generated: '2026-07-26' method: derived source: openapi/nar-m1-gateway-external-openapi.json sources: - openapi/nar-m1-gateway-external-openapi.json - collections/nar-m1-gateway-external.postman_collection.json - https://www.nar.realtor/about-nar/policies/mls-policy/real-estate-transaction-standards-rets-web-api api: REALTORS M1 Gateway External API summary: >- Cross-cutting standards conformance for NAR's own API surface, derived from the published Swagger 2.0 document and NAR's published integration notes. The important distinction for this provider: NAR is the body that MANDATES the RESO Data Dictionary and RESO Web API for association-owned MLSs through MLS Policy Statement 7.90, but its own M1 Gateway is a member-data API that implements none of those standards - it is neither OData nor RESO-shaped, and NAR holds no RESO certification of its own. standards: - id: openapi3 conforms: false evidence: The published definition is Swagger 2.0, not OpenAPI 3.x. - id: swagger2 conforms: true evidence: 'swagger: "2.0" with 64 paths, 88 operations and 99 definitions.' - id: rfc6902-json-patch conforms: true evidence: >- 58 write operations consume application/json-patch+json; every PATCH uses test + replace operation pairs through JsonPatchDocument envelopes. - id: rfc7617-http-basic conforms: true evidence: >- Single securityDefinition {"basic": {"type": "basic"}} applied globally via security [{"basic": []}]. - id: oauth2 conforms: false evidence: No oauth2 security scheme is declared and no authorization server is published. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404 on www.nar.realtor and 401 on the gateway host; no discovery document exists. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json media type; errors are plain HTTP status codes with a FieldValidationErrors body field. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.nar.realtor and 401 on the gateway host. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented or observed. - id: odata-v4 conforms: false evidence: >- No $metadata document, no OData query options, no OData media types - the M1 Gateway is a plain JSON REST surface, unlike the RESO Web API it sits alongside. - id: reso-web-api conforms: false evidence: >- The M1 Gateway carries member, office and association records, not listings, and implements no RESO transport. NAR does not appear in the public RESO certificate directory at reso.org/certificates. relationship: mandator note: >- MLS Policy Statement 7.90 requires MLS organizations owned and operated by associations of REALTORS to implement the RESO Data Dictionary and the RESO Web API and to stay current within one year of each ratification, demonstrated through the RESO Certification Process. NAR imposes the standard; it does not implement it. - id: reso-data-dictionary conforms: false evidence: >- No Data Dictionary field names appear in the M1 definitions; M1 models membership records, which the Data Dictionary does not cover. relationship: mandator - id: json-api conforms: false evidence: Plain JSON resource representations; no JSON:API document structure. - id: pagination conforms: false evidence: No page/offset/limit/cursor parameter appears in any of the 88 operations. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header is documented; duplicate-create protection is delegated to pre-flight CheckDuplicateMember / CheckDuplicateEmail lookups. - id: rate-limit-headers conforms: partial evidence: >- X-Rate-Limit-Limit / -Remaining / -Reset are emitted live (AspNetCoreRateLimit convention), but not the IETF draft RateLimit-* header fields, and the limits are undocumented. compliance_program: published: false note: >- NAR publishes no trust center, no SOC 2 / ISO 27001 / PCI attestation and no security-compliance page for the M1 Gateway. Probes for trust.nar.realtor, /trust, /security and /compliance found no certification claims.