generated: '2026-07-19' method: derived source: openapi/haekka-public-api-openapi.yml standards: - id: rest-json conforms: true evidence: JSON over HTTPS resource endpoints (employees, trainings, employee_trainings). - id: http-bearer-auth conforms: true evidence: securityScheme type http scheme bearer (API key as bearer token). - id: oauth2 conforms: false evidence: No oauth2 security scheme; auth is a static bearer API key. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Error responses are not documented as application/problem+json. - id: pagination conforms: false evidence: No pagination parameters or envelope documented on list endpoints. - id: idempotency conforms: false evidence: No idempotency-key header documented. - id: webhooks conforms: false evidence: No outbound webhook or AsyncAPI event surface published.