generated: '2026-08-11' method: probed source: https://cubbystorage.github.io/docs/api/ description: >- Cross-cutting standards conformance for Cubby, asserted only where a probe or the provider's own documentation supports it. Cubby's standards posture is bimodal: the MCP server is correctly built on the modern OAuth discovery RFCs, while the REST API it sits beside conforms to essentially no cross-cutting convention — not REST, not RFC 9457, no standard pagination, no idempotency, no rate-limit headers. standards: - id: oauth2 name: OAuth 2.0 / 2.1 Authorization Code with PKCE conforms: true scope: Cubby MCP Server only evidence: >- /.well-known/oauth-authorization-server returns 200 declaring response_types_supported ["code"], grant_types_supported ["authorization_code","refresh_token"] and code_challenge_methods_supported ["S256"]. url: https://api.cubbystorage.com/.well-known/oauth-authorization-server - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: 200 at /.well-known/oauth-authorization-server with issuer, authorization_endpoint, token_endpoint and registration_endpoint. url: https://api.cubbystorage.com/.well-known/oauth-authorization-server - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- 200 at /.well-known/oauth-protected-resource declaring authorization_servers, resource, scopes_supported and bearer_methods_supported; and the 401 from /mcp carries the matching WWW-Authenticate Bearer resource_metadata challenge. url: https://api.cubbystorage.com/.well-known/oauth-protected-resource - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://api.cubbystorage.com/connect/register advertised in the authorization server metadata. - id: rfc6750 name: OAuth 2.0 Bearer Token Usage conforms: true evidence: >- bearer_methods_supported ["header"]; the REST API also uses `Authorization: Bearer `, though with a static key rather than an OAuth token. - id: mcp name: Model Context Protocol conforms: true scope: transport and authorization only evidence: >- Live JSON-RPC endpoint at https://api.cubbystorage.com/mcp returning a spec-shaped 401 challenge. Tool-level conformance could not be assessed — tools/list is auth-gated. url: https://api.cubbystorage.com/mcp - id: rest name: REST conforms: false evidence: >- Cubby states it directly in its own introduction — "This is a JSON HTTP API. It is not a RESTful API." Every operation is POST, including reads. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors use a bespoke {"code": , "errors": []} envelope with application/json, not application/problem+json, and carry no type URI or stable error identifier. - id: idempotency name: Idempotency keys for unsafe requests conforms: false evidence: >- No Idempotency-Key header or retry-deduplication semantics documented anywhere in the reference, on an API where checkout and make-payment move money over POST. - id: pagination name: Documented pagination conforms: false evidence: >- No pagination model is described in the API introduction and none is stated for the search endpoints. - id: rate_limiting name: Rate limit signalling (RateLimit / X-RateLimit / Retry-After) conforms: false evidence: No rate limits and no rate-limit response headers documented. - id: rfc8594 name: Sunset header for deprecation conforms: false evidence: >- Deprecations are announced in the changelog with a removal month but no Deprecation or Sunset response headers are documented. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document served at any probed path on api.cubbystorage.com, www.cubbystorage.com or the docs host. The reference is hand-authored Slate HTML. - id: asyncapi name: AsyncAPI conforms: false evidence: Webhooks are documented in prose; no AsyncAPI document is published. - id: iso8601 name: ISO-8601 date and time conforms: true evidence: >- "We represent dates and times as ISO-8601 strings." Date-only as yyyy-MM-dd; timestamps UTC when Z-suffixed and facility-local otherwise. - id: e164 name: E.164 phone numbers conforms: partial evidence: >- The August 2026 changelog normalises the managers/search phone filter to E.164 and matches exactly; customers/search deliberately remains a partial match, so the API is not uniformly E.164. compliance_claims: published: false certifications: [] note: >- NO NAMED CERTIFICATIONS FOUND. No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears on the website, in the docs, in the payment processing notice or on any trust/security page — and no trust centre exists at trust., security., /trust, /security or /compliance. The payment processing notice names Stripe, Inc. and Payabli (Centavo Inc.) as processors and says only that "Your payment information is encrypted and securely processed by our third-party payment processors" and "We do not store your complete credit card or bank account numbers". No `Compliance` or `TrustCenter` pointer is emitted, because there is no published certification to point at. industry_context: sector: self-storage facility management regulated_surfaces: - name: Lien and auction process note: >- auctions/start-lien and auctions/cancel-lien drive a state-regulated statutory process; Cubby's own podcast covers "staying compliant in the self-storage lien process" but the API reference documents no compliance guardrails or jurisdiction handling on those operations. - name: Card payments note: PCI scope is pushed to Stripe/Payabli and to the hosted checkout web component. - name: Tenant PII note: >- handled via a per-key PII entitlement that silently omits 11 field classes rather than erroring — see authentication/cubby-authentication.yml. x-evidence: fetched: '2026-08-11' probes: - url: https://api.cubbystorage.com/.well-known/oauth-authorization-server http_status: 200 - url: https://api.cubbystorage.com/.well-known/oauth-protected-resource http_status: 200 - url: https://api.cubbystorage.com/mcp http_status: 401 - url: https://api.cubbystorage.com/openapi.json http_status: 404 - url: https://www.cubbystorage.com/payment-processing-notice http_status: 200