generated: '2026-07-23' method: searched source: - https://plaid.com/docs/api/ - https://plaid.com/trust/ - openapi/_original/plaid-openapi-original.yml description: Which industry / cross-cutting standards the Plaid platform conforms to, searched from Plaid's docs and trust pages and derived from the published OpenAPI. Plaid is a US open-finance data aggregator; it aligns to FDX for data access (Core Exchange), the UK Open Banking / PSD2 payment-initiation model for its EU/UK Payment Initiation product, and publishes SOC 2 / ISO 27001 compliance posture. standards: - id: openapi-3.0 conforms: true evidence: Plaid publishes a machine-readable OpenAPI 3.0 definition at github.com/plaid/plaid-openapi - id: fdx conforms: true evidence: Plaid Core Exchange is an FDX-aligned data-access API for data providers (github.com/plaid/core-exchange) - id: psd2 conforms: true evidence: Plaid Payment Initiation operates as a PSD2/Open Banking PISP in the UK and EU - id: open-banking-uk conforms: true evidence: Payment Initiation and Variable Recurring Payments (CVRP) built on UK Open Banking standards - id: oauth2 conforms: partial evidence: Plaid Link uses bank-side OAuth for institution authorization; the Plaid REST API itself authenticates with client_id + secret credentials, not OAuth bearer tokens - id: rfc9457-problem-details conforms: false evidence: Errors use Plaid's own JSON envelope (error_type/error_code/error_message/ request_id), not application/problem+json - id: cfpb-1033 conforms: true evidence: Core Exchange positioned for CFPB 1033 personal-financial-data-rights rules - id: soc2-type-ii conforms: true evidence: SOC 2 Type II reported on Plaid's trust center - id: iso-27001 conforms: true evidence: ISO 27001 certification reported on Plaid's trust center - id: webhook-signing-es256 conforms: true evidence: Webhooks signed with an ES256 JWT in the Plaid-Verification header (JWKS verification) - id: idempotency conforms: true evidence: Transfer money-movement endpoints accept an idempotency_key request field - id: oidc conforms: true evidence: an openIdConnect securityScheme is declared - id: rfc9457 conforms: false evidence: no response declares application/problem+json - id: pagination conforms: true evidence: list operations take limit, offset