generated: '2026-07-20' method: derived source: openapi/onecli-openapi-original.yml standards: - id: oauth2 conforms: false evidence: >- The OneCLI management API authenticates with an http bearer API key, not OAuth2. OAuth is used only by the gateway to connect downstream apps. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: >- Errors use two custom envelope shapes (a flat `error` string, or `{error:{message,type}}`), not application/problem+json. - id: json-api conforms: false - id: bearer-token-auth conforms: true evidence: openapi securitySchemes bearerAuth (http, scheme bearer) - id: openapi-3.1 conforms: true evidence: openapi 3.1.0 document published at https://onecli.sh/docs/openapi.yaml - id: uri-path-versioning conforms: true evidence: base path /v1 on all servers notes: - No published compliance program (SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP) was found; no trust center is published. No Compliance pointer is emitted.