generated: '2026-07-20' method: derived source: openapi/mist-openapi-original.json standards: - id: openapi-3.1 conforms: true evidence: Published OpenAPI 3.1.0 document (mist_openapi), 748 paths / 1050 operations. - id: rest conforms: true evidence: Resource-oriented HTTPS/JSON API using GET/POST/PUT/DELETE under /api/v1. - id: oauth2 conforms: partial evidence: >- OAuth2 is supported for admin login/SSO (login/oauth/{provider}), but the API's own request authentication uses API tokens, not OAuth2 bearer scopes. - id: apikey-auth conforms: true evidence: securitySchemes define an apiKey token in the Authorization header. - id: rfc9457-problem-details conforms: false evidence: Errors use a plain JSON `{detail}` envelope, not application/problem+json. - id: webhooks conforms: true evidence: Org- and site-level webhook subscriptions with topic filtering and ping/test. - id: rate-limiting conforms: true evidence: Documented hourly quota with HTTP 429 on exceed.