generated: '2026-07-19' method: derived source: openapi/lightstream-{live,layout,event}-openapi-original.yml + https://www.api.stream/docs/api/ notes: >- Standards posture derived from the three published Swagger 2.0 documents, the buf Protobuf configuration in golightstream/api.stream-sdk, and the API.stream design documentation. No published compliance program (SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP) was found for Lightstream or API.stream, so no Compliance pointer is wired. standards: - id: grpc conforms: true evidence: All services are gRPC-first; native gRPC, gRPC-Web and REST gateways documented at https://www.api.stream/docs/api/protocol/ - id: protobuf conforms: true evidence: proto/buf.yaml and buf.gen.yaml in golightstream/api.stream-sdk generate Go, TypeScript and gRPC bindings from Protobuf contracts - id: grpc-gateway conforms: true evidence: buf dependency buf.build/grpc-ecosystem/grpc-gateway; the REST surface is a generated gateway (rpcStatus error envelope, updateMask field masks) - id: openapi-2.0 conforms: true evidence: >- Swagger 2.0 documents published for the Live (2.1), Layout (2.0) and Event (2.0) APIs - id: openapi-3.x conforms: false evidence: specs are Swagger 2.0, not OpenAPI 3 - id: protobuf-field-mask conforms: true evidence: updateMask required on gRPC update RPCs, auto-computed by the REST gateway (https://www.api.stream/docs/api/live/usage) - id: jwt-rfc7519 conforms: true evidence: >- access tokens are JWTs asserted as the 'Authorization: Bearer' header - id: jwks-rfc7517 conforms: true evidence: PublicAuthenticationService_GetJsonWebKeySet publishes a JSON Web Key Set at https://live.api.stream/live/v2/authentication/jwks - id: oauth2 conforms: false evidence: no oauth2 securityDefinitions; tokens are minted by a backend API-key call, not an OAuth grant - id: openid-connect conforms: false evidence: no /.well-known/openid-configuration on any host (all 404) - id: rfc9457-problem-details conforms: false evidence: errors use the google.rpc.Status envelope (code/message/details), not application/problem+json - id: json-api conforms: false evidence: plain JSON request/response bodies generated from Protobuf messages - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on live.api.stream, api.stream and golightstream.com - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header support documented - id: idempotency-key conforms: false evidence: no idempotency key header or parameter in any published spec - id: webrtc conforms: true evidence: WebRTC ingest/egress is a first-class surface (ProjectService_StartProjectWebRtc, CreateWebRtcAccessToken, LiveKit-based backend) - id: rtmp conforms: true evidence: RTMP push/pull source and destination address types in the Live API definitions - id: srt conforms: true evidence: SRT push address type in the Live API source definitions - id: hls conforms: true evidence: HLS packaging and lifecycle (live / VOD) definitions in the Live API - id: buf-breaking-change-detection conforms: true evidence: 'proto/buf.yaml sets breaking.use: [FILE]'