generated: '2026-07-20' method: derived source: >- Derived from openapi/judo-bank-cds-banking-products-openapi.yml (CDS Banking API 1.36.0, x-fapi headers, ErrorV2 schema, page/page-size pagination, header versioning) and Judo Bank's status as an accredited ADI / CDR data holder (https://www.judo.bank/open-banking/). No independent security-certification program (SOC 2 / ISO 27001) is published on the developer surface, so no Compliance pointer is asserted. standards: - id: cdr-consumer-data-standards conforms: true evidence: >- Implements the DSB Consumer Data Standards Banking API (spec title "CDR Banking API", version 1.36.0); served at the CDS path /cds-au/v1. - id: cdr-product-reference-data conforms: true evidence: >- Public unauthenticated GET /banking/products and /banking/products/{productId} (Product Reference Data) confirmed live at https://public.open.judo.bank/cds-au/v1 (HTTP 200, x-v 3). - id: fapi conforms: partial evidence: >- Uses FAPI interaction headers (x-fapi-interaction-id, x-fapi-auth-date, x-fapi-customer-ip-address) per the CDS security profile; full FAPI-protected resource applies to the authenticated ADR data-sharing surface, not the public PRD endpoints. - id: oauth2 conforms: true evidence: >- CDR authenticated data sharing uses OAuth 2.0 authorisation-code + PKCE via the CDS security profile (data holder authorisation server brokered by the CDR Register). Not exercised by the public PRD surface. - id: oidc conforms: true evidence: >- CDS security profile is built on OpenID Connect (CDR uses OIDC hybrid / authorization-code flows). Discovery is not exposed on the public PRD host. - id: header-versioning conforms: true evidence: x-v / x-min-v request headers and x-v response header per CDS versioning. - id: pagination conforms: true evidence: page / page-size query parameters with meta.totalRecords / totalPages + links. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the CDS ErrorV2 list envelope with URN error codes, not application/problem+json. - id: rfc4122-uuid conforms: true evidence: x-fapi-interaction-id is an RFC 4122 UUID. - id: idempotency conforms: false evidence: Public PRD surface is read-only GET; no idempotency-key contract. - id: json-api conforms: false - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false