generated: '2026-09-13' method: searched source: https://developers.hyundai.com/web/v1/hyundai/specification/account provider: Hyundai providerId: hyundai note: >- Assertions are made against the provider's own published specification pages and against live probes. No OpenAPI exists, so nothing here is derived from a spec document. Absence is recorded as conforms: false with the evidence that establishes it. conformance: - id: oauth2 name: OAuth 2.0 conforms: true evidence: https://developers.hyundai.com/web/v1/hyundai/specification/account/account_authorize detail: >- Authorization code flow with response_type=code, client_id, redirect_uri and a state CSRF token; token endpoint with HTTP Basic client authentication and grant_type=authorization_code / refresh_token. The console guide states outright that the Hyundai integrated account supports OAuth 2.0. deviations: - >- Token revocation uses a non-standard grant_type=delete on the token endpoint rather than an RFC 7009 revocation endpoint. - No scope parameter; authorization is per-project and per-vehicle instead. - >- No /.well-known/oauth-authorization-server metadata on any host, so the flow is not machine-discoverable. - id: oidc name: OpenID Connect conforms: false evidence: https://www.hyundai.com/.well-known/openid-configuration detail: >- 404 on every host probed. The user-profile operation returns identity claims (id, email, name, mobileNum, birthdate, lang) but not as an ID token or a standards-shaped userinfo response. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: https://developers.hyundai.com/web/v1/hyundai/specification/data/status_odometer detail: >- Errors use a custom flat envelope {errId, errCode, errMsg} served as application/json, not application/problem+json, with no type URI, title, status or instance member. - id: rfc9116 name: RFC 9116 security.txt conforms: true evidence: https://www.hyundai.com/.well-known/security.txt detail: >- Served on www.hyundai.com with Contact, Expires and Preferred-Languages fields. The Expires value (2026-12-31) is current. No Policy, Encryption, Acknowledgments or Canonical field. - id: rfc8594 name: RFC 8594 Sunset HTTP Header conforms: false evidence: https://prd.kr-ccapi.hyundai.com/api/v1/user/profile detail: No Sunset or Deprecation header observed on live responses; no deprecation policy published. - id: rate-limit-headers name: Rate-limit response headers conforms: partial evidence: https://dev.kr-ccapi.hyundai.com/api_sample/v1/car/status/{carId}/odometer detail: >- X-RateLimit-Limit / Remaining / Reset are returned on every response — the legacy de-facto convention, not the IETF RateLimit-* draft headers. They are undocumented, so a client only finds them by observation. - id: pagination name: Pagination conforms: false evidence: https://developers.hyundai.com/web/v1/hyundai/specification/data/carprofile_carlist detail: No limit, offset, cursor or page parameter on any documented operation. - id: idempotency name: Idempotency keys conforms: false evidence: https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token detail: No Idempotency-Key header or equivalent on any of the four mutating operations. - id: pipa name: Personal Information Protection Act (Korea) / 개인정보 보호법 conforms: true evidence: https://developers.hyundai.com/web/v1/hyundai/specification/data/partner_deletecallback detail: >- The contract is built around PIPA rather than merely claiming compliance with it. A dedicated third-party-provision consent operation gates all vehicle data; a withdrawal operation reverses it; and an outbound delete callback cites the Act and its Enforcement Decree by name to impose an immediate bulk-deletion duty on the data recipient. The published platform principles state the customer owns the data and it is shared only with their agreement. regime: korea-pipa domain_standards: searched: true found: false note: >- No automotive or mobility domain standard is declared anywhere in the contract. Probed for and did not find: ISO 20078 (ExVe - extended vehicle web services), NGTP, OCPP or OCPI (EV charging), Sensoris, and W3C Automotive/VSS signal naming. Hyundai's payload vocabulary is bespoke — `odometers[]`, `soc`, `targetSOC.plugType`, an integer distance `unit` enum — and maps to no published signal catalogue. This is recorded as an honest absence; the rubric is reward-only and nothing is invented to fill the slot. probed_for: - id: iso-20078 name: ISO 20078 Extended Vehicle (ExVe) found: false - id: ocpi name: Open Charge Point Interface found: false - id: vss name: COVESA Vehicle Signal Specification found: false certifications: published: false trust_center: false note: >- No trust center, no SOC 2 / ISO 27001 / ISO 21434 certification page and no compliance programme page found on the developer portal or the corporate domain. No Compliance pointer is emitted.