generated: '2026-08-13' method: derived source: openapi/karumi-public-api-openapi.json + well-known/karumi-well-known.yml + https://www.karumi.ai/mcp-documentation standards: - id: openapi-3.1 conforms: true evidence: openapi/karumi-public-api-openapi.json declares openapi 3.1.0 and parses with 9 paths and 21 component schemas. - id: json-schema-2020-12 conforms: true evidence: OpenAPI 3.1 schema objects; the spec uses anyOf/null unions and format keywords (uuid, date-time) throughout. - id: mcp conforms: true evidence: Hosted MCP server at https://api.karumi.ai/mcp/ answering JSON-RPC over HTTPS with an mcp-session-id header; 37 published tools. - id: oauth2 conforms: true evidence: MCP server uses OAuth 2.0 authorization code with PKCE (S256) via the Supabase Auth authorization server named in its protected-resource metadata. - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported [S256, plain] in well-known/karumi-oauth-authorization-server.json - id: rfc9728-oauth-protected-resource conforms: true evidence: https://api.karumi.ai/.well-known/oauth-protected-resource returns 200, and the 401 from https://api.karumi.ai/mcp/ carries WWW-Authenticate Bearer with a resource_metadata parameter. - id: rfc8414-authorization-server-metadata conforms: partial evidence: Served by the delegated Supabase Auth issuer, not by Karumi. Karumi's own /.well-known/oauth-authorization-server returns 404. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint present in the delegated authorization server metadata. - id: oidc conforms: partial evidence: The delegated authorization server publishes an OpenID configuration and supports openid/profile/email scopes; Karumi itself is a relying party, not an OIDC provider. - id: rfc9457-problem-details conforms: false evidence: Errors are the FastAPI `detail` envelope in application/json; no application/problem+json anywhere in the spec or in observed responses. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Karumi host. - id: rfc8615-well-known-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every Karumi host. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Karumi host. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published; nothing to conform to. - id: json-api conforms: false evidence: Custom items/total/limit/offset envelope, not the JSON:API media type. - id: pagination conforms: true evidence: Consistent limit/offset with a total count on both list operations; see conventions/karumi-conventions.yml. - id: idempotency conforms: false evidence: No idempotency key contract. The published API is entirely GET, so the question does not arise on the REST surface; the MCP write tools publish no replay semantics. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy or Sunset header behaviour is documented. compliance_program: published: true url: https://trust.delve.co/karumi certifications: - SOC 2 - ISO 27001 - GDPR note: >- Certification names are taken verbatim from the enterprise-security section of https://www.karumi.ai/ and from the pricing page, which lists "SOC 2 Type II & ISO 27001 compliance" as an Enterprise-plan feature. The Delve-hosted trust portal returned HTTP 429 on direct fetch on both 2026-07-19 and 2026-08-13, so the certificate documents themselves were not read. See security/karumi-trust-center.yml.