generated: '2026-08-14' method: searched source: >- derived from openapi/ and well-known/, enriched from https://debounce.com/gdpr/, https://debounce.com/privacy-policy/ and https://debounce.com/data-retention-policy/ description: >- Which cross-cutting standards the DeBounce surface actually conforms to, asserted from artifacts in this repo rather than from marketing claims. The headline: DeBounce publishes valid OpenAPI 3.1.0, a conformant A2A agent card and RFC 8414/9728 OAuth metadata for its MCP endpoint — but the REST API itself conforms to almost none of the runtime conventions (no RFC 9457 errors, no RFC 6585/draft RateLimit headers, no RFC 8594 sunset, no RFC 9116 security.txt). standards: - id: openapi-3.1 conforms: true evidence: >- Three OpenAPI 3.1.0 documents published by the provider at developers.debounce.com/api-reference/openapi-{validation,bulk,disposable}.json and captured verbatim in openapi/_original/. - id: a2a-1.0 conforms: true grade: conformant evidence: >- /.well-known/agent-card.json on developers.debounce.com — capabilities is an object, protocolVersion present ("0.3"), skills is an array. See a2a/debounce-a2a.yml for the graded record and its one naming deviation. - id: agent-skills conforms: true evidence: >- A provider-published Agent Skill at /.well-known/agent-skills/de-bounce/skill.md, advertised from the agent card. - id: mcp conforms: true evidence: >- Two live MCP endpoints. tools/list returns 200 with three tools at https://developers.debounce.com/mcp. See mcp/debounce-mcp.yml. - id: llms-txt conforms: true evidence: >- /llms.txt served on both developers.debounce.com (index + OpenAPI links) and debounce.com (product index), plus /llms-full.txt on the docs host. - id: oauth2 conforms: partial evidence: >- An OAuth 2.0 authorization server exists at debounce.com for the WordPress MCP endpoint (authorization_code + refresh_token, PKCE S256, dynamic client registration). The REST validation API declares NO oauth2 scheme — it is api-key-in-query only. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: well-known/debounce-oauth-authorization-server.json (HTTP 200) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: well-known/debounce-oauth-protected-resource.json (HTTP 200) - id: oidc-discovery conforms: partial evidence: >- /.well-known/openid-configuration returns 200 but is byte-identical to the OAuth 2.0 metadata — it advertises no id_token support, no jwks_uri, no userinfo_endpoint and no subject_types_supported. It is OAuth metadata served at the OIDC path, not an OIDC provider. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a vendor envelope {"debounce":{"error":...},"success":"0"} with content-type application/json, not application/problem+json. See errors/debounce-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all six probed hosts. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on all six probed hosts. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy and no Sunset/Deprecation header documented. - id: ratelimit-headers conforms: false evidence: >- A live probe of https://api.debounce.io/v1/ on 2026-08-14 returned no RateLimit-*, X-RateLimit-* or Retry-After header on either the 200 or the 401 path. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key parameter in any published spec and none documented. All operations are GET, including the credit-consuming bulk upload. - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: pagination conforms: false evidence: No published operation returns a paged collection. - id: cors conforms: true evidence: >- access-control-allow-origin: * observed on api.debounce.io responses; `public_` keys additionally require per-key CORS domain allow-listing. compliance_program: published: true url: https://debounce.com/gdpr/ regimes: - id: gdpr claimed: true detail: >- GDPR compliance page published. Application servers hosted in the EU; validation servers international with EU or North America region selectable on request. A Data Processing Agreement is offered, contra-signed on request, alongside a list of third-party sub-processors on request. Records of processing activities are maintained and surfaced in the customer account (date, list name, processing location, record count). Data deletion and account deletion are self-service. first_aligned: '2018' supporting_documents: - name: Privacy Policy url: https://debounce.com/privacy-policy/ - name: Terms of Use url: https://debounce.com/terms-of-use/ - name: Data Retention Policy url: https://debounce.com/data-retention-policy/ - name: Cookie Policy url: https://debounce.com/cookie-policy/ certifications: [] note: >- NO third-party audited certification is published — no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR is named anywhere on the site. The compliance posture is a self-asserted GDPR program plus a DPA, which is normal for a company of this size but is not an attestation. spec_quality_notes: - >- openapi-validation.json declares the `api` parameter of getBalance with `schema: {type: apiKey}`. `apiKey` is not a JSON Schema type — this operation will fail strict schema validation. Every other operation types it as string. Captured verbatim and corrected in overlays/debounce-account-api-overlay.yaml rather than edited into the harvested spec. - >- The `success` field is typed as an integer enum in ValidationResult / ReverseResult / BalanceResult and as a string enum in UsageResult / BulkStatusResult / BulkUploadResult / Error, while the live API and every in-spec example return the string form. - >- checkBulkStatus declares only a 200 response, yet its own examples include the "List ID is not valid." error case inside that 200. - >- Operations carry summaries and descriptions and unique operationIds, but only one operation across all three published documents (getBalance) carries a tag.