generated: '2026-08-27' method: searched source: >- Klarna's own API reference and legal/compliance documentation, plus the OpenAPI files in this repo and the OIDC discovery document at login.klarna.com. description: >- Cross-cutting and domain-standard conformance for Klarna. Klarna's merchant REST APIs are plain JSON over HTTP with proprietary error envelopes — they conform to no general API standard. The standards Klarna genuinely implements sit at the identity and regulated-payments layer: OAuth 2.0 / OpenID Connect for Sign in with Klarna, and PSD2 / eIDAS for the XS2A open-banking API. Absences below are recorded as absences, not as failures. standards: - id: oauth2 conforms: true evidence: >- login.klarna.com publishes an RFC 8414-shaped discovery document declaring authorization_endpoint, token_endpoint, revocation_endpoint, grant_types_supported [authorization_code, refresh_token] and 34 scopes. Probed 2026-08-27, HTTP 200. source: https://login.klarna.com/.well-known/openid-configuration scope: Sign in with Klarna only — the merchant REST APIs do not use OAuth. - id: oidc conforms: true evidence: >- Full OpenID Connect discovery document: issuer, jwks_uri, userinfo_endpoint, subject_types_supported [public, pairwise], id_token_signing_alg_values_supported [RS256, ES256], claims_supported (16 claims including verified name and date of birth). source: https://login.klarna.com/.well-known/openid-configuration - id: oauth2-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256]' source: https://login.klarna.com/.well-known/openid-configuration - id: rfc8414-oauth-metadata conforms: partial evidence: >- The metadata is served at /.well-known/openid-configuration but NOT at /.well-known/oauth-authorization-server (probed 2026-08-27, HTTP 404). - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere. Klarna ships two proprietary JSON error envelopes — {correlation_id, error_code, error_messages} on the v1 merchant APIs and {error_id, error_type, error_code, error_message, errors[]} on the Klarna Network v2 gateway. source: errors/klarna-problem-types.yml - id: idempotency conforms: true evidence: >- Klarna-Idempotency-Key header on POST and PATCH, UUIDv5 keys, 24-hour retention, replay of the original result on a duplicate. Klarna states idempotent integration is REQUIRED for any action that could change a transaction's status. standard_header: false standard_header_note: >- Uses a vendor-prefixed header, not the IETF draft `Idempotency-Key`. source: https://docs.klarna.com/api/kn/direct-partner/integration-resilience/ - id: ietf-ratelimit-headers conforms: partial evidence: >- Klarna emits X-Ratelimit-Limit / -Remaining / -Reset (pre-standard prefixed names) but the quota-policy value syntax `N;w=S;name="..."` does follow the IETF draft RateLimit-Policy shape. No Retry-After on 429. source: https://docs.klarna.com/api/kn/direct-partner/rate-limiting/ - id: rfc8594-sunset-header conforms: false evidence: >- A written six-month deprecation policy exists, but no Sunset or Deprecation response header is documented on any Klarna endpoint. source: lifecycle/klarna-lifecycle.yml - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on www.klarna.com, api.klarna.com, docs.klarna.com and login.klarna.com (probed 2026-08-27), despite Klarna operating a published responsible- disclosure programme. source: well-known/klarna-well-known.yml - id: json-api conforms: false evidence: Plain JSON; no JSON:API document structure, media type or relationships. - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false evidence: Not a healthcare API. - id: openapi conforms: partial evidence: >- OpenAPI 3.0 documents exist for the v1 merchant APIs and are held in this repo, but Klarna publishes NO fetchable specification URL. Probed 2026-08-27: /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all 404 on api.klarna.com and docs.klarna.com. The reference site is a Next.js application that renders operations from an internally-held specification and exposes no downloadable artifact. - id: asyncapi conforms: false evidence: >- Klarna documents outbound push callbacks and a Notifications API, but publishes no AsyncAPI document. The AsyncAPI in this repo is a derived description of that webhook surface, not a Klarna-published specification. - id: mutual-tls conforms: true evidence: XS2A endpoints require mutual TLS with an eIDAS certificate; role extraction from the certificate. scope: Klarna XS2A only source: https://docs.klarna.com/api/xs2a/authentication/ - id: tls12-minimum conforms: true evidence: >- Klarna documents TLS 1.2 minimum and requires SNI. Live probe 2026-08-27 recorded TLSv1.2 on api.klarna.com and TLSv1.3 on www.klarna.com and docs.klarna.com. source: security/klarna-domain-security.yml domain_standards: - id: psd2 name: PSD2 / Berlin Group XS2A conforms: true market: European open banking / account information and payment initiation evidence: >- Klarna operates a PSD2 XS2A API at xs2a.banking.klarna.com. Its own requirements page states production access requires the caller to be "a licensed TPP according to PSD2 legislation" and to hold an eIDAS certificate for mutual identification. The certificate is validated and the TPP roles (AIS, PIS, PIIS) are extracted from it; an invalid certificate or insufficient role returns 403. spec_location: >- https://docs.klarna.com/api/xs2a/requirements/ and https://docs.klarna.com/api/xs2a/authentication/ — the conformance signature is the TPP role vocabulary (AIS/PIS/PIIS) and the eIDAS QWAC/QSEAL requirement, both PSD2 RTS constructs, asserted by the API's own access contract rather than by a marketing page. caveat: >- Klarna does not publish a Berlin Group NextGenPSD2 conformance statement or a downloadable XS2A specification; the standard is evidenced through the access requirements, not a spec. - id: eidas name: eIDAS qualified certificates conforms: true evidence: >- Approved Trust Centre certificates required for XS2A; Klarna names Bundesdruckerei as an issuer for German test certificates. source: https://docs.klarna.com/api/xs2a/requirements/ - id: emvco-3ds name: 3-D Secure conforms: true evidence: >- Klarna publishes a sandbox card number specifically to trigger a 3-D Secure flow (4687388888888881), i.e. the card rail behind Klarna's card products supports 3DS. source: https://docs.klarna.com/acquirer/klarna/resources/developer-tools/sample-data/sample-payment-data/ caveat: Klarna publishes no 3DS version or conformance statement. - id: iso-20022 conforms: false evidence: >- Settlement reports are published as CSV, PDF and JSON via the Settlements API and SFTP. No ISO 20022 message type (camt/pain/pacs) is published. compliance_program: published: partial certifications_published: [] note: >- Probed 2026-08-27 with 0-working/probe-security-programs.py: no trust centre found at trust.klarna.com, security.klarna.com, or klarna.com/trust|/security|/compliance. Klarna is a licensed bank (Klarna Bank AB, Swedish FSA) and its regulatory disclosures live in investor and legal pages rather than a developer-facing trust centre. NO Compliance pointer is emitted from this artifact, because Klarna publishes no named certification list (SOC 2 / ISO 27001 / PCI DSS AoC) that this pipeline could verify. Recording the absence rather than asserting a programme we could not find. verified_surfaces: - {url: 'https://www.klarna.com/international/responsible-disclosure/', status: 200, kind: responsible disclosure} - {url: 'https://www.klarna.com/us/legal/', status: 200, kind: legal index} regulatory_context: entity: Klarna Bank AB (publ) regime: EU banking + PSD2; consumer credit regulation per market (e.g. FCA in the UK) evidence: >- Klarna publishes market-specific regulated-financing promotion guidance for the UK naming the FCA, at https://docs.klarna.com/acquirer/klarna/resources/marketing-tools/partner-marketing-legal-guidelines/united-kingdom/regulated-financing-promotion-rules-101/ maintainers: - FN: Kin Lane email: kin@apievangelist.com