generated: '2026-08-13' method: derived source: >- Derived from well-known/google-analytics-openid-configuration.json, well-known/google-analytics-oauth-authorization-server.json, discovery/*.json, openapi/*.yml, grpc/*.proto, errors/, conventions/ and rate-limits/ in this repo; docs claims checked against https://developers.google.com/analytics/devguides/reporting/data/v1/errors and https://support.google.com/analytics/answer/6004245 on 2026-08-13 provider: Google Analytics providerId: google-analytics description: >- What cross-cutting standards the Google Analytics APIs actually conform to, each with the evidence that settled it. Absence of a standard is recorded as conforms: false, not omitted. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Every Data and Admin API securityScheme in openapi/_original/*.yaml declares oauth2 with authorizationUrl https://accounts.google.com/o/oauth2/auth and tokenUrl https://accounts.google.com/o/oauth2/token. Authorization-code, refresh-token, device-code and JWT-bearer grants are advertised. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- https://accounts.google.com/.well-known/oauth-authorization-server returns 200 with a valid metadata document (saved as well-known/google-analytics-oauth-authorization-server.json). Note the document is served by Google's identity host, not by any Google Analytics API host. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://accounts.google.com/.well-known/openid-configuration returns 200, issuer https://accounts.google.com, jwks_uri https://www.googleapis.com/oauth2/v3/certs. Applies to the identity layer the Analytics APIs sit behind; the Analytics APIs themselves are not OIDC relying parties. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- Errors use Google's canonical envelope ({"error":{"code","message","status"}}) with content-type application/json, not application/problem+json. Documented at https://developers.google.com/analytics/devguides/reporting/data/v1/errors. - id: rfc8594 name: Sunset HTTP header (RFC 8594) conforms: false evidence: >- No Sunset or Deprecation header is documented on any Google Analytics API, even though four services were sunset on 2024-07-01. Deprecation is announced only in docs, changelogs and a Google Group. - id: rfc9116 name: security.txt conforms: true partial: true evidence: >- Served at https://www.google.com/.well-known/security.txt (200) with Contact, Policy, Acknowledgments, Encryption and Expires. NOT served on any Google Analytics API host — all six probed hosts return 404. - id: ratelimit-headers name: RateLimit header fields for HTTP (draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: >- No X-RateLimit-*, RateLimit-* or Retry-After headers are documented or returned. Quota state is exposed only in-band via the opt-in returnPropertyQuota request field. - id: pagination name: Cursor pagination (AIP-158) conforms: true partial: true evidence: >- The Admin API implements pageSize/pageToken/nextPageToken exactly per AIP-158 (discovery/google-analytics-admin-api.json). The Data API does not — reporting methods use limit/offset with a rowCount total. - id: aip-122 name: Google AIP-122 resource names conforms: true evidence: >- All Admin and Data API resources are addressed by hierarchical resource names (accounts/{a}, properties/{p}/dataStreams/{d}/measurementProtocolSecrets/{s}). See data-model/google-analytics-data-model.yml. - id: idempotency name: Idempotency keys conforms: false evidence: >- No idempotency header, request-id or de-duplication token exists on any Google Analytics API. Measurement Protocol retries create duplicate events. See conventions/google-analytics-conventions.yml. - id: grpc name: gRPC / Protocol Buffers conforms: true evidence: >- Google publishes the service definitions as .proto in googleapis/googleapis — captured verbatim in grpc/. The first-party client libraries are gRPC clients; REST is the secondary transport. - id: openapi name: OpenAPI conforms: false evidence: >- Google publishes no OpenAPI for the Analytics APIs. The machine-readable contract Google actually serves is the Google API Discovery document (https://analyticsdata.googleapis.com/$discovery/rest?version=v1beta and https://analyticsadmin.googleapis.com/$discovery/rest?version=v1beta, both 200, captured in discovery/). The OpenAPI files in openapi/ are API Evangelist conversions of those discovery documents, not provider artifacts. - id: graphql name: GraphQL conforms: false evidence: No GraphQL endpoint is published for any Google Analytics service. - id: asyncapi name: AsyncAPI / event-driven surface conforms: false evidence: >- Google Analytics ships no webhooks, no event subscriptions and no streaming API. Data leaves the platform by pull (Data API) or by scheduled BigQuery export. There is nothing to describe in AsyncAPI, so no AsyncAPI artifact was written and no AsyncAPI or Webhooks pointer was emitted. - id: mcp name: Model Context Protocol conforms: true partial: true evidence: >- Google publishes an official MCP server (googleanalytics/google-analytics-mcp, PyPI analytics-mcp 0.7.0, 2026-07-29) — but local-stdio only, with no hosted endpoint. See mcp/google-analytics-mcp.yml. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and the legacy /.well-known/agent.json both 404 on all six probed hosts. See well-known/google-analytics-well-known.yml. - id: llmstxt name: llms.txt conforms: false evidence: https://developers.google.com/llms.txt and /analytics/llms.txt both 404. regulatory: - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: >- Google publishes the Google Ads Data Processing Terms, which supersede the former Google Analytics Data Processing Amendment and are accepted in the Analytics account settings. source: https://support.google.com/analytics/answer/3379636 - id: us-state-privacy name: US state privacy laws (CCPA/CPRA and successors) conforms: true partial: true evidence: >- Addressed in Google's "Safeguarding your data" page for Analytics, alongside data-retention controls, IP anonymization and Consent Mode. source: https://support.google.com/analytics/answer/6004245 certifications: published: false note: >- No Google Analytics-specific certification page (SOC 2, ISO 27001, ISO 27018) was found on developers.google.com or support.google.com during this pass. Google Cloud publishes a compliance-offerings index at https://cloud.google.com/security/compliance/offerings, but the page is JS-rendered and its product-scope table could not be read without a browser, so no certification is asserted here and no Compliance pointer was emitted. Recorded as an unverified gap rather than a claim. maintainers: - FN: Kin Lane email: kin@apievangelist.com