generated: '2026-07-19' method: derived source: - https://dev.iron.io/mq/3/reference/api/ - https://dev.iron.io/worker/reference/api/ notes: >- Cross-cutting standards posture derived from the public IronMQ v3 and IronWorker API references. No published compliance program (SOC 2 / ISO 27001 / PCI / HIPAA) was found on the developer or trust surface, so no Compliance pointer is emitted. standards: - id: oauth2 conforms: false evidence: >- Uses a static per-project token labeled "OAuth" in the Authorization header, not a full OAuth2 authorization-grant flow (no authorize/token endpoints or scopes). - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: 'Errors use a bespoke {"msg": "..."} envelope, not application/problem+json.' - id: json-api conforms: false evidence: Responses use resource-root wrappers (queue/messages/ids/msg), not JSON:API. - id: rest-json conforms: true evidence: JSON over HTTP with resource-oriented paths and standard verbs (GET/POST/PUT/PATCH/DELETE). - id: cursor-pagination conforms: true evidence: Queue listing pages with per_page + previous marker parameters. - id: webhooks conforms: true evidence: Push queues deliver to subscriber HTTP endpoints; POST /webhook ingests events. - id: idempotency conforms: false evidence: No idempotency-key header documented; at-least-once delivery semantics.