generated: '2026-08-09' method: derived source: - openapi/infoway-real-time-market-data-api-openapi.yml - asyncapi/infoway-real-time-market-data-api-streaming-asyncapi.yml - https://infoway.readme.io/reference/api-protocols-and-response-formats.md - https://infoway.io/en/terms-and-conditions - https://infoway.io/en/privacy-policy standards: - id: openapi-3.0 conforms: true evidence: >- Provider publishes OpenAPI 3.0.0 documents per endpoint on its ReadMe hub; 13 operations harvested to openapi/infoway-real-time-market-data-api-openapi.yml. - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published. A WebSocket streaming surface exists and is fully documented in prose; asyncapi/ in this repo is an API Evangelist derivation, not a provider artifact. - id: api-key-auth conforms: true evidence: 'openapi securitySchemes ApiKeyAuth — type apiKey, in header, name apiKey' - id: oauth2 conforms: false evidence: No oauth2 security scheme in the spec and no OAuth documentation on any host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on data.infoway.io, docs.infoway.io and infoway.io. - id: rfc9457-problem-details conforms: false evidence: >- Errors are carried in a proprietary {ret, msg, traceId, data} envelope; no application/problem+json response is declared anywhere in the spec or docs. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on all three hosts. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; header support undocumented. - id: json-api conforms: false evidence: Custom envelope, not JSON:API. - id: rest-pagination conforms: false evidence: >- No cursor, next-page token or total-count field is documented. limit/offset appear in the official SDK signatures for the sector families only. - id: idempotency-key conforms: false evidence: No idempotency-key mechanism documented; every published operation is a GET read. - id: model-context-protocol conforms: true evidence: >- Official MCP server published (PyPI infoway-mcp-server, 17 tools, stdio transport) with a provider-authored SKILL.md. - id: llms-txt conforms: true evidence: 'https://docs.infoway.io/llms.txt returns 200 with a full documentation index.' - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both returned 404 on data.infoway.io, docs.infoway.io and infoway.io. compliance_program: published: false certifications: [] note: >- No SOC 2, ISO 27001, PCI DSS or other certification claim was found on the marketing site, docs or a trust center; trust.infoway.io and security.infoway.io do not resolve. Terms and a privacy policy are published (https://infoway.io/en/terms-and-conditions, https://infoway.io/en/privacy-policy) but a legal-agreements page is not a compliance program, so no `Compliance` pointer is emitted. x-evidence: fetched: '2026-08-09'