generated: '2026-08-13' method: derived source: openapi/_original/pixc-public-api-swagger-original.json docs: https://pixc.com/api/ note: >- Derived from the published Swagger 2.0 document and live probes. Pixc publishes no certification or compliance program of any kind — no trust centre, no SOC 2 / ISO 27001 / PCI / HIPAA / GDPR statement on a reachable page (probe-security-programs.py returned vdp=none trust=none; /security, /trust and /compliance all 404) — so NO `Compliance` pointer is emitted in apis.yml. standards: - id: openapi conforms: false evidence: >- Pixc publishes Swagger 2.0 (swagger: "2.0") at https://dashboard.pixc.com/v1/schema, not OpenAPI 3.x. The OpenAPI 3.1 documents in openapi/ are an API Evangelist conversion of that source, not a provider publication. - id: swagger-2.0 conforms: true evidence: 'swagger: "2.0" with host, basePath, paths, definitions and securityDefinitions' - id: oauth2 conforms: partial evidence: >- securityDefinitions.pixc_auth declares type oauth2 with the implicit flow against https://dashboard.pixc.com/v1/oauth and eleven scopes, and every operation carries a scoped security requirement. But the implicit flow is deprecated by OAuth 2.0 Security Best Current Practice (RFC 9700), no tokenUrl or refresh is declared, and the Getting Started docs route developers to a long-lived personal Access Token instead of the flow. - id: oauth2-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on dashboard.pixc.com - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on dashboard.pixc.com - id: rfc9457-problem-details conforms: false evidence: >- Errors use a bespoke { success, code, message } envelope on application/json; no application/problem+json media type appears anywhere in the spec. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on dashboard.pixc.com and 403 on pixc.com - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header support is documented - id: rfc9116-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 - id: idempotency-key conforms: false evidence: no idempotency header, parameter or retry-safety contract in spec or docs - id: pagination conforms: partial evidence: >- Offset pagination via limit/start on all five list operations, but no total count, no cursor, no link headers and no documented default or maximum page size. - id: webhooks conforms: true evidence: >- Webhooks are a first-class REST resource with full CRUD and a three-value event enum (order_created, order_status_updated, download_generated). See asyncapi/pixc-webhooks.yml. - id: asyncapi conforms: false evidence: no AsyncAPI document is published on any host or in the Pixc2 GitHub org - id: json-api conforms: false evidence: bespoke { success, data } envelope; no JSON:API media type or structure - id: mcp conforms: false evidence: no MCP server published; see mcp/pixc-mcp.yml - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on dashboard.pixc.com and 403 on pixc.com - id: tls conforms: true evidence: 'HTTPS enforced with HSTS max-age=31536000; includeSubDomains observed live on dashboard.pixc.com' - id: cors conforms: true evidence: 'Access-Control-Allow-Origin: * with GET,PUT,POST,DELETE,OPTIONS observed live' compliance_program: published: false certifications: [] evidence: - {url: 'https://pixc.com/security', status: 404} - {url: 'https://pixc.com/trust', status: 404} - {url: 'https://pixc.com/compliance', status: 404} checked: '2026-08-13'