generated: '2026-08-13' method: derived source: >- derived from the published Pabbly API guides at apidocs.pabbly.com, the security page at www.pabbly.com/security/, and npm @pabbly/connect-platform@1.0.0 provider: Pabbly providerId: pabbly standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document is published. Every candidate path on the docs host (/openapi.json, /openapi.yaml, /swagger.json, /spec.json, per-product variants) returns the Next.js SPA HTML shell with Content-Type text/html; /api/v1/openapi.json on the API hosts returns 401/404 JSON. The reference is prose + markdown only. - id: asyncapi conforms: false evidence: >- Webhooks are documented in prose (23 event types on Subscription Billing); no AsyncAPI document is published. - id: graphql conforms: false evidence: No /graphql surface is documented or advertised on any host. - id: grpc conforms: false - id: json-api conforms: false evidence: Bespoke {status,message,data} / {success,error} envelopes. - id: rfc9457-problem-details conforms: false evidence: >- Errors are '{"success": false, "error": ""}'; no application/problem+json anywhere. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt 404s on every host, even though a vulnerability disclosure program is published at https://www.pabbly.com/security-vulnerability-disclosure/. - id: rfc7617-http-basic conforms: true evidence: >- Subscription Billing, Hook and Email Verification use 'Authorization: Basic '. - id: rfc6750-bearer-token conforms: true evidence: >- Chatflow, Email Marketing and Connect Platform use 'Authorization: Bearer '. Note the token is a long-lived API key, not an OAuth 2.0 access token. - id: oauth2 conforms: false evidence: >- No OAuth 2.0 flow is offered on Pabbly's own APIs; /.well-known/oauth-authorization-server 404s on every host. Pabbly Connect Platform brokers OAuth to THIRD-PARTY apps on a tenant's behalf (hosted connect links + token vending), which is an OAuth client role, not an OAuth authorization server. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on every host. - id: mcp conforms: true evidence: >- Pabbly Connect ships a hosted MCP server (beta) plus a first-party stdio bridge on npm (pabbly-mcp-remote, which depends on @modelcontextprotocol/sdk 1.8.0). See mcp/pabbly-mcp.yml. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json 404 (or return an SPA HTML shell) on all 11 probed hosts. - id: llms-txt conforms: true evidence: >- https://apidocs.pabbly.com/llms.txt (index) plus five per-product llms.txt documents, and a second llms.txt on the commerce host https://buy.pabbly.com/llms.txt. - id: markdown-content-negotiation conforms: true evidence: >- Accept: text/markdown on a canonical docs URL returns 200 text/markdown; buy.pabbly.com additionally serves /content/*.md twins of its pages. - id: idempotency conforms: false evidence: >- No idempotency key or replay-safety mechanism on any of the 173 documented operations, including create-subscription and record-payment. - id: pagination conforms: false evidence: >- No pagination contract published for the documented list operations; only Connect Platform (SDK-documented) takes page/limit. - id: iso-27001 conforms: true evidence: >- "ISO 27001:2022 Certified" published at https://www.pabbly.com/security/ (self-asserted; no certificate number or body named). - id: soc2-type2 conforms: true evidence: >- "SOC2 Type 2 Compliant" published at https://www.pabbly.com/security/ (self-asserted; no report or auditor named). - id: pci-dss conforms: false evidence: >- Not claimed. Pabbly states it stores no card data and delegates card handling to the payment gateways it integrates with. - id: gdpr conforms: unknown evidence: >- No GDPR page (https://www.pabbly.com/gdpr/ returns 404); the privacy policy is the only published data-protection document. maintainers: - FN: Kin Lane email: kin@apievangelist.com