generated: '2026-07-28' method: derived source: openapi/*.json + json-schema/*.json + well-known/ + https://opentravel.org/openapi-initiative-cooperation/ note: >- OpenTravel is itself a standards body, so the interesting question is which OTHER cross-cutting standards its published artifacts conform to. It publishes no certification, no conformance test suite and no certified-implementer registry — the closest thing is a self-nominated adopter directory. Nothing below is a claim by OpenTravel; each entry is evidenced from the artifacts or from a page on opentravel.org. standards: - id: swagger-2.0 conforms: true evidence: >- All eight harvested documents declare "swagger": "2.0" and parse. Generated by the OTM compiler 4.0-SNAPSHOT between 2018-04-05 and 2020-05-15. - id: openapi-3.x conforms: false evidence: >- No OpenAPI 3.x document is published anywhere in the corpus or on the site, despite the /openapi/ and /openapi-arazzo-specification/ advocacy pages describing OAS 3.1. - id: json-schema-draft-04 conforms: true evidence: >- All seven harvested model modules declare "$schema": "http://json-schema.org/draft-04/schema#" (163 definitions total). sources: [json-schema/] - id: xml-schema-1.0 conforms: true evidence: >- 10,848 .xsd files in the public mirror; every Swagger operation carries an `x-xml-schema` $ref beside its JSON $ref. - id: oauth2 conforms: true evidence: >- opentravel.org publishes RFC 8414 authorization-server metadata with authorization_code + refresh_token grants. scope: opentravel.org MCP surface only — not the OpenTravel specification - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://opentravel.org/.well-known/oauth-authorization-server returns 200 application/json - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://opentravel.org/.well-known/oauth-protected-resource returns 200 application/json - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] in the authorization-server metadata - id: model-context-protocol conforms: true evidence: >- Two MCP servers mounted at /wp-json/mcp/; both return a JSON-RPC-shaped 401 with a WWW-Authenticate Bearer challenge pointing at the protected-resource metadata. caveat: tools/list is OAuth-gated, so protocol version and tool surface are unverified - id: openid-connect conforms: false evidence: /.well-known/openid-configuration is a WordPress soft 404 (HTML, not JSON) - id: rfc9457-problem-details conforms: false evidence: >- No operation declares application/problem+json; errors reuse the model payload media types. See errors/opentravel-alliance-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns nginx 404 on both opentravel.org and opentravelmodel.net - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog is a WordPress soft 404 - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header contract is published; no operation is marked deprecated - id: asyncapi conforms: false evidence: >- No AsyncAPI document exists. The only event-shaped surface is the HotelDescriptiveContentResource `Notification` operation — see asyncapi/opentravel-alliance-notifications-webhooks.yml - id: arazzo conforms: false evidence: >- OpenTravel publicly advocates the Arazzo Specification at https://opentravel.org/openapi-arazzo-specification/ and links to the OAI repository, but publishes no Arazzo workflow of its own. - id: iata-ndc conforms: false evidence: >- OpenTravel is a peer of IATA, not an NDC participant. No NDC certification level is claimed anywhere on the site. - id: iata-codes conforms: true evidence: >- cityCode is documented as "the three character IATA city code"; the OpenTravel Code Lists curate IATA airline/location codes. - id: iso-4217-currency conforms: true evidence: >- displayCurrency documented as "a 3 char currency code as defined in ISO 4127" [sic — the spec text misprints ISO 4217] with pattern [a-zA-Z]{3}. - id: tti-hotel-codes conforms: true evidence: hotelCode_TTI query parameter — "TTI hotel reference code" certifications: published: none detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR posture is published, and probe-security-programs.py found no trust center and no vulnerability-disclosure programme on 2026-07-28. OpenTravel is a volunteer non-profit holding no customer data. registry: >- https://opentravel.org/opentravel-message-adopters-integrators/ is a self-nominated adopter directory with no levels, dates or verification — it is not a certification.