generated: '2026-08-25' method: searched source: >- https://auth0.metabolon.com/.well-known/openid-configuration ; openapi/metabolon-portal-api-openapi.yml ; https://www.metabolon.com/quality-assurance/ ; https://www.metabolon.com/support/portal/data/ note: >- Cross-cutting standards asserted against the live contract and Metabolon's own published quality and data pages. Metabolon's market (metabolomics contract research) has laboratory and clinical-research standards rather than an API interchange standard, and no domain API standard (there is no metabolomics equivalent of FHIR or SCIM that Metabolon's contract declares), so domain_standard is recorded as not-applicable rather than failed. standards: - id: openapi-3.0 conforms: true evidence: 'All four services publish OpenAPI 3.0.0 documents at /swagger/v1/swagger.json, generated by NSwag v14.x' - id: oauth2 conforms: true evidence: 'auth0.metabolon.com serves RFC 8414 /.well-known/oauth-authorization-server with authorization, token and revocation endpoints' - id: oidc conforms: true evidence: 'auth0.metabolon.com serves an OpenID Provider Configuration with issuer, jwks_uri, userinfo_endpoint and 16 claims_supported' - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported = [S256, plain] in the OIDC discovery document' - id: rfc7009-token-revocation conforms: true evidence: 'revocation_endpoint https://auth0.metabolon.com/oauth/revoke' - id: rfc8628-device-authorization conforms: true evidence: 'device_authorization_endpoint https://auth0.metabolon.com/oauth/device/code' - id: rfc7807-problem-details conforms: true evidence: 'Every 4xx/5xx response references components.schemas.ProblemDetails (type/title/status/detail/instance + additionalProperties); two operation descriptions name RFC7807 explicitly' - id: rfc9457-problem-details conforms: false evidence: 'Problem bodies are served as application/json, not application/problem+json; the document targets the RFC 7807 predecessor' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on www.metabolon.com and on all four API hosts' - id: rfc8594-sunset-header conforms: false evidence: 'No Sunset or Deprecation response headers are declared anywhere in the published specs' - id: rfc6749-idempotency conforms: false evidence: 'No Idempotency-Key header parameter appears in any of the four specs' - id: pagination conforms: partial evidence: 'skip/take on pipeline-status records and page_size/limit on Salesforce pending users; no cursor scheme and no pagination envelope shared across resources' - id: json-api conforms: false evidence: 'Plain JSON DTOs; no JSON:API document structure' - id: odata conforms: false evidence: 'No $metadata surface and no OData query options' - id: scim conforms: false evidence: 'User and role management is a bespoke /api/v1/admin/users surface; no urn:ietf:params:scim:schemas URNs' - id: graphql conforms: false evidence: 'No /graphql surface responded on any Metabolon host' - id: asyncapi conforms: false evidence: 'No event, streaming or webhook surface is published; the Auth0 hooks are inbound calls INTO the Portal API, not outbound webhooks' - id: mcp conforms: false evidence: 'No hosted MCP server and no MCP package published by Metabolon' - id: a2a conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json return 404 on every real host' domain_standard: applicable: false note: >- Metabolon operates in metabolomics contract research. Its regulated obligations are laboratory and clinical-trial standards (CLIA, CAP, ISO 9001, GCP/GCLP, ICH M10), which are process accreditations, not machine-readable interchange contracts. Community metabolomics data standards do exist (mzML, MetaboLights/MetabolomeXchange, the MSI reporting standards), but the published Metabolon contract declares none of them — result files are delivered as opaque downloads through the Files and SpectralData operations, whose response schemas expose only file metadata and pre-signed download links, not typed spectral records. Recorded as not-applicable rather than non-conformant. published_compliance: page: https://www.metabolon.com/quality-assurance/ certifications: - id: iso-9001-2015 name: ISO 9001:2015 Quality Management Standard scope: organisation - id: clia name: Clinical Laboratory Improvement Amendments certification scope: laboratory - id: cap name: College of American Pathologists accreditation scope: laboratory - id: gcp-ich-e6 name: Good Clinical Practice (ICH E6) scope: clinical studies - id: gclp name: Good Clinical Laboratory Practice (WHO GCLP/08) scope: clinical studies - id: ich-m10 name: ICH M10 bioanalytical method validation scope: bioanalysis - id: gdpr name: General Data Protection Regulation (EU and UK) scope: data protection - id: ccpa name: California Consumer Privacy Act scope: data protection data_center: page: https://www.metabolon.com/support/portal/data/ statement: 'The facility is annually audited under SSAE 18 SOC 2 Type II, PCI-DSS, GLBA, and HIPAA standards and is ITAR registered.' caveat: >- These are audits of the Durham, NC data-centre FACILITY as stated by Metabolon, not certifications of Metabolon itself. Metabolon publishes no SOC 2 report, no ISO 27001 certificate and no trust centre; trust.metabolon.com does not resolve.