generated: '2026-07-19' method: derived source: openapi/fortify-software-fod-openapi.json standards: - id: oauth2 conforms: true evidence: >- OAuth 2.0 client-credentials token endpoint (/oauth/token) with tenant scopes documented per operation; bearer access tokens. - id: openapi-swagger2 conforms: true evidence: Provider publishes a Swagger 2.0 document at /swagger/docs/v3. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom ErrorResponse envelope ({errors:[{errorCode,message}]}), not application/problem+json. - id: rest-json conforms: true evidence: Resource-oriented JSON REST API over HTTPS under /api/v3. - id: pagination-offset-limit conforms: true evidence: List endpoints use offset/limit with items/totalCount wrappers. - id: sarif conforms: true evidence: >- FoD imports/exports SARIF (e.g. StaticScansV3_PutImportSarifScan); first-party tooling converts FPR to SARIF. - id: cyclonedx-sbom conforms: true evidence: >- Open-source / software-composition scanning and SSC parser plugins consume CycloneDX SBOM inputs.