generated: '2026-08-26' method: searched source: >- Namely developer portal (developers.namely.com) articles and the published Swagger 2.0 contract at openapi/namely-api-openapi.json, read 2026-08-26. name: Namely standards conformance description: >- Namely's contract is a Swagger 2.0 document with a JSON API-flavoured response envelope. Its strongest standards claim is not in the REST API at all - it is the SCIM 2.0 provisioning surface Namely runs alongside it for identity providers, which is the domain standard for HR systems of record feeding IdPs and is declared with the standard IETF SCIM extension URN. conformance: - id: scim label: SCIM 2.0 (System for Cross-domain Identity Management) conforms: true domain_standard: true evidence: - type: endpoint value: https://{company}.namely.com/api/scim/v2/Users.json source: https://developers.namely.com/docs/okta/syncing-custom-fields.md note: >- The canonical SCIM 2.0 /Users resource path, served per-tenant on the customer's own Namely subdomain. - type: schema-urn value: 'urn:ietf:params:scim:schemas:extension:custom:2.0:User' source: https://developers.namely.com/docs/okta/syncing-custom-fields.md note: >- Namely instructs integrators to declare custom profile attributes under the IETF SCIM extension namespace - a contract-level declaration of the standard, not a marketing claim. - type: docs value: https://developers.namely.com/docs/okta/okta-overview.md note: >- "The Okta <> Namely SCIM integration allows you to use Namely as a master for your user profiles" - Namely is the SCIM source of record. note: >- REWARD-ONLY signal. This is the domain standard that matters for an HRIS: an identity platform that already speaks SCIM integrates with Namely without a bespoke connector. The SCIM surface is documented but is NOT described by the published Swagger contract, which covers only the /api/v1 REST surface. - id: saml label: SAML 2.0 conforms: true role: Service Provider evidence: - type: docs value: https://developers.namely.com/docs/getting-started/sso.md note: >- "Namely currently supports SAML 2.0." Namely publishes a SAML metadata endpoint for IdP configuration and names Okta, OneLogin and Microsoft Entra ID (Azure AD) as supported identity providers. - id: oauth2 label: OAuth 2.0 conforms: true profile: RFC 6749 authorization code grant + refresh token evidence: - type: docs value: https://developers.namely.com/docs/getting-started/authentication.md note: >- Documented 3-legged authorization code flow with /oauth2/authorize and /oauth2/token on the tenant host, 15-minute access tokens and non-expiring refresh tokens. - type: gap value: >- The published Swagger 2.0 document declares only an apiKey securityDefinition; the OAuth 2.0 flows are absent from the machine-readable contract. - id: oidc label: OpenID Connect conforms: false evidence: - type: probe value: https://namely.com/.well-known/openid-configuration status: 404 - type: probe value: https://api.namely.com/.well-known/openid-configuration status: 200 note: Returns the HRIS login page HTML, not a discovery document. Treated as absent. - id: json-api label: 'JSON API: linked-object envelope' conforms: partial evidence: - type: docs value: https://developers.namely.com/docs/getting-started/linked-objects.md note: >- Namely's own docs title this "JSON API: Linked Objects" and the envelope is the early JSON API shape - a top-level resource array, a per-resource `links` hash of related ids, a top-level `links` type map, and a top-level `linked` sideload hash. deviations: - >- This is the pre-1.0 JSON API sideloading shape (`linked`), not the jsonapi.org 1.0 `included`/`relationships` structure. Content type is application/json, not application/vnd.api+json. - >- Namely states plainly that linkage is read-only: "it is not possible in our current API to do a POST or a PUT that will link objects together." - id: rfc9457 label: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: - type: spec value: openapi/namely-api-openapi.json note: >- The contract declares no application/problem+json media type and, in fact, declares no 4xx or 5xx response at all across its 54 operations. - id: rfc8594 label: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: - type: search value: developers.namely.com note: No Sunset or Deprecation header, and no deprecation policy, is documented. - id: idempotency label: Idempotency keys conforms: false evidence: - type: spec value: openapi/namely-api-openapi.json note: >- No Idempotency-Key header parameter on any of the seven POST operations, and no idempotency guidance in the docs. - id: pagination label: Pagination conforms: true style: page-number evidence: - type: docs value: https://developers.namely.com/docs/getting-started/changelog.md note: >- "Pagination of /notifications (per_page defaults to 30; can be set as 50 max)" and the 2017-09-20 entry requiring clients to paginate /profiles. Response meta carries `count` (this page) and `total_count` (all available), a distinction Namely fixed on 2017-08-15. - id: openapi label: OpenAPI / Swagger conforms: true version: '2.0' evidence: - type: spec value: openapi/namely-api-openapi.json note: >- Provider-published Swagger 2.0, 39 paths / 54 operations / 95 definitions, exported from Namely's own Stoplight workspace (workspace slug `namely`, domain developers.namely.com). deviations: - Swagger 2.0, not OpenAPI 3.x. info.version is an empty string. - No `host` or `basePath`; the base URL is documented in prose only, and is tenant-templated. - No `security` requirement applied to any operation. - No 4xx/5xx responses declared anywhere in the document. - id: asyncapi label: AsyncAPI / event surface conforms: false evidence: - type: search value: developers.namely.com + github.com/namely note: >- Namely documents no webhooks, no event stream and no callback surface, and publishes no AsyncAPI. Integration with Okta, Greenhouse, Jobvite and NetSuite is polling/batch sync through Namely Connect, not provider-emitted events. Not penalised - there is no event surface to describe. - id: fhir label: FHIR conforms: false applicable: false note: Not a health-data provider; out of domain. compliance_certifications: published: false searched: - url: https://namely.com/compliance/ status: 200 finding: >- A product-features page about the HR compliance reporting Namely gives its customers (OSHA, EEO-1, EEOC, ACA), not a page about Namely's own security attestations. - url: https://trust.namely.com/ status: 200 finding: >- NOT a Namely trust center. It resolves to /users/login and is a Namely CUSTOMER's tenant ("Trust Automation Inc. on Namely") on the multi-tenant {company}.namely.com pattern. Recording it as a trust center would have been a false positive. - url: https://namely.com/security/ status: 200 finding: Redirects to the marketing homepage; no security page exists at that path. note: >- Namely names no SOC 2, ISO 27001, HIPAA, PCI or FedRAMP attestation on any public page found in this pass. No Compliance or TrustCenter pointer is emitted.