generated: '2026-08-13' method: searched source: >- https://api.ontraport.com/doc/, https://ontraport.com/support/My-account/mcp-server, https://ontraport.com/features/platform/security-and-scalability/, https://ontraport.com/legal, live probes of https://mcp.ontraport.com/.well-known/oauth-protected-resource and https://app.ontraport.com/.well-known/oauth-authorization-server, plus openapi/ontraport-objects-api-openapi.yml and openapi/ontraport-metadata-api-openapi.yml description: >- What Ontraport actually conforms to, standard by standard, with evidence for each verdict. The shape of the answer: Ontraport is strong on the newest agent-facing standards (MCP, OAuth 2.1 with PKCE, RFC 9728/8414 discovery metadata — all live and probeable) and weak on the long-established REST ones (no RFC 9457 errors, no RFC 8594 deprecation headers, no standard RateLimit-* headers, no OpenAPI published by the provider). The MCP server is a 2026 build; the REST API is a 2017 design that has not been modernised. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- First-party remote MCP server at https://mcp.ontraport.com, documented by the provider at https://ontraport.com/support/My-account/mcp-server. An unauthenticated tools/list POST returns HTTP 401 with a correct RFC 9728 Bearer challenge rather than a 404 or an HTML shell — the server is real and reachable. 47 tools published across four categories. transport: streamable-http gated: true - id: oauth2 name: OAuth 2.0 / 2.1 authorization code with PKCE conforms: true scope: mcp surface only evidence: >- https://app.ontraport.com/.well-known/oauth-authorization-server returns HTTP 200 with authorization_code + refresh_token grants, code_challenge_methods_supported ["S256"], a registration endpoint and a revocation endpoint. The REST API has no OAuth. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://mcp.ontraport.com/.well-known/oauth-protected-resource returns HTTP 200 with resource, authorization_servers, scopes_supported and bearer_methods_supported. The same URL is advertised in the WWW-Authenticate header of a 401. file: well-known/ontraport-oauth-protected-resource.json - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- https://app.ontraport.com/.well-known/oauth-authorization-server returns HTTP 200 with a complete metadata document including dynamic client registration support. file: well-known/ontraport-oauth-authorization-server.json - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: >- registration_endpoint https://app.ontraport.com/oauth/register published in the authorization-server metadata, with client_id_metadata_document_supported true. - id: oidc name: OpenID Connect conforms: false evidence: >- /.well-known/openid-configuration returns 404 on ontraport.com, app.ontraport.com and mcp.ontraport.com. OAuth only, no ID tokens. - id: openapi name: OpenAPI Specification conforms: false evidence: >- Ontraport publishes no OpenAPI. Probed /openapi.json, /openapi.yaml, /swagger.json, /api-docs and /1/openapi.json on api.ontraport.com (502 or 401) and /openapi.json on ontraport.com (404). The reference at https://api.ontraport.com/doc/ is a server-rendered HTML page, readable but not machine-consumable. The specs in openapi/ are API Evangelist derivations of the generic object interface, not provider artifacts. - id: asyncapi name: AsyncAPI conforms: false evidence: >- A real webhook surface exists (4 events, subscribe/unsubscribe via the API, a Webhook Log object) but no AsyncAPI or event-schema document is published. Captured as a webhook catalog in asyncapi/ontraport-webhooks.yml. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors use a custom application/json envelope {code, data, account_id} with no type URI and no machine-readable error slug. Documented at https://api.ontraport.com/doc/#error-and-response-codes. - id: rfc8594 name: Sunset HTTP Header / deprecation signalling conforms: false evidence: >- No Sunset or Deprecation header. Deprecations are announced as dated prose entries in the change log, and at least two announced deprecations (num_purchased, group_ids) remain in service with no removal date. - id: ratelimit-headers name: IETF RateLimit header fields conforms: false partial: true evidence: >- Ontraport DOES publish rate-limit headers, which most providers do not — but under the legacy X-Rate-Limit-Limit / X-Rate-Limit-Remaining / X-Rate-Limit-Reset names rather than the RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset form. No Retry-After on 429. - id: pagination name: Consistent pagination conforms: true