generated: '2026-08-13' method: searched source: >- openapi/ (44 SendGrid v3 specs), the SendGrid errors and rate-limits documentation, and the SendGrid SSO product. Cross-cutting industry-standard conformance derived from the specs and confirmed against docs where noted. description: >- Which cross-cutting industry / interoperability standards the SendGrid v3 API conforms to. SendGrid is a bearer-API-key REST platform; it does not run an OAuth2/OIDC authorization server for API access, does not use RFC 9457 problem+json errors (it uses a custom errors[] envelope), and is not a healthcare/financial-standard API. It does offer SAML 2.0 SSO for console login (not for API auth). standards: - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any of the 44 OpenAPI specs; the sole scheme is HTTP bearer (API key). API-key permission "scopes" exist but are not OAuth2 scopes. - id: openid-connect conforms: false evidence: No openIdConnect securityScheme; /.well-known/openid-configuration returns 403. - id: saml2-sso conforms: true evidence: >- SendGrid Single Sign-On API manages SAML 2.0 IdP integrations (Okta, Duo, Microsoft Entra ID) for console access — openapi/tsg_sso_v3.yaml. - id: rfc9457-problem-details conforms: false evidence: >- No response uses application/problem+json across the specs; errors use a custom envelope {errors:[{field,message}]}. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns HTTP 403 on api.sendgrid.com and sendgrid.com. - id: rfc6750-bearer-token conforms: true evidence: API keys are sent as a bearer token in the Authorization header (HTTP bearer scheme). - id: rate-limit-headers conforms: true evidence: >- Responses carry X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset; 429 on exhaustion (rate-limits docs). - id: pagination conforms: true evidence: >- Mixed conventions across products: limit/offset (classic list endpoints), page_size/page_token cursor pagination (Marketing Campaigns contacts/lists). - id: webhooks-async conforms: true evidence: >- Event Webhook and Inbound Parse are modeled as AsyncAPI in asyncapi/; Event Webhook supports signed payloads (ECDSA signature verification). - id: mcp conforms: true evidence: >- Twilio (SendGrid's parent) serves a live, unauthenticated Model Context Protocol endpoint at https://mcp.twilio.com/docs. Probed 2026-08-13: initialize returned protocolVersion 2025-11-25 and serverInfo twilio-docs-mcp 0.1.0; tools/list returned two tools with full inputSchemas. It is a documentation/discovery server, not an execution server — see mcp/sendgrid-tool-crosswalk.yml. - id: agent-skills conforms: true evidence: >- Twilio publishes eight SendGrid Agent Skills (SKILL.md with name + description frontmatter) at github.com/twilio/ai/tree/main/skills/sendgrid, distributed as the twilio-developer-kit plugin. Saved verbatim in skills/. - id: a2a-agent-card conforms: false evidence: >- No /.well-known/agent-card.json or /.well-known/agent.json on sendgrid.com (403), api.sendgrid.com (403) or www.twilio.com (404). - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation response headers are documented; deprecations are announced through the Twilio changelog. See lifecycle/sendgrid-lifecycle.yml. - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: odata conforms: false - id: json-api conforms: false - id: idempotency-key conforms: false evidence: No Idempotency-Key header documented; mail-send batching uses batch_id instead.