generated: '2026-07-25' method: derived source: >- openapi/*.json, well-known/sk-telecom-well-known.yml, errors/sk-telecom-error-codes.yml, conventions/sk-telecom-conventions.yml, review.yml, plus searches of the SK open API portal and the CAMARA / GSMA Open Gateway public record. standards: - id: openapi-3.1 conforms: true evidence: All six harvested documents declare openapi 3.1.0 and parse. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec; portal serves no oauth-authorization-server document. - id: oidc conforms: false evidence: >- T ID is a federated identity service, but /.well-known/openid-configuration returns 404 on openapi.sk.com and the SPA shell on developers.t-id.co.kr — no OIDC discovery is published. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: 404 on every SK Telecom host probed. - id: rfc9728-oauth-protected-resource-metadata conforms: partial evidence: >- Served only for the ReadMe documentation MCP endpoints on the five *-skopenapi.readme.io hubs, pointing at ReadMe's authorization server — not for any SK Telecom API. - id: rfc9457-problem-details conforms: false evidence: No operation returns application/problem+json; a proprietary {"error":{...}} envelope is used. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any SK Telecom or SK open API host. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation headers; the OVS API was terminated with ~1 day of notice-board warning and the spec was never marked deprecated. - id: rfc6750-bearer-token conforms: false evidence: Auth is an appKey request header, not an Authorization bearer token. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published; no callbacks or webhooks in any spec. - id: graphql conforms: false evidence: No /graphql endpoint on any SK Telecom host. - id: grpc conforms: false evidence: No .proto published in the SK Telecom GitHub organisation, on buf.build or in the docs. - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: camara conforms: false evidence: >- SK Telecom is a listed CAMARA participant (camaraproject/Governance PARTICIPANTS.MD) and a GSMA Open Gateway signatory, and has three commercial routes to market for network APIs (TTA three-operator MoU 2024-10-28, Bridge Alliance BAEx endorsement 2024-08-27, Aduna / SK telink MoU 2025-09-08). No CAMARA endpoint — Number Verification, SIM Swap, KYC Match, Quality on Demand — is callable from any SK Telecom-operated host. Participation is real; conformance is not. - id: gsma-open-gateway conforms: false evidence: >- GSMA maintains an organisation page for SK Telecom, but gsma.com returned HTTP 403 to anonymous probes and no Open Gateway endpoint exists under any sktelecom.com hostname. - id: tmforum-open-api conforms: false evidence: No TM Forum Open API conformance certification found; no TMF surface published. - id: ciba conforms: false evidence: CIBA does not appear anywhere in SK Telecom's public developer surface. compliance_program: published: false trust_center: null certifications: [] note: >- No trust centre, no security/compliance page and no named certification (SOC 2, ISO 27001, ISMS-P, PCI DSS) is published on any SK Telecom developer-facing host. trust.sktelecom.com does not resolve; probe-security-programs.py returned no hit on 2026-07-25. No Compliance pointer is emitted in apis.yml because there is no published compliance programme to point at.