generated: '2026-07-19' method: searched source: https://apizone.suunto.com/how-to-start notes: >- Standards conformance for the Suunto Cloud API, asserted only where the public documentation carries direct evidence. Liesheng publishes no certifications or compliance program (no SOC 2 / ISO 27001 / PCI / HIPAA page was found by probe or search), so no Compliance pointer is emitted. standards: - id: oauth2 conforms: true evidence: >- Authorization-code flow documented with authorize and token endpoints on https://cloudapi-oauth.suunto.com, plus refresh tokens. - id: rfc6749-authorization-code conforms: true evidence: >- response_type=code, redirect_uri, grant_type=authorization_code exchange documented verbatim. - id: rfc7519-jwt conforms: true evidence: >- Access tokens are JWTs; the FAQ cites RFC 7519 directly and documents a custom `user` claim. - id: rfc7617-http-basic conforms: true evidence: >- Token endpoint authenticated with Authorization: Basic Base64(client_id:client_secret). - id: openid-connect conforms: false evidence: >- No /.well-known/openid-configuration on cloudapi.suunto.com or apizone.suunto.com (404); OAuth2 authorization only, no id_token documented. - id: ant-fit conforms: true evidence: >- Workout payloads are FIT files; the FAQ links ANT+ FIT technical guidance and publishes FIT examples and device product-ID references. - id: gpx conforms: true evidence: Routes are pushed to the API as GPX files with waypoints. - id: rfc9457-problem-details conforms: false evidence: No public error reference or application/problem+json usage found. - id: rfc9116-security-txt conforms: partial evidence: >- https://www.suunto.com/.well-known/security.txt exists and parses, but its Contact and Policy fields both point at the privacy policy rather than a vulnerability-disclosure channel. - id: asyncapi conforms: false evidence: >- Webhooks are documented in prose only; no AsyncAPI document is published.