generated: '2026-08-13' method: derived source: https://open.ezrpro.com/#/apiFile note: >- Derived from the published EZR Open Platform reference (developer guide, status-code page, signing page and the 236 interface definitions). EZR makes no standards-conformance claim of any kind and holds no published certification, so almost every row here is a negative — an honest measurement of a proprietary, pre-standards integration surface. No Compliance pointer is emitted in apis.yml because there is no published compliance programme to point at. standards: - id: openapi conforms: false evidence: No OpenAPI/Swagger document at any probed location on any EZR host (see well-known/ezr-well-known.yml). - id: asyncapi conforms: false evidence: No AsyncAPI document; the 31 push interfaces are described in prose only. - id: json-schema conforms: false evidence: Parameters are typed in a proprietary ReqParam/ResParam tree (Fd/FdType/IsRequire), not JSON Schema. - id: graphql conforms: false evidence: No /graphql surface on any host. - id: grpc conforms: false evidence: No .proto published; no buf.build or GitHub org exists for EZR. - id: rest conforms: false evidence: >- EZR describes the API as "标准的RESTful API方式设计", but every interface is POST to a verb-named route with a form-encoded envelope, no resource URIs, no HTTP method semantics and HTTP 200 for every outcome. The claim is not met. - id: http-status-semantics conforms: false evidence: HTTP 200 is returned for success and failure alike; the outcome lives in a JSON StatusCode field. - id: rfc9457-problem-details conforms: false evidence: Errors use a proprietary Status/StatusCode/Msg envelope, not application/problem+json. - id: oauth2 conforms: false evidence: No OAuth 2.0. Authentication is a shared AppId + Token with an uppercase SHA1/MD5 request signature. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc8414-oauth-metadata conforms: false evidence: No /.well-known/oauth-authorization-server on any host. - id: rfc9116-security-txt conforms: false evidence: No security.txt served; the web hosts soft-404 the path with 200. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document served on any of the four hosts. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header; deprecation is prose-only (已废弃) with no dates. - id: mcp conforms: false evidence: No MCP server published or discoverable. - id: a2a conforms: false evidence: No agent card at either /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: agent-skills conforms: true evidence: >- EZR publishes a packaged Agent Skill with frontmatter (name/description) and a manifest, distributed as ezr-skills-openapi.zip and documented on its own portal page. Saved verbatim in skills/. This is the single standards-aligned agent surface EZR ships. - id: idempotency conforms: false evidence: >- No idempotency key on any interface. The only idempotency language in the reference places the obligation on the CONSUMER of EZR's push retries, not on EZR. - id: pagination conforms: partial evidence: PageIndex/PageSize on 26 of 236 interfaces; no cursor pagination, no uniform paging envelope. - id: request-signing conforms: true evidence: >- A complete, published, symmetric signing scheme — SHA1/MD5 over a sorted AppId/Timestamp/Token query string, uppercase hex, applied to requests, responses AND outbound pushes, with a 10-minute replay window enforced by StatusCode 308. - id: tls conforms: true evidence: TLS 1.3 on www.ezrpro.com; HTTPS published for every environment. See security/ezr-domain-security.yml. caveat: Plaintext HTTP base URLs are published alongside HTTPS for the UCloud and QCloud production environments. certifications: published: [] trust_center: null note: >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS / GDPR / 等保 (MLPS) statement, and no security or compliance page found on ezrpro.com. As a China-domiciled processor of retail consumer identity, points and transaction data, EZR is in scope for PIPL and the Personal Information Security Specification, but publishes no attestation of either. regulatory_context: jurisdiction: China (上海 / Shanghai) applicable_regimes: [PIPL, Cybersecurity Law, Data Security Law] published_posture: >- A privacy policy at http://www.ezrpro.com/privacy.html and an ICP filing are the only published compliance artifacts located.