generated: '2026-07-21' method: derived source: openapi/reasonblocks-openapi-original.json notes: >- Derived from the published OpenAPI 3.1.0 schema and the REST API setup/versioning docs. No published third-party compliance certifications (SOC 2 / ISO 27001 / etc.) were found, so no `Compliance` pointer is emitted. standards: - id: openapi-3.1 conforms: true evidence: openapi field is 3.1.0 (rb-api.reasonblocks.com/openapi.json) - id: http-bearer-auth conforms: true evidence: components.securitySchemes.HTTPBearer type http scheme bearer - id: oauth2 conforms: false evidence: no oauth2 security scheme; API-key bearer only - id: openid-connect conforms: false - id: rfc9457-problem-details conforms: false evidence: 'error bodies are plain JSON {"detail": ""}, not application/problem+json' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on reasonblocks.com and rb-api.reasonblocks.com - id: uri-path-versioning conforms: true evidence: all public routes mounted under /v1/, v2 reserved for breaking changes - id: token-pagination conforms: true evidence: list endpoints expose limit/offset/token query parameters - id: rate-limiting conforms: true evidence: per-key sliding-window limiter, 429 with Retry-After header - id: idempotency-keys conforms: false evidence: no Idempotency-Key header or parameter documented in the spec or docs - id: fhir-r4 conforms: false - id: scim-2.0 conforms: false - id: json-api conforms: false