generated: '2026-09-03' method: derived source: openapi/mystars-faas-fulfilment-api-openapi-original.json note: >- Derived from the published OpenAPI 3.1.0 and the developer-portal overview. No published compliance program or certifications (no SOC 2 / ISO 27001 / PCI page, no trust center) - the service is explicitly non-custodial and no-KYC, so no Compliance pointer is emitted. The provider's market (Telegram digital-goods fulfilment on TON) has no domain API standard to declare; reward-only, not penalised. standards: - id: openapi-3.1 conforms: true evidence: Published spec at https://mystars.tg/openapi.json declares openapi 3.1.0 with 9 operations. - id: apis-json conforms: true evidence: >- Valid APIs.json (specificationVersion 0.18, aid mystars.tg:faas) served at https://mystars.tg/apis.json - saved verbatim in well-known/. - id: rfc9116-security-txt conforms: true evidence: >- RFC 9116 security.txt at https://mystars.tg/.well-known/security.txt with Contact, Expires, Preferred-Languages, Canonical. - id: idempotency conforms: true evidence: >- Required Idempotency-Key header on POST /v1/orders; same key + identical body replays the original order, different body is 409 (components.parameters.IdempotencyKey). - id: pagination conforms: true evidence: Cursor pagination on GET /v1/orders (limit + cursor params, next_cursor response field). - id: ratelimit-headers conforms: true evidence: >- RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset + Retry-After documented on the per-minute budget 429s (draft-ietf-httpapi-ratelimit-headers style). - id: hmac-webhook-signing conforms: true evidence: >- X-Faas-Signature - hex HMAC-SHA256 of the exact raw body under the webhook secret (Stripe/GitHub scheme), with a 24-hour dual-signature secret-rotation rollover. - id: rfc9457-problem-details conforms: false evidence: 'Errors use a custom { error: { code, message } } envelope, not application/problem+json.' - id: oauth2 conforms: false evidence: Single apiKey scheme (X-Api-Key header); no oauth2/openIdConnect securitySchemes. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header support or deprecation policy found.