generated: '2026-09-03' method: derived source: openapi/mediacaption-api-openapi.yaml + https://www.mediacaption.io/docs description: >- Cross-cutting standards posture derived from the OpenAPI 3.1 contract and the public docs. No industry compliance claims (SOC 2, ISO 27001, etc.) are published anywhere on the site. standards: - id: openapi-3.1 conforms: true evidence: 'openapi/mediacaption-api-openapi.yaml declares openapi: 3.1.0 with 13 operations and 3 webhooks; served from the provider''s own docs host.' - id: oauth2 conforms: false evidence: The public API authenticates with static API keys only (bearer mc_live_ or X-API-Key); no oauth2 securityScheme is declared. A Clerk OIDC tenant exists for web sign-in only (well-known/mediacaption-api-clerk-openid-configuration.json). - id: oidc conforms: false evidence: OIDC discovery at clerk.mediacaption.io governs the web app, not the public API. - id: rfc9457 conforms: false evidence: 'Errors use a proprietary { error: { code, message } } envelope, not application/problem+json.' - id: pagination conforms: true evidence: Cursor pagination (limit/cursor params, Job.nextCursor) on GET /v1/jobs/{id} items. - id: idempotency conforms: false evidence: No Idempotency-Key mechanism on writes; docs warn duplicate POST retries spend additional credits. Webhook consumers get MediaCaption-Event-Id for delivery dedupe. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation headers or deprecation policy published. - id: webhook-signatures conforms: true evidence: 'HMAC-SHA256 signatures (MediaCaption-Signature: v1=…, timestamp + "." + rawBody) with timestamp staleness checks and constant-time comparison guidance at https://www.mediacaption.io/docs/webhooks.' domain_standards: note: >- No domain standard is declared by the contract. Transcript output is offered to end users as SRT and VTT downloads on the web product, but the API contract returns transcript segments as proprietary JSON ({ startSec, durationSec, text }) rather than declaring WebVTT/SRT media types on API responses, so no domain_standard_conformance is claimed.