generated: '2026-08-13' method: searched source: https://developers.klaviyo.com/en/reference/api_overview derived_from: openapi/*.yml (23 files, 308 operations, revision 2026-04-15) standards: - id: openapi-3.0 conforms: true evidence: 'All 23 documents in openapi/ declare openapi: 3.0.2.' - id: json-api conforms: partial evidence: >- Every 2xx response is application/vnd.api+json; resources carry type/id/attributes/ relationships; /relationships/ sub-resources exist for every association; JSON:API filtering, sparse fieldsets (fields[TYPE]) and includes are implemented. Klaviyo describes the API as following JSON:API conventions but makes no formal 1.x conformance claim, and the error envelope is JSON:API-shaped rather than certified. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the JSON:API `errors[]` envelope with application/vnd.api+json, not application/problem+json. See errors/klaviyo-problem-types.yml. - id: oauth2 conforms: true evidence: >- Authorization Code grant at https://www.klaviyo.com/oauth/authorize, token at https://a.klaviyo.com/oauth/token, revocation at /oauth/revoke, 46 published scopes. See scopes/klaviyo-scopes.yml. - id: rfc7636-pkce conforms: true evidence: >- PKCE is MANDATORY for both public and confidential clients; code_challenge_method must be S256 (Klaviyo OAuth docs). - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- /.well-known/oauth-authorization-server returns 200 JSON on both a.klaviyo.com and mcp.klaviyo.com. See well-known/klaviyo-well-known.yml. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- https://mcp.klaviyo.com/.well-known/oauth-protected-resource returns 200 with resource_name "Klaviyo MCP Server" and a resource_documentation link. - id: oidc-discovery conforms: true evidence: >- https://a.klaviyo.com/.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint and scopes_supported [openid, profile, email, phone]. - id: rfc7591-dynamic-client-registration conforms: true evidence: >- Both authorization servers advertise a registration_endpoint (https://mcp.klaviyo.com/register, https://a.klaviyo.com/staff/mcp/oauth/register). - id: mcp conforms: true evidence: >- Hosted streamable-HTTP MCP server at https://mcp.klaviyo.com/mcp (401 OAuth challenge observed 2026-08-13) plus a first-party local stdio distribution (PyPI klaviyo-mcp-server). See mcp/klaviyo-mcp.yml. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Klaviyo host. Nothing written to a2a/. - id: asyncapi conforms: partial evidence: >- Klaviyo publishes no AsyncAPI document of its own. asyncapi/klaviyo-webhooks-asyncapi.yaml in this repo is an API Evangelist description of the documented webhook surface, not a provider artifact. - id: rfc8594-sunset-header conforms: false evidence: >- A written 2-year deprecation policy exists but no Sunset/Deprecation response headers are emitted. See lifecycle/klaviyo-lifecycle.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Klaviyo host. - id: draft-ietf-httpapi-ratelimit-headers conforms: true evidence: >- Responses carry RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset (the draft spelling, not X-RateLimit-*), replaced by Retry-After on a 429. - id: rfc3339-datetimes conforms: true evidence: Docs state all datetimes must be formatted as ISO 8601 RFC 3339. - id: hmac-webhook-signing conforms: true evidence: Klaviyo-Signature header, HMAC-SHA256 over the request body with a shared secret. - id: llms-txt conforms: true evidence: https://www.klaviyo.com/llms.txt returns 200 with a real llms.txt document. - id: gdpr conforms: true evidence: >- Published on https://trust.klaviyo.com/; the API exposes a Data Privacy endpoint (request_profile_deletion) for subject deletion requests. - id: soc2 conforms: true evidence: Listed on https://trust.klaviyo.com/. - id: iso-27001 conforms: true evidence: Listed on https://trust.klaviyo.com/ (plus ISO 27017 and ISO 27018). - id: pci-dss conforms: true evidence: Listed on https://trust.klaviyo.com/. - id: hipaa conforms: true evidence: Listed on https://trust.klaviyo.com/. - id: csa-star conforms: true evidence: Listed on https://trust.klaviyo.com/. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false compliance_program: published: true url: https://trust.klaviyo.com/ certifications: [SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR] artifact: security/klaviyo-trust-center.yml x-evidence: - {fetched: '2026-08-13', url: 'https://trust.klaviyo.com/', http_status: 200} - {fetched: '2026-08-13', url: 'https://mcp.klaviyo.com/.well-known/oauth-protected-resource', http_status: 200} - {fetched: '2026-08-13', url: 'https://a.klaviyo.com/.well-known/openid-configuration', http_status: 200} - {fetched: '2026-08-13', url: 'https://www.klaviyo.com/llms.txt', http_status: 200}