generated: '2026-07-28' method: searched source: >- easyJet Distribution Charter (version March 2026), easyJet approved-channels page, ndctracker.com, and live probes of every easyJet host, 2026-07-28 summary: >- easyJet references no interface standard anywhere in its public estate. The one standards claim that matters commercially in this sector — IATA NDC — is explicitly absent: the March 2026 Distribution Charter never uses the word NDC, easyJet is not on ndctracker.com's list of airlines with launched or in-development NDC programmes, and its own approved channels describe the link as a direct connect. Everything below is recorded as verified negative evidence. No compliance certification programme is published either, so no Compliance pointer is wired. standards: - id: iata-ndc conforms: false evidence: >- The Distribution Charter (version March 2026) never mentions NDC. easyJet does not appear on ndctracker.com's list of 73 airlines with launched or in-development NDC programmes. Approved channel Duffel labels the easyJet connection "Direct Connect"; AirGateway lists its Kyte-facilitated easyJet link separately from its "27+ major NDC airlines". - id: opentravel-ota conforms: false evidence: No OpenTravel / OTA message set, WSDL or XSD is referenced or published. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is served anywhere. Probes of /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs and /docs on api.easyjet.com and b2b.easyjet.com all return HTTP 403 (Akamai); the same paths on www.easyjet.com return 404. - id: graphql conforms: false evidence: >- No /graphql surface exists. POST introspection against api.easyjet.com/graphql and b2b.easyjet.com/graphql returns HTTP 403; www.easyjet.com/graphql 302s to the marketing site. - id: asyncapi conforms: false evidence: No event catalogue, webhook documentation or AsyncAPI document is published. - id: soap-wsdl conforms: false evidence: No WSDL or XSD is published; xml.easyjet.com does not resolve. - id: oauth2 conforms: unknown evidence: >- Nothing is published. /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource on both API hosts return HTTP 403 before any metadata is served, so no assertion can be made either way. - id: oidc conforms: unknown evidence: >- /.well-known/openid-configuration returns 403 on api.easyjet.com and b2b.easyjet.com and 404 on www.easyjet.com. The only observable identity flow is the easyDom partner widget SSO (components/easyjet-components.yml), which is a proprietary session/callback model, not OIDC. - id: rfc9457-problem-details conforms: false evidence: No error contract is published; no application/problem+json response was observed. - id: rfc9116-security-txt conforms: false evidence: >- No security.txt at /.well-known/security.txt or /security.txt on any easyJet host. corporate.easyjet.com answers 200 with the body "Invalid key", which is a catch-all, not a security.txt. See well-known/easyjet-well-known.yml. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on www.easyjet.com and 403 on both API hosts. - id: rfc8594-sunset-header conforms: unknown evidence: No API response can be observed anonymously, so deprecation signalling cannot be assessed. - id: llms-txt conforms: false evidence: /llms.txt returns 404 on www.easyjet.com. - id: mcp conforms: false evidence: mcp.easyjet.com does not resolve; no hosted MCP server is published. compliance_programme: published: false note: >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS attestation page and no vulnerability disclosure programme were found (trust.easyjet.com and security.easyjet.com do not resolve). Regulatory obligations that do bind easyJet — UK CAA operating licence, UK GDPR / DPA 2018, ATOL and the Package Travel Regulations, EU261/UK261 — are legal regimes, not published API compliance artifacts.