generated: '2026-08-12' method: derived source: >- openapi/ibotta-product-api-openapi.yml + well-known/ibotta-well-known.yml + well-known/ibotta-dashboard-openid-configuration.json + security/ibotta-domain-security.yml + live probes 2026-08-12 standards: - id: openapi-3.0 conforms: true evidence: >- https://ibotta.com/bex-api/api-docs.json is a valid OpenAPI 3.0.1 document (info + servers + paths + components.schemas), 1 operation. - id: openapi-3.1 conforms: false evidence: Published document declares openapi 3.0.1, not 3.1.x. - id: oidc-discovery conforms: true evidence: >- https://auth.dashboard.ibotta.com/.well-known/openid-configuration returns 200 with a complete OIDC provider metadata document (issuer, authorization/token/userinfo/jwks). - id: rfc8414-authorization-server-metadata conforms: true evidence: >- https://auth.dashboard.ibotta.com/.well-known/oauth-authorization-server returns 200 with the same RFC 8414 metadata body. - id: oauth2 conforms: true evidence: >- Auth0 tenant supports authorization_code, client_credentials, refresh_token, device_code, token-exchange and jwt-bearer grants. - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported includes S256 (and plain). - id: oauth2-dpop conforms: true evidence: dpop_signing_alg_values_supported includes ES256. - id: rfc9728-protected-resource-metadata conforms: false evidence: /.well-known/oauth-protected-resource returns 404 on every Ibotta host. - id: rfc9116-security-txt conforms: false evidence: >- No security.txt served. ibotta.com returns a 200 SPA HTML shell (soft 404); every other host 404s. A coordinated disclosure program does exist on HackerOne and Bugcrowd. - id: rfc9457-problem-details conforms: false evidence: >- Errors are a bare application/json {"message": string} envelope; no application/problem+json media type is declared or returned. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no Sunset/Deprecation headers documented. - id: idempotency conforms: false evidence: >- No idempotency key mechanism documented. The single published operation is a read-shaped POST search, so idempotency is not applicable to it. - id: pagination conforms: false evidence: >- Search accepts a `limit` (default 25) but no offset/cursor/page parameter and returns no pagination metadata — results are capped, not paged. - id: rate-limit-headers conforms: false evidence: >- No RateLimit-* / X-RateLimit-* headers documented and none observable anonymously (requests 401 before any limit is signalled). - id: mcp conforms: false evidence: No Model Context Protocol server published on any Ibotta host. - id: a2a conforms: false evidence: >- No A2A agent card. /.well-known/agent-card.json and /.well-known/agent.json return the ibotta.com SPA HTML shell (200) or 404 elsewhere. - id: asyncapi conforms: false evidence: No AsyncAPI document and no public event/webhook catalog. - id: graphql conforms: false evidence: No public /graphql surface found on any Ibotta host. - id: openai-plugin-manifest-v1 conforms: true evidence: >- https://ibotta.com/.well-known/ai-plugin.json is a schema_version v1 plugin manifest with api/auth/logo_url/contact_email/legal_info_url. Note the OpenAI plugin platform it targets was retired in 2024 — see lifecycle/ibotta-lifecycle.yml. - id: hsts conforms: true evidence: home.ibotta.com serves Strict-Transport-Security with max-age 31536000 (probed 2026-07-19). - id: dnssec conforms: false evidence: ibotta.com has no DNSSEC chain (probed). - id: caa conforms: false evidence: No CAA records published for ibotta.com (probed). - id: spf conforms: true evidence: ibotta.com publishes an SPF record. - id: dmarc conforms: true evidence: ibotta.com publishes DMARC with policy p=reject. compliance_program: published: false note: >- No public trust center and no named certifications (SOC 2 / ISO 27001 / PCI DSS) located on Ibotta's own properties. legal.ibotta.com is a Transcend-hosted, JS-rendered privacy center with no machine-readable certification listing. No Compliance pointer emitted.