generated: '2026-08-04' method: derived source: openapi/_original/hotel-engine-omni-partner-api-2.4.0-swagger-original.json + grpc/ + docs enriched_from: https://engine-public.github.io/engine-partner-api/ summary: >- The Omni Partner API is a protobuf-first gRPC API with a generated HTTP/JSON projection. It conforms to the Google API design idiom (proto3, google.rpc.Status errors, AIP-158 page tokens, google.api.http annotations) and to Semantic Versioning, but it does not implement the web-API standards families — no OAuth2/OIDC, no RFC 9457 problem details, no JSON:API, no RFC 8594 Sunset headers, no OpenAPI 3.x (the published contract is Swagger 2.0). standards: - id: proto3 conforms: true evidence: All 48 harvested .proto files declare syntax = "proto3". - id: grpc conforms: true evidence: Four gRPC services published at partner-api.engine.com:443 with pre-compiled JVM bindings on Maven Central. - id: swagger-2.0 conforms: true evidence: 'Published contract declares swagger: "2.0" with 11 operations and 118 definitions.' - id: openapi-3.x conforms: false evidence: >- The published document is Swagger 2.0, generated by grpc-gateway protoc-gen-openapiv2. Engine separately maintains engine-public/protoc-gen-openapi, which emits OpenAPI 3.1, but the Partner API release artifacts are not yet produced with it. - id: google-aip conforms: true evidence: >- google.api.http annotations for HTTP/JSON transcoding; page_size/page_token/next_page_token pagination (AIP-158); google.rpc.Status error envelope with typed details. - id: grpc-status-errors conforms: true evidence: Every operation declares a default response of rpcStatus (google.rpc.Status) with typed protobuf details. - id: rfc9457-problem-details conforms: false evidence: No application/problem+json media type anywhere in the contract; errors use google.rpc.Status. - id: json-api conforms: false - id: odata conforms: false - id: oauth2 conforms: false evidence: No securityDefinitions of type oauth2; authentication is mutual TLS only. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any Engine host (all 404). - id: mutual-tls conforms: true evidence: >- Documented in the integration guide and verified live — a TLS 1.3 handshake to partner-api.engine.com:443 emits a certificate request and the connection returns no HTTP response without a client certificate. - id: tls-1.3 conforms: true evidence: partner-api.engine.com negotiates TLSv1.3; certificate issued by Amazon RSA 2048 M01. - id: dnssec conforms: true evidence: engine.com is DNSSEC-signed (probed). - id: caa conforms: true evidence: engine.com publishes CAA records including an iodef contact (mailto:security@engine.com). - id: dmarc conforms: true evidence: engine.com DMARC policy = reject. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host, though a responsible-disclosure policy page exists. - id: rfc8594-sunset-header conforms: false evidence: Deprecation policy is prose + a published EOL table; no Sunset or Deprecation response headers are documented. - id: semver-2.0.0 conforms: true evidence: Versioning page explicitly cites semver.org and enumerates breaking/minor/patch change classes. - id: idempotency-key conforms: false evidence: No idempotency-key header is documented or present in the protos; replay safety relies on the ConfirmOffer continuation-token handshake. - id: rate-limit-headers conforms: partial evidence: >- Publishes ratelimit-limit / ratelimit-remaining / ratelimit-reset. These are the draft-polli IETF RateLimit field names in their pre-RFC 9910 form; the current RFC 9910 structured-field form (RateLimit / RateLimit-Policy) is not used. - id: apache-2.0 conforms: true evidence: The engine-partner-api repository and every .proto file carry the Apache License 2.0. - id: llms-txt conforms: true evidence: https://engine.com/llms.txt returns 200 with a well-formed llms.txt document. - id: mcp conforms: false evidence: No MCP server is published for the Omni API. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on every Engine host. - id: asyncapi conforms: false evidence: No AsyncAPI document and no public webhook catalog — see asyncapi note in the review. compliance_program: published: true trust_center: https://trust.engine.com/ certifications: [SOC 2 Type II] privacy_frameworks: [GDPR, CCPA] see: security/hotel-engine-trust-center.yml