generated: '2026-07-19' method: derived source: >- openapi/ plus https://rajaongkir.com/docs/qrisly/getting-started/authentication, https://rajaongkir.com/docs/payment-api/getting-started/callback-handling note: >- Derived from the harvested specs and documentation. Komerce publishes no security or compliance certifications (no SOC 2, ISO 27001, PCI DSS or trust centre was found), so no Compliance pointer is wired into apis.yml. standards: - id: openapi-3 conforms: true evidence: Four OpenAPI 3.0.3 descriptions generated from the published reference; Komerce itself publishes no machine-readable spec. - id: api-key-header-auth conforms: true evidence: All four products authenticate with a header API key (key / x-api-key / X-API-Key). - id: oauth2 conforms: false evidence: No OAuth 2.0 flows are documented on any surface. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors use a proprietary meta{message,code,status} or success/message/error_code envelope, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented. - id: idempotency-key conforms: false evidence: No idempotency key header or parameter is documented on any operation. - id: pagination conforms: true evidence: limit / offset query parameters on the destination search operations of the Shipping Cost API. - id: rate-limit-headers conforms: true evidence: X-RateLimit-Limit / X-RateLimit-Remaining / X-RateLimit-Reset plus Retry-After documented for QRISLY. - id: hmac-sha256-webhook-signature conforms: true evidence: Payment Service callbacks are signed HMAC-SHA256 over the raw JSON body and delivered in the X-Callback-Api-Key header. - id: qris conforms: true evidence: >- QRISLY generates dynamic QRIS payloads conforming to QRIS, the Indonesian national QR payment standard operated by Bank Indonesia; the generated qris_string is an EMVCo-style QR payload. - id: json-api conforms: false - id: odata conforms: false - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: psd2 conforms: false evidence: Indonesian market; PSD2 is an EU regime and does not apply. - id: fapi conforms: false certifications: published: false evidence: No trust centre, security page, or named certification was found on komerce.id, rajaongkir.com or collaborator.komerce.id.