generated: '2026-09-04' method: derived source: >- openapi/*.yml, asyncapi/red5-webrtc-streaming-asyncapi.yml, https://www.red5.net/docs/red5-pro/users-guide/authentication/, https://www.red5.net/docs/red5-cloud/users-guide/authentication/, https://www.red5.net/legal/data-processing-addendum/ standards: - id: whip name: WHIP — WebRTC-HTTP Ingestion Protocol (RFC 9725) conforms: true evidence: >- openapi/red5-proxy-api-openapi.yml declares POST /proxy/whip/{nodeGroupName}/{streamGuid} (operationId whipPublish) as the WebRTC ingest endpoint; the Red5 HTML SDK ships WHIPClient as its only publisher class since 15.0.0. domain_standard: true market: live video streaming - id: whep name: WHEP — WebRTC-HTTP Egress Protocol (IETF draft) conforms: true evidence: >- openapi/red5-proxy-api-openapi.yml declares POST /proxy/whep/{nodeGroupName}/{streamGuid} (operationId whepSubscribe); the Red5 HTML SDK ships WHEPClient as its only subscriber class since 15.0.0, and Red5 publishes a standalone red5pro-whep-player. domain_standard: true market: live video streaming - id: rtmp name: RTMP / Enhanced RTMP (E-RTMP) conforms: true evidence: >- openapi/red5-rtmp-restreamer-api-openapi.yml provisions RTMP and RTMPS push and pull restreaming (createRtmpProvision, createRtmpPullProvision); Red5 publishes an E-RTMP product page and ships RTMP ingest across every plan tier. domain_standard: true market: live video streaming - id: hls name: HTTP Live Streaming (RFC 8216) conforms: true evidence: >- HLS delivery is a documented output of the Video Packager node role in Stream Manager 2.0 and is listed as a supported protocol on every published pricing tier. domain_standard: true market: live video streaming - id: srt name: SRT — Secure Reliable Transport conforms: true evidence: >- Stream Manager 2.0 restreamer examples document SRT and SRT-caller provisions (stream-manager-2.0-restreamer-example-srt, -srt-caller). domain_standard: true market: live video contribution - id: moq name: Media over QUIC (MoQ / MoQT) conforms: true evidence: >- org.red5:red5-moq-pkgr 1.3.11 and org.red5:moq-cmaf 1.1.2 are published to Maven Central; Red5 ships MoQ protocol support in Red5 Pro v15.4.0 and runs a public MoQ beta. Emerging standard — Red5 is an implementer, not a certified conformer. domain_standard: true market: live video streaming - id: cmaf name: CMAF — Common Media Application Format (ISO/IEC 23000-19) conforms: true evidence: org.red5:moq-cmaf published to Maven Central; CMAF/CMSF covered in Red5's own docs and blog. - id: jwt name: JSON Web Token (RFC 7519) conforms: true evidence: >- Stream Manager 2.0 Auth API issues JWTs; openapi securityScheme `bearerAuth` declares type http, scheme bearer, bearerFormat JWT. Red5 Pro also ships a standalone JwtAuthenticator that validates RFC 7519 claims locally. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any of the ten OpenAPI documents; derive-oauth-scopes.py found 0 oauth2 schemes and 0 scopes. Authentication is JWT bearer (Stream Manager 2.0) or an `accessToken` query parameter (standalone plugins). - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Red5-owned host probed 2026-09-04. - id: rfc9457-problem-details conforms: false evidence: >- All 4xx responses return a flat application/json `{code, message}` Error object. No application/problem+json media type appears in any spec. See errors/red5-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header is documented or declared. See lifecycle/red5-lifecycle.yml. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header or equivalent replay-protection parameter appears in any of the 26 operations, and none is documented. See conventions/red5-conventions.yml. - id: pagination conforms: false evidence: >- No collection operation declares limit/offset/cursor/page parameters. listNodeGroups, listNodes, listMixers and listMixerInputs return a bare `{data: [...]}` envelope with no paging controls. - id: rate-limit-headers conforms: false evidence: >- No RateLimit-*, X-RateLimit-* or Retry-After header is documented, and no 429 response is declared on any operation. See rate-limits/red5-rate-limits.yml. - id: gdpr conforms: true evidence: >- Published Data Processing Addendum at https://www.red5.net/legal/data-processing-addendum/ incorporating EU Standard Contractual Clauses, plus a published privacy policy and acceptable use policy. - id: ccpa conforms: true evidence: CCPA obligations are addressed explicitly in the published DPA. - id: soc2 conforms: false evidence: >- No trust center, no certification page. probe-security-programs.py 2026-09-04 returned trust=none; trust.red5.net does not resolve and /security/ returns 404. - id: iso27001 conforms: false evidence: Not claimed anywhere on the public site or in the legal documents. domain_standard_summary: market: live video streaming and real-time media delivery note: >- Red5's contract declares its domain standards in the paths themselves — /proxy/whip and /proxy/whep are the IETF WHIP/WHEP ingest and egress endpoints, not bespoke vendor verbs, so a client that already speaks WHIP/WHEP integrates with no custom connector. RTMP/E-RTMP, HLS, SRT and now MoQ/CMAF are carried the same way.