generated: '2026-08-13' method: derived source: openapi/_original/nimble-openapi-original.yml docs: https://www.nimble.com/developers/docs/ notes: >- Cross-cutting standards conformance derived from the OpenAPI Nimble publishes plus its narrative Authentication and Handling Errors references. No published compliance program (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) could be verified from any Nimble surface, so no Compliance pointer is emitted from this file — see the compliance block below for what was probed. standards: - id: openapi-3.0 conforms: true evidence: >- Nimble publishes an OpenAPI 3.0.0 document (58 paths, 89 operations, 180 component schemas, 14 tags) embedded as the Redoc state of https://www.nimble.com/developers/docs/. - id: oauth2 conforms: true evidence: >- RFC 6749 authorization_code grant with refresh_token, documented with authorize (https://app.nimble.com/oauth/authorize) and token (https://app.nimble.com/api/oauth/token) endpoints, client_secret_post client authentication and form-encoded token requests. Implicit flow is explicitly not supported. - id: rfc6750-bearer-token conforms: true evidence: >- Access tokens are presented as Authorization: Bearer ; the docs cite RFC 6750 directly. - id: rfc8414-oauth-metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns 404 on every Nimble host. OAuth endpoints are documented in prose only and cannot be discovered programmatically. - id: oidc conforms: false evidence: >- No /.well-known/openid-configuration (404 on all hosts); no id_token in the documented token response. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a vendor envelope {message, code} with application/json, not application/problem+json. See errors/nimble-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all four Nimble hosts. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header support and no deprecation policy is published. See lifecycle/nimble-lifecycle.yml. - id: ietf-ratelimit-headers conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers and no 429 response anywhere in the spec. See rate-limits/nimble-rate-limits.yml. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header or equivalent in any of the 89 operations. - id: json-api conforms: false evidence: >- Responses use a Nimble-specific {meta, resources} envelope, not the JSON:API {data, included} media type. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on every Nimble host. - id: mcp conforms: false evidence: >- No MCP server; tools/list returns 404 on every candidate host. See mcp/nimble-mcp.yml. - id: llms-txt conforms: true evidence: >- https://www.nimble.com/llms.txt returns 200 with a well-formed llms.txt (H1, blockquote summary, sectioned link lists) plus a linked llms-full.txt. Captured at llms/nimble-llms.txt. - id: rest conforms: true evidence: >- Resource-oriented paths with conventional GET/POST/PUT/DELETE method semantics across contacts, deals, pipelines and fields. - id: scim2 conforms: false evidence: No /scim/v2 paths or SCIM schemas in the spec. - id: odata conforms: false evidence: No OData query conventions ($filter/$select/$expand) in the spec. compliance: published: false certifications: [] probed: - url: https://trust.nimble.com/ status: 200 finding: >- Resolves and returns 200 but renders client-side — the served HTML body contains only the word "Nimble" and no certification names, no document list and no trust-platform markup (no SafeBase/Vanta/Drata embed detected). Nothing machine-readable to record. - url: https://www.nimble.com/security/ status: 404 finding: No security/compliance landing page at the conventional path. note: >- Because no certification could be read from any Nimble surface, neither a Compliance nor a TrustCenter pointer is emitted. The automated probe-security-programs pass also returned vdp=none trust=none. This is a recorded gap, and the single cheapest thing Nimble could fix: the trust subdomain exists but serves nothing a machine can read.