generated: '2026-08-13' method: searched source: >- https://api-docs.omnisend.com/reference/responses, https://api-docs.omnisend.com/reference/oauth, https://mcp.omnisend.com/.well-known/oauth-authorization-server, https://mcp.omnisend.com/.well-known/oauth-protected-resource, https://www.omnisend.com/.well-known/security.txt, https://api-docs.omnisend.com/reference/mcp-server-v2, and the harvested openapi/omnisend-*-openapi.yml contracts description: >- Cross-cutting standards Omnisend does and does not conform to, each with the evidence that decided it. Omnisend is unusually strong on the modern agent/auth stack (RFC 9457, RFC 8414, RFC 9728, MCP, PKCE) and notably absent on the transactional-safety and compliance-publication side. standards: - id: rfc9457 name: Problem Details for HTTP APIs conforms: true evidence: >- "All error responses follow RFC 9457" on the Responses reference page, and three Problem schemas (Problem, ValidationProblem, RateLimitProblem) with type/title/status/detail/instance are present in all 15 harvested OpenAPI contracts. artifact: errors/omnisend-problem-types.yml - id: oauth2 name: OAuth 2.0 (RFC 6749) authorization code grant conforms: true evidence: >- https://api-docs.omnisend.com/reference/oauth documents the authorization code flow; authorization_endpoint https://app.omnisend.com/oauth2/authorize, token_endpoint https://app.omnisend.com/oauth2/token. Declared grant types authorization_code + refresh_token. caveat: >- Access tokens are documented as never expiring unless revoked (expires_in 9223372036), and client credentials are issued by hand after a Google Form request — not self-serve. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: 'https://mcp.omnisend.com/.well-known/oauth-authorization-server returns 200 JSON with issuer, endpoints, 26 scopes_supported and code_challenge_methods_supported.' artifact: well-known/omnisend-mcp-oauth-authorization-server.json - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://mcp.omnisend.com/.well-known/oauth-protected-resource returns 200 JSON, and the MCP endpoint's 401 challenge carries WWW-Authenticate: Bearer resource_metadata="...". artifact: well-known/omnisend-mcp-oauth-protected-resource.json - id: rfc7636 name: PKCE conforms: true evidence: 'code_challenge_methods_supported: ["S256"] in the authorization server metadata.' - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: 'registration_endpoint https://app.omnisend.com/oauth2/register declared in the RFC 8414 metadata.' caveat: Advertised for the MCP surface; the human OAuth docs still route app developers through a manual credential request form. - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: true evidence: 'revocation_endpoint https://app.omnisend.com/oauth2/revoke declared in the RFC 8414 metadata.' - id: mcp name: Model Context Protocol conforms: true evidence: >- Two first-party hosted servers — https://mcp.omnisend.com/mcp (4 tools) and https://mcp.omnisend.com/v2/mcp (7 tools) — documented with Claude/ChatGPT/Cursor setup, and probed live returning a spec-shaped 401 OAuth challenge. artifact: mcp/omnisend-mcp.yml - id: rfc9116 name: security.txt conforms: true evidence: 'https://www.omnisend.com/.well-known/security.txt returns 200 with Contact and Policy fields.' caveat: Minimal — no Expires field, which RFC 9116 requires; no Encryption, Canonical or Preferred-Languages. artifact: well-known/omnisend-security.txt - id: pagination name: Consistent cursor pagination conforms: true evidence: 'Documented at https://api-docs.omnisend.com/reference/pagination — opaque after/before cursors, paging.hasMore, limit max 250, applied across every list endpoint.' - id: openapi name: OpenAPI conforms: true version: 3.0.0 evidence: 15 machine-readable OpenAPI 3.0.0 documents published through the documentation host and harvested into openapi/. caveat: >- Only the Event Metadata API declares operationId. 79 of 82 operations have no operationId, no tags and no declared top-level security, which limits tooling and code generation. - id: idempotency name: Idempotency keys for unsafe methods conforms: false evidence: >- No Idempotency-Key or equivalent header in any of the 15 harvested contracts and no mention in the documentation. POST /contacts is an upsert and DELETE /automations/{id} is documented as idempotent, but neither is a retry-safety key. - id: rfc8594 name: Sunset HTTP header conforms: false evidence: >- No Sunset or Deprecation header is emitted. Version retirement is announced only in-band as HTTP 410 with an RFC 9457 body, after the fact. - id: ratelimit-headers name: RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: >- No X-RateLimit-* / RateLimit-* / Retry-After header is documented. 429 carries a retryAfter integer inside the RFC 9457 body on some endpoints only. - id: oidc name: OpenID Connect conforms: false evidence: '/.well-known/openid-configuration 404s on www.omnisend.com and returns an SPA HTML shell on app.omnisend.com. Omnisend is an OAuth 2.0 provider, not an OIDC provider.' - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document published. Omnisend has a real outbound event surface (the sendWebhook automation action block) but describes it only in prose — see asyncapi/omnisend-webhooks.yml. - id: a2a name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json probed on 5 hosts — 404 on api.omnisend.com and api-docs.omnisend.com, HTML SPA shells (not cards) on www/app/mcp.' - id: json-api name: 'JSON:API' conforms: false evidence: Responses are plain JSON with a resource-named array plus a paging object; no JSON:API document structure. - id: rfc9727 name: api-catalog well-known URI conforms: false evidence: '/.well-known/api-catalog 404s or returns an HTML shell on every Omnisend host probed.' compliance: published_certifications: [] trust_center: false note: >- NO named certification is published anywhere Omnisend serves publicly. trust.omnisend.com, security.omnisend.com, /compliance, /security and /gdpr all fail to resolve or 404; https://www.omnisend.com/trust redirects to an unrelated marketing page (/trusted-by-cloudways/). The site footer offers a Data Processing Agreement, Terms of Use, Privacy Policy, Acceptable Use Policy and a Modern Slavery Statement — legal documents, not an audited compliance posture. Omnisend's product marketing references TCPA- and GDPR-compliant opt-in forms, which is a feature claim about the customer's sending, not a certification of Omnisend. No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim was found. Because nothing is published, no Compliance or TrustCenter pointer is emitted for this provider. security_program: bug_bounty: true url: https://www.omnisend.com/bug-bounty/ contact: mailto:security@omnisend.com scope: [app.omnisend.com, omnisend.com, api.omnisend.com, appmarket.omnisend.com, partners.omnisend.com, 'WordPress plugins'] out_of_scope: [phishing, social engineering, denial of service] note: WordPress plugin vulnerabilities are routed to Patchstack rather than to Omnisend. artifact: security/omnisend-vulnerability-disclosure.yml summary: conforms: 12 does_not_conform: 8 strongest: OAuth/MCP discovery stack — RFC 8414 + RFC 9728 + PKCE + dynamic registration, all live and anonymous weakest: No idempotency, no rate-limit headers, no Sunset header, and no published certification of any kind