generated: '2026-07-19' method: searched source: https://developers.gardin.ag/docs/gardin-api/gardin-api standards: - id: oauth2 conforms: true evidence: OAuth2 client-credentials flow with token endpoint https://login.gardin.ag/oauth2/token and documented scopes. - id: oauth2-client-credentials conforms: true evidence: grant_type=client_credentials, HTTP Basic client auth, Bearer JWT access tokens. - id: jwt conforms: true evidence: Access tokens issued as JWTs. - id: hmac-webhook-signing conforms: true evidence: Notification webhooks signed with HMAC-SHA256 in the Gardin-Signature header. - id: rfc3339-timestamps conforms: true evidence: Alert timestamps documented as RFC-3339. - id: offset-pagination conforms: true evidence: GET /devices supports limit (max 100) and skip pagination. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom JSON message envelope, not application/problem+json. - id: openid-connect conforms: false evidence: login.gardin.ag exposes no OIDC discovery document (probed 404). - id: asyncapi conforms: false evidence: Event surface documented as webhooks/websockets but no AsyncAPI spec published. compliance: published_program: false note: No public trust center or named certifications (SOC 2 / ISO 27001 / etc.) found; no Compliance pointer emitted.