style: offset evidence: >- start/range on every plural endpoint, default and maximum page size 50, count available via GET /objects/getInfo and since 2025-08-28 via a `count` parameter. Documented at https://api.ontraport.com/doc/#pagination. Calendar events are a documented exception that pages by moving the start timestamp instead. caveat: >- Offset-only, no cursor, and unpaginated collection reads silently truncate at 50 rather than erroring. - id: idempotency name: Idempotent writes conforms: true partial: true evidence: >- No Idempotency-Key header. Repeat-safety is provided by an upsert operation, POST /objects/saveorupdate, which matches on a unique field and updates instead of duplicating; Ontraport names it "the recommended way to add records because it prevents duplicates" on both the REST and MCP surfaces, and the MCP server exposes it as saveorupdate_object. Plain creates and all commerce writes have no idempotency mechanism. see: conventions/ontraport-conventions.yml - id: rest name: REST / resource-oriented design conforms: false partial: true evidence: >- A generic object interface where the resource is chosen by an objectID parameter rather than by a path, with named aliases layered on top. HTTP verbs are used conventionally (GET/POST/PUT/DELETE on /objects) but the resource model is RPC-flavoured, and a `code` field inside a 200 body duplicates the status line. - id: json-schema name: JSON Schema conforms: false evidence: >- No published schemas. Field discovery is a runtime call (GET /objects/meta), which is a reasonable design for a platform with per-account custom fields but means no static contract exists for any object. - id: webhooks name: Outbound webhooks conforms: true partial: true evidence: >- Four events, API-managed subscriptions, a queryable delivery log. No signature, shared secret or replay protection is documented, and no retry policy is published. see: asyncapi/ontraport-webhooks.yml - id: pci-dss name: PCI DSS conforms: true level: Level 1 evidence: >- "Ontraport meets the highest level of security – PCI-DSS Level 1 Certification" at https://ontraport.com/features/platform/security-and-scalability/, repeated as a "PCI DSS, Level 1" badge in the site footer. Self-asserted on the provider's own site; no AOC, QSA name or attestation date is published. attestation_document: not published - id: gdpr name: GDPR conforms: true role: data processor evidence: >- https://ontraport.com/legal carries a GDPR section stating Ontraport "attests that we comply with GDPR as a Data Processor but does not and can not ensure your compliance as a Data Controller", and commits to maintaining a published sub-processor list. - id: soc2 name: SOC 2 conforms: false evidence: >- No SOC 2 claim on the security page, the legal page or anywhere else on the site. No trust portal exists. - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: No ISO 27001 claim published. - id: hipaa name: HIPAA conforms: false evidence: >- No BAA offer or HIPAA claim published, despite a Health and wellness industry landing page. - id: fedramp name: FedRAMP conforms: false evidence: No FedRAMP claim published, despite a Public sector industry landing page. - id: security-txt name: RFC 9116 security.txt conforms: false evidence: >- 404 on ontraport.com/.well-known/security.txt, ontraport.com/security.txt and mcp.ontraport.com/.well-known/security.txt; 502 on api.ontraport.com. No vulnerability disclosure policy or security contact is published anywhere on the site. - id: a2a name: A2A Agent Card conforms: false evidence: >- 404 on /.well-known/agent-card.json and /.well-known/agent.json across ontraport.com, api.ontraport.com (502) and mcp.ontraport.com. No agent card is served. - id: llms-txt name: llms.txt conforms: false evidence: >- 404 on ontraport.com/llms.txt, support.ontraport.com/llms.txt and mcp.ontraport.com/llms.txt; 502 on api.ontraport.com/llms.txt. - id: dnssec name: DNSSEC conforms: false evidence: security/ontraport-domain-security.yml — dnssec false, no CAA records. - id: hsts name: HTTP Strict Transport Security conforms: false evidence: >- security/ontraport-domain-security.yml — hsts false on both ontraport.com and api.ontraport.com, despite TLS 1.3 on both. summary: conformant: 10 non_conformant: 14 headline: >- Ontraport's agent surface conforms to more current standards than its REST surface does to older ones. Every OAuth/MCP discovery document a 2026 agent looks for is present and returns 200; every classic REST hygiene standard — OpenAPI, RFC 9457, RFC 8594, RateLimit-*, security.txt — is absent.