generated: '2026-08-16' method: derived source: openapi/franklin-whole-home-openapi.yml + live responses from https://test-api.franklinwh.com standards: - id: oauth2 conforms: false evidence: No oauth2 securityScheme; authentication is a cp/ck credential exchange at /api-common/tokenizer returning an opaque token carried in the Authorization header. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (404). - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on every host. - id: rfc9457-problem-details conforms: false evidence: Errors are returned as a bespoke {code, msg} envelope with HTTP 200, not application/problem+json. - id: http-status-semantics conforms: false evidence: Authentication and authorisation failures are returned inside a 200 response body (code 401 "wrong token", code 403 "missing token or token param") rather than as HTTP status codes. - id: rest-resource-naming conforms: false evidence: RPC-style verb paths (/api-common/querySiteList, /api-common/setSwitchParam) rather than resource-oriented URIs. - id: pagination conforms: true evidence: 'Offset pagination on list operations: current + pageSize (default 20, max 50) on /api-common/querySiteList and /api-common/fetchOperationLog; next + pageSize (default 100, max 1000) on /api-sunrun/queryComponents/assets.' - id: idempotency conforms: false evidence: No idempotency key header or parameter appears anywhere in the published operation catalogue; write operations (setSwitchParam, setTouProfile, setGridEvents) offer no replay protection. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. - id: openapi conforms: false evidence: FranklinWH publishes its operation catalogue as a proprietary JavaScript module in its API portal, not as an OpenAPI document. openapi/franklin-whole-home-openapi.yml is an API Evangelist conversion of that catalogue. - id: ieee-2030.5 conforms: false evidence: No IEEE 2030.5 (SEP2) / CSIP claim found in the API portal or product documentation. certifications_published: false note: No compliance programme, trust centre or named certification (SOC 2, ISO 27001, PCI DSS) is published for the API, so no Compliance or TrustCenter pointer is emitted. Product-level electrical safety listings (UL) are hardware certifications and are out of scope for API conformance.