generated: '2026-07-21' method: searched source: https://docs.roller.app/docs/api/overview standards: - id: oauth2 conforms: true evidence: >- REST and Reporting APIs authenticate with an OAuth2 client-credentials flow against api.roller.app/token (docs.roller.app/docs/api/authentication). - id: octo conforms: true evidence: >- ROLLER exposes an OCTO API (Open Connectivity for Tourism Operators) surface — OCTO API Core plus the Pricing Capability — as part of its Advanced Channel Manager, per the Developer Center. See docs.octo.travel. reference: https://docs.octo.travel/ - id: webhooks conforms: true evidence: >- Provider documents webhooks for real-time, event-driven notifications (docs.roller.app/docs/api/webhooks-overview). - id: pci-dss conforms: true evidence: >- PCI DSS listed among ROLLER's security certifications (trust center). reference: https://trust.roller.software/ - id: soc2 conforms: true evidence: >- SOC 2 listed among ROLLER's security certifications (trust center). reference: https://trust.roller.software/ - id: rfc9457-problem-details conforms: false evidence: not verified — public OpenAPI spec not available for inspection