generated: '2026-09-07' method: searched source: https://help.expeditors.com/globalhelp/shipment_api/POST_oauth2_token.htm note: >- Asserted from the published API Developer Center documentation and from live probes; Expeditors publishes no OpenAPI, so nothing here is derived from a machine-readable contract. standards: - id: oauth2 conforms: true evidence: >- RFC 6749 client-credentials grant at https://api.expeditors.com/tracking/v2/oauth2/token — HTTP Basic client authentication, grant_type=client_credentials, JSON response with access_token/token_type/expires_in/scope. - id: oauth2-bearer-rfc6750 conforms: true evidence: 'Resource requests carry `Authorization: Bearer {token}`; invalid_token/insufficient_scope error slugs are the RFC 6750 vocabulary.' - id: oidc-discovery conforms: true scope: corporate website only evidence: >- https://www.expeditors.com/.well-known/openid-configuration returns 200 with issuer, authorization/token/userinfo/revocation endpoints and jwks_uri. This is the Umbraco CMS member-authentication layer for the website, not the Tracking API. - id: rest conforms: true evidence: >- Best Practices states the service "attempts to conform to the design principles of Representational State Transfer (REST) and relevant W3C HTTP/1.1 standards" and uses JSON. - id: semver conforms: true evidence: Version Policy declares semantic versioning with the major version in the base path. - id: rfc9457-problem-details conforms: false evidence: Errors use the OAuth 2.0 error/error_description JSON shape with media type application/json; no type URI and no application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: A six-month decommission window is stated in prose; no Sunset or Deprecation response headers are documented. - id: ratelimit-headers-rfc9239 conforms: false evidence: No RateLimit-*/X-RateLimit-*/Retry-After headers are documented; only the 429 status and too_many_requests body. - id: openapi conforms: false evidence: No OpenAPI/Swagger document is published. /openapi.json, /swagger.json, /api-docs and /v3/api-docs all 404 on api.expeditors.com; /tracking/v2/* returns 401 for every path. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published. Change notification is a help-page banner plus email to registered contacts. - id: json-api conforms: false evidence: Responses are bare JSON arrays/objects with no JSON:API document structure. domain_standards: note: >- Expeditors' market (freight forwarding / customs brokerage) has real interchange standards — ANSI X12 (214/315/315), UN/EDIFACT (IFTSTA, IFTMIN), and the customs filings behind them. Expeditors' marketing pages say the platform handles "traditional EDI and every major communication protocol", and third-party EDI networks list it as a trading partner, but the published Tracking API contract declares none of these: its documented payloads are bespoke JSON types (Shipment, Container, Consignment, Event, Reference, Document) with no X12/EDIFACT message identifiers, no transaction-set codes and no standard code lists. The EDI surface itself is bilateral and account-provisioned, with no public specification, so no domain-standard conformance can be asserted from a contract. entries: [] compliance_program: published: false note: >- No trust center, no security/compliance page, and no named certifications (SOC 2, ISO 27001, PCI DSS) were found on the public surface; trust.expeditors.com and status.expeditors.com do not resolve. No Compliance pointer is emitted.