generated: '2026-08-12' method: derived source: >- openapi/*.yml securitySchemes; https://oauth.fatsecret.com/.well-known/openid-configuration (HTTP 200, probed 2026-08-12); https://platform.fatsecret.com/docs/guides standards: - id: oauth2 conforms: true evidence: >- OpenAPI securitySchemes declares oauth2 with a clientCredentials flow at https://oauth.fatsecret.com/connect/token; documented at https://platform.fatsecret.com/docs/guides/authentication/oauth2 - id: oauth1a conforms: true evidence: >- 3-legged OAuth 1.0a request signing is documented for member/profile data at https://platform.fatsecret.com/docs/guides/authentication/oauth1/three-legged and declared in the spec as the oauth1 scheme - id: oidc-discovery conforms: true evidence: >- https://oauth.fatsecret.com/.well-known/openid-configuration returns 200 application/json with issuer, jwks_uri, authorization_endpoint, token_endpoint, userinfo_endpoint, introspection_endpoint, revocation_endpoint, device_authorization_endpoint, RS256 id_token signing and S256 PKCE support - id: oauth2-pkce conforms: true evidence: 'code_challenge_methods_supported: ["plain","S256"] in the OIDC discovery document' - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint: https://oauth.fatsecret.com/connect/revocation' - id: rfc7662-token-introspection conforms: true evidence: 'introspection_endpoint: https://oauth.fatsecret.com/connect/introspect' - id: rfc8628-device-authorization conforms: true evidence: 'device_authorization_endpoint: https://oauth.fatsecret.com/connect/deviceauthorization' - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on oauth.fatsecret.com - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any fatsecret host (404 or SPA shell) - id: rfc9457-problem-details conforms: false evidence: >- errors use a vendor envelope {"error":{"code":N,"message":"..."}}, not application/problem+json — see errors/fatsecret-error-codes.yml - id: rfc8594-sunset-header conforms: false evidence: no Sunset/Deprecation header support documented - id: idempotency-key conforms: false evidence: no idempotency key documented on any write method - id: pagination conforms: true evidence: 'offset pagination via page_number/max_results with total_results in the envelope' - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false evidence: >- Nutrition data is served in a fatsecret-proprietary shape; no FHIR NutritionOrder/NutritionProduct resource mapping is published, despite the health/wellness domain - id: hipaa conforms: false evidence: no HIPAA/BAA claim published on the platform site - id: gdpr conforms: unknown evidence: >- A privacy policy is published (https://foods.fatsecret.com/Default.aspx?pa=priv&l=en) but no GDPR/DPA or subprocessor page is exposed on the developer portal - id: soc2 conforms: false evidence: >- no trust center and no SOC 2 / ISO 27001 claim found; trust.fatsecret.com does not resolve and probe-security-programs.py returned trust=none compliance_program_published: false note: >- Every "conforms: true" above is derived from the machine-readable auth surface or the published guides. fatsecret publishes NO certification or compliance program, so no Compliance pointer is emitted for this provider.