generated: '2026-07-20' method: derived source: openapi/dispatch-rest-v3-openapi.yml docs: https://github.com/DispatchMe/v3-api-docs summary: >- Cross-cutting standards conformance for the Dispatch REST API v3, derived from the generated OpenAPI and the provider's public documentation. Dispatch publishes no certification or compliance program, so no Compliance pointer is emitted. standards: - id: oauth2 conforms: true evidence: >- POST /v3/oauth/token implements the client_credentials, password and refresh_token grants of RFC 6749 and returns a standard token response (access_token, token_type, created_at, expires_in, refresh_token). - id: oauth2-bearer-rfc6750 conforms: true evidence: Tokens are presented as Authorization bearer tokens; 401 is returned for an incorrect token. - id: oauth2-scopes conforms: false evidence: >- No scope vocabulary is published. Authorization is an account-level ACL negotiated with an account manager, not a scoped grant. - id: oidc conforms: false evidence: No /.well-known/openid-configuration (404 on api.dispatch.me and dispatch.me) and no ID token. - id: oauth2-authorization-server-metadata-rfc8414 conforms: false evidence: /.well-known/oauth-authorization-server returned 404 on 2026-07-20. - id: rfc9457-problem-details conforms: false evidence: >- Errors use bare HTTP status codes with a validation body on 422; no application/problem+json media type is documented or returned. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on dispatch.me and api.dispatch.me on 2026-07-20. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response headers documented; no deprecation policy published. - id: rfc3966-tel-uri conforms: true evidence: >- Phone numbers on Customer, Organization and User are documented as RFC 3966 format, with an explicit link to the RFC. - id: iana-timezones conforms: true evidence: Location.timezone is documented as an IANA timezone identifier. - id: iso8601-timestamps conforms: true evidence: Appointment.time and appointment window start/end times are documented as ISO 8601 timestamps. - id: json-api conforms: false evidence: >- Responses use a resource-named root key with limit/offset paging and a filter[] query object - a Rails/Ransack-style convention, not the JSON:API media type or its document structure. - id: odata conforms: false - id: graphql conforms: false - id: grpc conforms: false - id: openapi conforms: false evidence: >- Dispatch publishes no machine-readable specification. The OpenAPI in this repo was generated by API Evangelist from the provider's public documentation. - id: asyncapi conforms: false evidence: Webhooks exist but are account-manager configured; no AsyncAPI document or event catalog is published. - id: idempotency-key conforms: false evidence: >- No idempotency-key header or replay window is documented. Dispatch instead offers caller-supplied external_ids for dedupe of customers and organizations. - id: pagination conforms: true evidence: Documented limit/offset paging on all multi-record GET requests, with a maximum limit of 100. - id: cors conforms: true evidence: >- Access-Control-Allow-Methods and Access-Control-Allow-Headers observed on a live HEAD to https://api.dispatch.me on 2026-07-20. - id: hsts conforms: true evidence: 'strict-transport-security: max-age=63072000; includeSubdomains; preload observed on api.dispatch.me.' - id: http-etag-conditional-requests conforms: true evidence: 'Weak ETag and cache-control: max-age=0, private, must-revalidate observed on api.dispatch.me.' compliance_program: published: false certifications: [] note: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA claim, and no compliance page was found on dispatch.me. No Compliance pointer is emitted. related: - openapi/dispatch-rest-v3-openapi.yml - authentication/dispatch-authentication.yml - conventions/dispatch-conventions.yml - security/dispatch-domain-security.yml