generated: '2026-08-12' method: derived source: openapi/finditparts-reseller-api-openapi.yml docs: https://api-docs.finditparts.com/ note: >- Cross-cutting standards conformance, derived from the contract and cross-checked against the provider's published documentation. FinditParts publishes no security or compliance certifications anywhere on its public surface, so no Compliance and no TrustCenter pointer is emitted in apis.yml — see security/ and the compliance section below. standards: - id: openapi conforms: false evidence: >- FinditParts publishes no OpenAPI. The spec in this repo is derived by API Evangelist from the provider's Postman collection. Note the collection's own example payloads leak strings like "reference #/components/schemas/ResellerCustomers not found in the OpenAPI spec", which indicates FinditParts maintains an OpenAPI internally and generated the collection from it — it is simply not published. - id: postman-collection-v2 conforms: true evidence: First-party public Postman collection published at https://api-docs.finditparts.com/ - id: oauth2 conforms: false evidence: No oauth2 securityScheme; no authorization server; /.well-known/oauth-authorization-server 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration 404. - id: jwt-rfc7519 conforms: true evidence: >- Authentication is an HS256-signed JWT with registered claims iss, exp and sub, presented as an RFC 6750 bearer token. - id: rfc6750-bearer-token conforms: true evidence: 'Authorization: Bearer on every operation, for both JWT and API key.' - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {errno, message} envelope on application/json, not application/problem+json. See errors/finditparts-error-codes.yml. - id: json-api conforms: false evidence: Responses are bare resource envelopes (product, products, cart, orders), not JSON:API documents. - id: odata conforms: false - id: graphql conforms: false evidence: No /graphql surface documented or discovered. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists to describe. - id: webhooks conforms: false evidence: >- No server-to-server callbacks. The only event surface is a browser postMessage from the embedded session iframe. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent on any operation, including the four order-placing operations. See conventions/finditparts-conventions.yml. - id: pagination conforms: true evidence: >- Page-number pagination via page (and per on productSearch), with a pagination{current_page, per_page, total_count} response object on listResellerCustomers. Applied inconsistently across list operations. - id: rate-limit-headers-rfc9239 conforms: false evidence: No RateLimit-* or X-RateLimit-* headers documented. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support published. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404. - id: mcp conforms: false evidence: No first-party MCP server published. See mcp/finditparts-mcp.yml (candidate only). - id: llms-txt conforms: true evidence: >- A substantive, first-party /llms.txt (200) plus its own /llms.json companion — both hand-authored for this site, covering discovery, PDP URL patterns, interpretation rules and crawl behavior. Captured in llms/. - id: schema-org conforms: true evidence: >- FinditParts states in its own llms.txt and llms.json that product detail pages carry Schema.org Product and FAQPage JSON-LD in the HTML head, with offers.url as a canonical source of truth. - id: pies conforms: true evidence: >- Auto Care Association PIES (Product Information Exchange Standard) product data is exposed on getProduct via the include_pies_data flag and is named as PDP content in llms.json. This is the aftermarket-parts industry data standard. domain: automotive-aftermarket - id: hsts conforms: true evidence: 'HSTS present on finditparts.com and www.finditparts.com, max-age 63072000. See security/finditparts-domain-security.yml.' - id: dnssec conforms: false evidence: DNSSEC not enabled on finditparts.com. - id: caa conforms: false evidence: No CAA records on finditparts.com. - id: spf-dmarc conforms: true evidence: SPF present; DMARC present with policy reject. compliance_program: published: false certifications: [] trust_center: null evidence: >- No trust center, no security page, no compliance page and no named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found on any FinditParts host. trust.finditparts.com and security.finditparts.com do not resolve; probe-security-programs.py returned vdp=none trust=none. Note this is an API that takes card payments (completeCartWithCreditCard accepts a payment_method_nonce and device_data — a Braintree-shaped tokenization handoff), so the absence of a published PCI posture is a notable gap rather than a non-applicable check.