generated: '2026-07-28' method: derived source: >- Derived from the published contract shape (Navitaire New Skies SOAP/WCF, NSK 4.6), the partner FAQ at https://apiblog.jetstar.com/faq/, the domain-security probe in security/jetstar-domain-security.yml, and the negative full-text search of all 838 partner posts recorded in review.yml. Nothing is asserted that Jetstar does not publish. description: >- Which industry and cross-cutting standards the Jetstar API conforms to. The headline finding is negative and important: this is a vendor shape, not an industry shape. No IATA NDC, no OpenTravel/OTA, no HTNG, no OpenAPI, no published WSDL. A partner integrating with Jetstar writes code against Navitaire's object model, not against a specification any competitor also implements. standards: - id: soap-1.x conforms: true evidence: >- Navitaire New Skies is a SOAP/WCF web service; Jetstar's partner documentation references .svc endpoints (UtilitiesManager.svc) and typed C# request objects (GetStationListRequest / GetStationListRequestData). - id: wsdl conforms: unknown evidence: >- A WSDL almost certainly exists behind the gate (WCF services publish one), but no WSDL is retrievable publicly — jqapi.navitaire.com refuses connections without a client certificate and an allow-listed IP, and https://jqapi.navitaire.com/BookingManager.svc?wsdl returned no response. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document on any Jetstar or Navitaire host. apiblog.jetstar.com answers a catch-all login HTML shell for /openapi.json, /swagger.json and /api-docs. - id: iata-ndc conforms: false evidence: >- Full-text search of all 838 partner posts for "New Distribution Capability", "AirShopping" and "OrderCreate" returned zero results. No NDC endpoint, schema version or certification claim found. The portal's category named "NDC" is a local label containing route and bundle notices, not IATA NDC content. Parent Qantas separately runs the NDC@Scale-certified Qantas Distribution Platform; nothing found extends it to Jetstar. - id: opentravel-ota conforms: false evidence: No OpenTravel/OTA message set referenced anywhere in Jetstar's published partner documentation. - id: iata-codes conforms: true evidence: >- Airline designators JQ/GK, numeric code 081, three-letter station codes (StationCode, GetStationList), agency numbers, SSR codes and Regulation 830d passenger contact fields are all used on the wire. - id: mutual-tls conforms: true evidence: >- Jetstar issues a client SSL certificate per approved partner and publishes an installation manual in the gated Download Centre. - id: oauth2 conforms: false evidence: >- No authorization server, token endpoint or scope surface. Session authentication is a Navitaire Signature, not a bearer token. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host probed. - id: rfc9457-problem-details conforms: false evidence: Errors are SOAP Faults; no application/problem+json. - id: rfc9116-security-txt conforms: partial evidence: >- No security.txt on any Jetstar host; the parent Qantas Group publishes one at https://www.qantas.com/.well-known/security.txt whose stated scope is "Qantas Group digital assets". - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support and no written deprecation policy. - id: idempotency conforms: false evidence: No idempotency key, retry-safety guarantee or replay semantics published. - id: pagination conforms: false evidence: No pagination convention published; no bulk/export operation exists. - id: webhooks conforms: false evidence: No webhook, callback or event surface published. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir-r4 conforms: false - id: psd2 conforms: false transport_security: tls: TLSv1.3 observed on www.jetstar.com and apiblog.jetstar.com hsts: apiblog.jetstar.com max-age 31536000; not observed on www.jetstar.com dnssec: false (jetstar.com, navitaire.com) caa: none published (jetstar.com, navitaire.com) spf: true (jetstar.com, navitaire.com) dmarc: p=reject (jetstar.com, navitaire.com) detail: security/jetstar-domain-security.yml compliance_program: published: false note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published on any Jetstar surface reached, and no trust centre was found. No Compliance or TrustCenter pointer is emitted. regulatory_context: - name: Australian Privacy Principles (Privacy Act 1988, Cth) note: >- Jetstar's privacy policy states it will provide access to information it holds "to the extent required by applicable law" — APP 12 in Australia. A written request, not an endpoint. - name: IATA BSP accreditation note: >- GoStandard or GoGlobal accreditation is a precondition of API access; GoLite has been unsupported for BSP settlement since 4 December 2023.