generated: '2026-08-27' method: searched source: - https://www.osha.gov/sites/default/files/ita/documentation/osha_injury-tracking-application-api-documentation-v1.pdf - https://usdepartmentoflabor.github.io/Developer/health-and-safety/dol-osha-enforcement/ - live probes 2026-08-27 note: >- Cross-cutting standards assessed against what OSHA's own published contracts and documentation actually declare. Reward-only: an absent standard is recorded as conforms:false with the reason, never inferred from marketing copy. standards: - id: oauth2 conforms: false evidence: No oauth2 scheme on any surface; ITA uses a static bearer token, DOL uses a static API key. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 (www.osha.gov) or an SPA shell (data.dol.gov). - id: rfc6750-bearer-token conforms: true evidence: 'ITA API documents `Authorization: Bearer [ITA API Token]` on every call.' - id: rfc9457-problem-details conforms: false evidence: Responses use a custom {success, errors[]} envelope; no application/problem+json anywhere. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 403 on www.osha.gov and an SPA shell on data.dol.gov. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation headers; the enforcedata.dol.gov retirement was announced in site copy only. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger anywhere. Probed /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs and /api/v1 on www.osha.gov, data.dol.gov, dataportal.dol.gov and api.dol.gov — 404 on the OSHA host, SPA catch-all 200 on the DOL hosts. The contract is a PDF. - id: graphql conforms: false evidence: No /graphql surface on any host. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published on either API. - id: pagination conforms: true evidence: 'DOL enforcement API documents limit/offset path segments; default 100 records, max 200 per request.' - id: idempotency conforms: false evidence: No idempotency key or replay semantics on any endpoint (see conventions/osha-conventions.yml). - id: hateoas conforms: true evidence: ITA responses carry a `links` array with self / establishment / form300ALinks / submissions cross-references. - id: json-api conforms: false evidence: Custom envelope, not the JSON:API media type or document structure. - id: odata conforms: partial evidence: >- The legacy DOL producer at api.dol.gov/V1 is described by the DOL developer portal as an OData producer with XML by default. It is not the surface OSHA enforcement data is documented against today (data.dol.gov/get/ is), and it answers 403 MissingAuthenticationToken to anonymous callers, so conformance cannot be verified. - id: fedramp conforms: false evidence: No FedRAMP authorization is published for either API surface; no trust center exists. - id: dcat-us conforms: unverified evidence: >- DOL maintains a Project Open Data / DCAT-US catalog (the USDepartmentofLabor/public-data-listing repo publishes data.json per DOL organization, which would include OSHA). www.dol.gov/data.json returned HTTP 403 to every non-browser client we tried and www.osha.gov/data.json is 404, so we could not fetch and verify the OSHA slice. Recorded as unverified rather than claimed. - id: ckan conforms: unverified evidence: 'catalog.data.gov CKAN API (/api/3/action/package_search) returned HTTP 404 from this run; OSHA datasets are listed on catalog.data.gov via its web UI.' domain_standards: note: >- OSHA's domain standard is one OSHA itself writes. The ITA API is the machine surface for 29 CFR Part 1904 recordkeeping, and its request bodies are field-for-field the OSHA paper forms — the contract declares the standard in its own data dictionary, not in prose. standards: - id: osha-form-300a name: 'OSHA Form 300A — Summary of Work-Related Injuries and Illnesses' conforms: true evidence: >- The ITA API's 300A data dictionary is keyed to the form's own field letters: fields G-J (number of cases), H (cases with days away), I (cases with job transfer/restriction), K (days away from work), L (days of job transfer/restriction) and M1-M6 (injury and illness types), with the cross-field validations enforced server-side. spec_location: 'ITA API documentation, "Data Dictionary: 300A Summary fields" and "Additional Data Validations"' endpoint: https://www.osha.gov/oshaApi/v1/forms/form300A - id: osha-form-300-301 name: 'OSHA Forms 300 and 301 — Log and Incident Report (case data)' conforms: true evidence: A dedicated case-data endpoint carries per-case Form 300/301 records with its own published field specification. spec_location: https://www.osha.gov/sites/default/files/ita_case_data_api_specifications.pdf endpoint: https://www.osha.gov/oshaApi/v1/forms/caseData - id: cfr-29-1904 name: 29 CFR Part 1904 — Recording and Reporting Occupational Injuries and Illnesses conforms: true evidence: >- The ITA API exists to satisfy 1904.41 electronic submission. Establishment status, year_filing_for and the submission/re-submission model are regulatory constructs, not API design choices. spec_location: https://www.osha.gov/laws-regs/regulations/standardnumber/1904 - id: naics name: NAICS industry classification conforms: true evidence: >- NAICS is the join key across both surfaces — the establishment record carries the establishment's NAICS code, and the DOL enforcement API exposes NAICS search over inspections. compliance_program: published: false note: >- OSHA publishes no certifications, SOC 2 / ISO 27001 report, trust center or vulnerability disclosure policy for these APIs. As a federal agency its obligations run through FISMA and CISA BOD 20-01, but neither is asserted at any URL we could fetch (probed /vulnerability-disclosure-policy on www.osha.gov -> 404). No Compliance pointer is emitted. x-evidence: - {url: 'https://www.osha.gov/oshaApi/v1/establishments', status: 403, fetched: '2026-08-27'} - {url: 'https://api.dol.gov/V1/DOLAgency/Agencies?KEY=test', status: 403, fetched: '2026-08-27'} - {url: 'https://www.osha.gov/openapi.json', status: 404, fetched: '2026-08-27'} - {url: 'https://www.dol.gov/data.json', status: 403, fetched: '2026-08-27'} - {url: 'https://catalog.data.gov/api/3/action/package_search?q=osha&rows=1', status: 404, fetched: '2026-08-27'} - {url: 'https://www.osha.gov/vulnerability-disclosure-policy', status: 404, fetched: '2026-08-27'}