generated: '2026-07-20' method: derived source: https://docs.firstlook.gg/developers/api/ notes: >- Cross-cutting standards conformance for Pragma's public developer surface, derived from the documented auth model, the FirstLook External API (REST + Swagger UI), and the OAuth-based MCP server. No published compliance certifications (SOC 2 / ISO 27001 / PCI / HIPAA) were located on the public site, so no Compliance pointer is emitted. standards: - id: rest conforms: true evidence: FirstLook External API is a REST API documented via Swagger/OpenAPI UI. - id: openapi conforms: true evidence: Interactive Swagger UI published at https://api.firstlook.gg/external/swagger-ui/ (spec behind bot protection; not harvested). - id: oauth2 conforms: true evidence: FirstLook MCP server authenticates via OAuth (authorization code) with a FirstLook account. - id: mcp conforms: true evidence: Hosted Model Context Protocol server at https://mcp.firstlook.gg/mcp (Streamable HTTP). - id: api-key-auth conforms: true evidence: Scoped API tokens (header) for the FirstLook External API. - id: rfc9457-problem-details conforms: false evidence: Not documented on the public surface. - id: fhir-r4 conforms: false - id: scim conforms: false