generated: '2026-08-12' method: derived source: >- errors/optinmonster-problem-types.yml ; authentication/optinmonster-authentication.yml ; conventions/optinmonster-conventions.yml ; well-known/optinmonster-well-known.yml ; security/optinmonster-domain-security.yml ; https://optinmonster.com/gdpr/ ; https://optinmonster.com/privacy/ note: >- Cross-cutting standards assertions for the OptinMonster API surface. Every `conforms: false` below is a checked negative with the evidence that established it, not an assumption. No `Compliance` pointer is emitted in apis.yml: OptinMonster publishes GDPR/CCPA process pages and a DPA, but no audited certification (SOC 2, ISO 27001, PCI DSS, HIPAA) is named anywhere on its site, and a self-described privacy process is not a published compliance attestation. standards: - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization or token endpoint on any host; /.well-known/oauth-authorization-server returns 404 on optinmonster.com and a non-document 301 on the API hosts. Authentication is a static account API key in the X-OptinMonster-ApiKey header. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returns 404 / non-document 301 on every host probed. - id: rfc9457 name: 'RFC 9457 — Problem Details for HTTP APIs' conforms: false evidence: >- Errors use a vendor envelope {error, code, message, status} served as application/json. No application/problem+json media type, no `type` URI, no `title`/`detail`/`instance` members. The envelope is consistent and machine-parseable, but it is not the standard one. - id: rfc9116 name: 'RFC 9116 — security.txt' conforms: false evidence: >- No /.well-known/security.txt on optinmonster.com (404), api.optinmonster.com, app.optinmonster.com or api.omwpapi.com (301 to a non-document). A security contact is published, but on an HTML page. - id: rfc8594 name: 'RFC 8594 — Sunset HTTP header' conforms: false evidence: No Sunset or Deprecation header observed on any response; no deprecation policy exists. - id: rfc9110-ratelimit name: RateLimit header fields conforms: false evidence: >- No RateLimit-*, X-RateLimit-* or Retry-After header on any observed response, and no documented limits. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document at any probed location on api.optinmonster.com, api.omwpapi.com, or the docs host — /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /v2/openapi.json, /api-docs, /docs, /redoc all miss. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document. One webhook event is documented in prose only. See asyncapi/optinmonster-webhooks.yml. - id: graphql name: GraphQL conforms: false evidence: /graphql on api.optinmonster.com returns a non-document 301; no GraphQL surface exists. - id: mcp name: Model Context Protocol conforms: false evidence: >- No hosted MCP server. /mcp on the API host returns a non-document 301, and no OptinMonster MCP server is published in any registry. - id: a2a name: 'A2A Agent Card' conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on optinmonster.com (404) and api/app/omwpapi hosts (301 to an HTML "Invalid .well-known request" body). No card served. - id: api-catalog name: 'RFC 9727 — /.well-known/api-catalog' conforms: false evidence: 404 on optinmonster.com; non-document 301 on the API hosts. - id: llmstxt name: llms.txt conforms: true evidence: >- https://optinmonster.com/llms.txt returns 200 with a 453 KB llms.txt-format document (1,883 linked entries), generated by All in One SEO Pro v4.9.3. note: >- Present and well-formed, but it is an SEO plugin's index of marketing and help-centre pages. It contains no API reference, no endpoint list, and no spec link — so it serves discovery of the website, not of the API. - id: webhooks name: Webhook event delivery conforms: partial evidence: >- One documented outbound webhook with a stable JSON payload and an X-OptinMonster-Webhook-Version header. No authentication, no signature, no retry policy, no subscription API. - id: pagination name: Documented pagination conforms: false evidence: >- No pagination contract published. The one anonymous collection returns 697 objects as an unpaginated bare array. - id: idempotency name: Idempotent write semantics conforms: false evidence: >- No idempotency key header in the docs, in the first-party client, or in the CORS allow-headers list. - id: cors name: CORS conforms: true evidence: >- access-control-allow-origin *, allow-methods GET/HEAD/OPTIONS/POST/PUT/DELETE, and an explicit allow-headers list, returned on an OPTIONS preflight to /v2/campaigns (200). - id: tls name: TLS 1.2+ everywhere conforms: true evidence: >- TLSv1.3 on optinmonster.com and api.optinmonster.com. See security/optinmonster-domain-security.yml. - id: hsts name: HTTP Strict Transport Security conforms: partial evidence: >- HSTS present on optinmonster.com (max-age 31536000) but ABSENT on api.optinmonster.com — the API host itself does not send HSTS. - id: dnssec name: DNSSEC conforms: false evidence: 'optinmonster.com: dnssec false.' - id: caa name: CAA records conforms: false evidence: 'optinmonster.com: no CAA records published.' - id: spf name: SPF conforms: true evidence: SPF record present on optinmonster.com. - id: dmarc name: DMARC conforms: true evidence: DMARC present on optinmonster.com with policy `reject`. - id: gdpr name: GDPR conforms: claimed evidence: >- Dedicated GDPR page at https://optinmonster.com/gdpr/ (200) describing data-processing commitments and a DPA. The product also carries a `privacyConsent` field through the lead payload and offers consent-capture campaign fields. note: Self-described process. Not an audited certification. - id: ccpa name: CCPA conforms: claimed evidence: Referenced in the privacy policy at https://optinmonster.com/privacy/. - id: soc2 name: SOC 2 conforms: false evidence: Not named on the security page, the GDPR page, or anywhere on the site. No trust center. - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: Not named anywhere on the site. - id: pci-dss name: PCI DSS conforms: false evidence: >- Not named. OptinMonster does not process cardholder data through this API — it is a lead-capture platform. - id: hipaa name: HIPAA conforms: false evidence: Not named; no BAA offered. counts: asserted: 27 conforms_true: 6 conforms_partial: 3 conforms_claimed: 2 conforms_false: 16 certifications_named: []