdstrike.com/ngsiem/overview/ domain_standard: true note: 'This is the closest thing to a domain-standard declaration on the CrowdStrike contract surface: it governs the SHAPE of ingested log data in the SIEM market, and it is stated by the provider, not inferred.' - id: mitre-attack conforms: true evidence: Detection behaviors carry MITRE ATT&CK tactic and technique identifiers throughout the detections/alerts surface domain_standard: true - id: stix-taxii conforms: false evidence: No STIX/TAXII endpoint is documented in the public API reference; intelligence is served through Falcon-native Intel collections and the FDR export. - id: openapi conforms: false evidence: No OpenAPI/Swagger document is published. The SDKs are generated from an internal swagger.json the gofalcon Makefile explicitly says must be obtained manually; probes of /openapi.json, /swagger.json, /openapi.yaml, /api-docs on api.crowdstrike.com all returned 404 on 2026-09-19. - id: asyncapi conforms: false evidence: Event Streams is documented as a REST-discovered streaming feed; no AsyncAPI document is published. compliance_programs: url: https://trust.crowdstrike.com/ certifications: - SOC 2 - ISO 27001 - ISO 27017 - PCI DSS - FedRAMP - GDPR - CSA STAR source: security/crowdstrike-trust-center.yml (probe-security-programs.py, 2026-09-19) maintainers: - FN: Kin Lane email: kin@apievangelist.com