generated: '2026-07-25' method: searched source: https://developers.mtn.com/getting-started/things-every-developer-should-know, https://developers.mtn.com/getting-started/understanding-oauth-20, developers.mtn.com product catalogue, openapi/ standards: - id: tmforum-open-api conforms: true evidence: '22 TM Forum Open API products published in the catalogue: TMF620, TMF621, TMF622, TMF629, TMF632, TMF633, TMF635, TMF637, TMF639, TMF652, TMF654, TMF658, TMF666, TMF667, TMF676, TMF677, TMF678, TMF681, TMF683, TMF685, TMF688, TMF720 — with TMF hub/listener event registration and tmf-api URI namespaces' - id: oauth2 conforms: true evidence: client_credentials flow at https://api.mtn.com/v1/oauth/access_token; oauth2 securityScheme declared in 77 harvested specifications - id: oauth2-client-credentials conforms: true evidence: grant_type=client_credentials documented as the only grant - id: openid-connect conforms: false evidence: no /.well-known/openid-configuration on any MTN host; no openIdConnect securityScheme in any spec - id: camara conforms: false evidence: 'MTN South Africa is a GSMA Open Gateway participant (Number Verification and SIM Swap announced with Cell C and Telkom, February 2024) but nothing published is CAMARA-shaped: SIM Swap and Device Swap are MTN-proprietary designs secured with OAuth2 client_credentials rather than the CAMARA OIDC/CIBA profile, and no CAMARA API is callable from either portal' - id: gsma-open-gateway conforms: partial evidence: announced participant via MTN South Africa; no Open Gateway conformant endpoint is published on developers.mtn.com - id: rfc9457-problem-details conforms: false evidence: no specification declares application/problem+json; MADAPI uses a timestamp/status/error/message/path envelope - id: rfc8594-sunset-header conforms: false evidence: version-support window is published (n and n-1 only) but no Sunset or Deprecation header contract - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.mtn.com, developers.mtn.com and momodeveloper.mtn.com - id: rfc3339-datetime conforms: true evidence: RFC 3339 mandated for date/time fields in the platform conventions - id: iso3166-country-codes conforms: true evidence: ISO 3166 mandated for country names and codes - id: iso4217-currency-codes conforms: true evidence: ISO 4217 currency codes; sandbox currency is EUR - id: e123-msisdn conforms: true evidence: E.123 mandated for telephone MSISDN numbers - id: hateoas conforms: true evidence: responses carry a _links object; the platform conventions document hypermedia navigation - id: uri-path-versioning conforms: true evidence: https://api.mtn.com/v1/customers — URI namespace versioning documented - id: idempotency-key conforms: true evidence: MoMo X-Reference-Id (UUID v4) must be unique per request; replay returns 409 RESOURCE_ALREADY_EXIST - id: openapi-3 conforms: partial evidence: 16 of 115 harvested specifications are OpenAPI 3.0.x; the remaining 99 are Swagger 2.0 - id: asyncapi conforms: false evidence: no AsyncAPI document published; event surfaces are documented prose plus TMF hub/listener operations - id: psd2 conforms: false - id: fapi conforms: false - id: scim2 conforms: false - id: fhir conforms: false - id: odata conforms: false - id: json-api conforms: false certifications_published: false certifications_note: No trust centre and no named certification (SOC 2, ISO 27001, PCI DSS) is published on the developer or corporate surface. MTN publishes an Information Security position statement PDF and MTN (PTY) LTD is an authorised South African Financial Service Provider, FSP licence 44774, but neither is an API compliance programme.