generated: '2026-07-19' method: derived source: >- openapi/kotoba-transcription-openapi-original.yml, openapi/kotoba-asr-realtime-openapi-original.yml, openapi/kotoba-sts-realtime-openapi-original.yml, openapi/kotoba-tts-realtime-openapi-original.yml, asyncapi/kotoba-asr-asyncapi.yml, asyncapi/kotoba-sts-asyncapi.yml, asyncapi/kotoba-tts-asyncapi.yml, https://docs.kotoba.tech/overview/authentication notes: >- Derived from the captured specs and the public docs. Kotoba publishes no certification or compliance program (no SOC 2 / ISO 27001 / HIPAA / GDPR page was found), so no `Compliance` pointer is emitted. standards: - id: openapi-3.1 conforms: true evidence: 'all four OpenAPI documents declare `openapi: 3.1.0`' - id: asyncapi-2.6 conforms: true evidence: 'all three realtime channels declare `asyncapi: 2.6.0`' - id: rfc6455-websocket conforms: true evidence: >- ASR, STS and TTS are JSON-over-WebSocket channels with `wss` servers declared in the AsyncAPI documents - id: rfc6750-bearer-token conforms: true evidence: >- securityScheme `bearerAuth` (http/bearer); docs specify `Authorization: Bearer ` on the WebSocket handshake - id: rfc7617-http-basic conforms: true evidence: securityScheme `httpBasic` (http/basic) on the STS channel; device_id as username, api_key as password - id: oauth2 conforms: false evidence: no oauth2 securityScheme in any spec and no OAuth flow documented - id: openid-connect conforms: false evidence: no openIdConnect securityScheme; /.well-known/openid-configuration not served - id: rfc9457-problem-details conforms: false evidence: >- errors do not use application/problem+json; the REST API returns a FastAPI-style HTTPValidationError envelope (`detail[]` of loc/msg/type) and the realtime channels emit a bespoke `error` event - id: json-api conforms: false evidence: responses are plain application/json, not JSON:API media type - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt served on any host (see well-known/kotoba-well-known.yml) - id: rfc8594-sunset-header conforms: false evidence: no deprecation or sunset policy published - id: pagination conforms: false evidence: no collection-listing operations in the REST surface; nothing to paginate - id: idempotency conforms: false evidence: >- no idempotency key header or parameter in any spec and none documented; POST /v1/transcription_jobs creates a new job per call - id: iso-639-1-language-codes conforms: true evidence: >- `language` parameter documented as ISO-639-1 (en, ja, ko, zh; plus es for STS and TTS) - id: llms-txt conforms: true evidence: https://docs.kotoba.tech/llms.txt published, with llms-full.txt and per-page .md - id: model-context-protocol conforms: true evidence: >- live remote MCP server at https://docs.kotoba.tech/_mcp/server, protocol version 2025-06-18 (documentation scope only)