generated: '2026-08-12' method: derived source: >- Derived from authentication/peer39-authentication.yml, conventions/peer39-conventions.yml, errors/peer39-problem-types.yml and well-known/peer39-well-known.yml, all of which were built from the published Peer39 MCP server source and live probes on 2026-08-12. No compliance or conformance claim is published on any Peer39 host. api: Peer39 External API standards: - id: oauth2 conforms: false evidence: >- Authentication is username + password exchanged at POST /api/external/login for a short-lived sessionId carried as a bearer token. No authorization endpoint, no token grant types, no scopes, no client registration. Not OAuth 2.0. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration 404s on www.peer39.com and returns the SPA HTML shell on app.peer39.com. No id_token, no OIDC discovery. - id: rfc9457 conforms: false evidence: >- Errors are a proprietary {value, code, description, message} envelope returned with HTTP 200, not application/problem+json. A non-zero `code` on a 200 response is the error signal. - id: rfc7807 conforms: false evidence: Same as rfc9457 — no problem+json media type is emitted. - id: rfc9116 name: security.txt conforms: false evidence: >- /.well-known/security.txt returns 404 on www.peer39.com and the SPA HTML shell on app.peer39.com. No security.txt is served. - id: rfc8594 name: Sunset header conforms: false evidence: No Sunset or Deprecation header convention is published or observed. - id: pagination conforms: true style: offset-limit evidence: >- GET /api/external/customcategories accepts start (offset) and max (page size, 1–999) and returns value.total alongside value.result. Conventional offset paging, though the server defaults (start=50, max=0) return zero rows unless overridden. - id: idempotency conforms: false evidence: >- No Idempotency-Key header, no request-deduplication, no idempotent-retry semantics. POST /api/external/customcategories retried will create a duplicate category. The reference client retries only after a 401 re-login, which is the one case where the original request was never processed. - id: rest conforms: partial evidence: >- Resource-oriented JSON over HTTP, but with material deviations: delete is a PUT with a body rather than an HTTP DELETE, application errors return HTTP 200, and write payloads are wrapped in a single "value" key rather than posted at the root. - id: json-api conforms: false evidence: No JSON:API media type, no data/attributes/relationships envelope. - id: odata conforms: false evidence: No $filter/$select/$expand; filtering uses bespoke filterProperty/filterValue. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is served from any Peer39 host. Probed /openapi.json, /swagger.json and /api-docs on www.peer39.com (404) and app.peer39.com (SPA HTML). - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is documented. The API is request/response only; category changes are synced to DSPs server-side with no callback to the caller. - id: mcp name: Model Context Protocol conforms: partial evidence: >- A first-party-authored MCP server exists in two deployments — a stdio server (10 tools) and a remote streamable-HTTP connector (9 tools) whose OAuth 2.1 authorization server implements RFC 7591, RFC 8414, RFC 9728 and RFC 8707 with PKCE S256. Marked PARTIAL rather than true because neither is published to npm, neither is hosted on a Peer39-controlled domain, and both self-describe as internal pre-release beta. Detail in mcp/peer39-mcp.yml. - id: a2a conforms: false evidence: >- No Agent Card at /.well-known/agent-card.json or /.well-known/agent.json on any Peer39 host. compliance_programs: published: false certifications: [] trust_center: null evidence: >- probe-security-programs.py returned vdp=none, trust=none on 2026-08-12. Peer39 publishes no trust center, no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP certification page, and no named compliance program. Its privacy posture is stated narratively in https://www.peer39.com/privacy-policy/ and https://www.peer39.com/crawler-notice, which assert that Peer39 drops no cookies and does not track or append browsing behavior to individual users — a privacy CLAIM, not an audited certification, so no Compliance pointer is emitted. industry_context: note: >- Peer39 appears as an example data provider in the AdCP (Ad Context Protocol) Signals Activation Protocol documentation. No evidence was found that Peer39 operates an AdCP signals agent or publishes an AdCP-conformant endpoint, so no conformance is claimed.