generated: '2026-06-20' method: derived source: openapi/*.yml, asyncapi/fal-ai-asyncapi.yml, https://trust.fal.ai, https://fal.ai/enterprise notes: > Cross-cutting / industry standards this provider conforms to. Derived from the captured OpenAPI + AsyncAPI and enriched with searched compliance claims from the fal trust center and enterprise pages. standards: - id: oauth2 conforms: false evidence: API authentication is a static API key (apiKey header Authorization; Key $FAL_KEY). No oauth2 securityScheme. - id: oidc conforms: false evidence: OIDC/SAML SSO is offered for the enterprise dashboard, not for API authentication. - id: rfc9457-problem-details conforms: false evidence: 'Error responses use a custom `{detail: string|array}` envelope, not application/problem+json.' - id: server-sent-events conforms: true evidence: openapi streamRequest returns text/event-stream; SSE-compatible progress on the queue. - id: websocket conforms: true evidence: Realtime API over wss://realtime.fal.run (asyncapi/fal-ai-asyncapi.yml). - id: webhooks conforms: true evidence: Queue completion webhooks with HMAC signature verification (fal_webhook query param). - id: pagination conforms: false evidence: List operations (listApps, listSecrets, listFiles) return unpaginated arrays. - id: idempotency conforms: false evidence: No Idempotency-Key header documented; queue submissions create a new request each call. - id: rfc8594-sunset conforms: false evidence: No documented Sunset/Deprecation header policy. - id: soc2 conforms: true evidence: SOC 2 Type II audit completed; report available in the fal trust center (https://trust.fal.ai).