generated: '2026-07-19' method: derived source: openapi/*.json + https://api-docs.koin.com.br/docs/integration-requirements note: Standards asserted from the harvested contracts and the provider's published integration requirements. Koin publishes no trust center and names no third-party certification (SOC 2, ISO 27001, PCI DSS) on its public site, so no `Compliance` pointer is emitted in apis.yml. standards: - id: openapi-3.0 conforms: true evidence: Seven of eight harvested contracts declare openapi 3.0.3 (Payments, Antifraud x5, Onboarding). - id: openapi-3.1 conforms: true evidence: The BNPL Payment Request contract declares openapi 3.1.0. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any contract; authentication is a single bearer private key. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any probed host (well-known/koin-well-known.yml). - id: rfc6750-bearer-token conforms: partial evidence: >- Credentials are transmitted as `Authorization: Bearer sk_...`, matching RFC 6750 header syntax, but the token is a static provisioned private key rather than an OAuth 2.0 access token. - id: rfc9457-problem-details conforms: false evidence: Errors use application/json with a proprietary {code, message, causes[]} envelope, not application/problem+json. See errors/koin-problem-types.yml. - id: json-api conforms: false evidence: Resource payloads are plain JSON without JSON:API document structure. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no operation marked deprecated. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every probed host. - id: emv-3ds conforms: true evidence: Koin documents 3-D Secure 2 integration for card antifraud, publishes 3DS test cards for frictionless and challenge flows, and returns authentication proof (CAVV, ECI, XID, directory_server_transaction_id, spec version) in `additional_info` for acquirer pre-authorization. docs: https://api-docs.koin.com.br/docs/antifraud-with-3ds-integration - id: pix conforms: true evidence: Native support for Brazil's Pix instant-payment scheme — dynamic QR pay-in with end_to_end_id and tx_id provider references, plus Pix payout. Status page tracks PIX - Payin and PIX - Payout as separate components. docs: https://api-docs.koin.com.br/docs/pix-copy - id: iso-4217-currency conforms: true evidence: Amounts carry an explicit `currency_code` (e.g. BRL) throughout the Payments contract. - id: iso-3166-country conforms: true evidence: Requests and notifications carry `country_code` (e.g. BR). - id: iso-18245-mcc conforms: true evidence: BNPL notifications carry `store.category` as a merchant category code (e.g. 4816). - id: rfc3339-timestamps conforms: true evidence: All webhook and resource timestamps use RFC 3339 / ISO 8601 UTC form (2021-01-01T00:00:00.000Z). - id: idempotent-notification-processing conforms: true evidence: Integration requirements INF4, CBK3 and NOT1 mandate replay-safe, idempotent processing keyed on a stable unique reference_id. See conventions/koin-conventions.yml. - id: brazilian-cpf-cnpj-identity conforms: true evidence: Buyer identity is captured as document {type CPF|CNPJ, number}, with dedicated validation codes (999 Invalid CPF) and duplicate-identity codes (10101). - id: pagination conforms: false evidence: No collection endpoint exposes page/limit/offset/cursor parameters. - id: rate-limit-headers conforms: false evidence: No rate-limit signalling documented or declared in any contract. - id: asyncapi conforms: false evidence: No AsyncAPI document published; the event surface is a documented webhook catalog (asyncapi/koin-payments-webhooks.yml).