generated: '2026-07-20' method: derived source: openapi/forum-openapi-original.yml + docs.forum.market standards: - id: oauth2 conforms: false evidence: Auth is HMAC-SHA256 API-key signing (apiKey headers), not OAuth2. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: 'Errors use a custom { error: { code, message, details } } envelope, not application/problem+json.' - id: hmac-request-signing conforms: true evidence: FORUM-ACCESS-SIGN = Base64(HMAC-SHA256(secret, timestamp+method+path+body)). - id: cursor-pagination conforms: true evidence: Opaque cursor / nextCursor across list endpoints. - id: idempotency conforms: true evidence: clientOrderId provides idempotent order creation; DUPLICATE_CLIENT_ORDER_ID on reuse. - id: rate-limit-headers conforms: true evidence: X-RateLimit-Limit/Remaining/Reset + Retry-After; 429 on exceed. - id: asyncapi-3.0 conforms: true evidence: Published AsyncAPI 3.0.0 WebSocket feed (asyncapi/forum-websocket-asyncapi.yml). - id: openapi-3.1 conforms: true evidence: Published OpenAPI 3.1.0 (openapi/forum-openapi-original.yml). compliance_program: published: false note: >- No SOC 2 / ISO 27001 / PCI / trust-center posture published (early-stage exchange, launched Feb 2026). No Compliance pointer emitted.