generated: '2026-08-05' method: searched source: openapi/smart-pension-keystone-openapi.yml docs: - https://developers.autoenrolment.co.uk/smart/8746c0c6c82b7-o-auth - https://developers.autoenrolment.co.uk/smart/28783c05ecb6a-using-the-api - https://trust.smart.co/ standards: - id: openapi-3.0 conforms: true version: 3.0.3 evidence: >- The provider publishes an OpenAPI 3.0.3 document with 271 paths, 383 operations and 222 component schemas, exported from its Stoplight-hosted developer portal. - id: oauth2 conforms: true evidence: >- components.securitySchemes declares an oauth2 scheme with an authorizationCode flow; the docs additionally document a clientCredentials flow (RFC 6749) for machine-to-machine partners. - id: oauth2-client-credentials conforms: true evidence: >- Documented POST to /oauth/token with client_id, client_secret, grant_type=client_credentials and scope, returning access_token / token_type / expires_in / scope / created_at. caveat: >- Credentials are sent in a JSON body with a non-standard `Token-Type: jwt` header rather than the RFC 6749 form-encoded body or HTTP Basic client authentication. - id: oauth2-metadata-rfc8414 conforms: false evidence: >- /.well-known/oauth-authorization-server returns 401 on the API hosts and 404 elsewhere; no authorization-server metadata document is published. - id: oidc conforms: false evidence: >- No /.well-known/openid-configuration is served on any host, and no openIdConnect security scheme is declared. The identity service at id.autoenrolment.co.uk is an OAuth 2.0 authorization server, not an advertised OpenID Provider. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom code/title/detail/source envelope over application/json, not application/problem+json. See errors/smart-pension-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt on any host, despite a published responsible-disclosure program. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy is published. - id: rfc8615-well-known conforms: false evidence: >- No well-known URI is served. On the API hosts the entire origin is token-authenticated, so even /.well-known/ paths return 401 rather than being anonymously reachable. - id: json-api conforms: partial evidence: >- The error object borrows JSON:API's `source.pointer` convention and the paginated envelope carries a `links` block with self/next/prev/first/last relations, but responses are plain JSON objects — there is no `data`/`type`/`attributes` resource envelope and no application/vnd.api+json media type. - id: pagination conforms: true style: offset-limit evidence: >- limit (default 50, max 100) and offset (default 0) with a links envelope carrying self/next/prev/first/last. Documented as unstable under concurrent writes. - id: idempotency conforms: false evidence: >- No idempotency key, replay window or safe-retry contract is documented, and no Idempotency-Key parameter appears in the OpenAPI — notable for an API whose primary write is a pension contribution. - id: rate-limit-headers conforms: false evidence: >- Numeric per-endpoint limits are published and 429 is returned, but no RateLimit / X-RateLimit / Retry-After response headers are documented. - id: papdis conforms: true full_name: Payroll and Pension Data Interface Standard evidence: >- The Flows guide documents POSTing a PAPDIS CSV to the /imports endpoint as the "light integration" path, mirroring the portal's own file upload; the help centre publishes a PAPDIS article and a PAPDIS error-fixing guide. PAPDIS is the UK payroll-to-pension data interchange standard. docs: https://www.smartpension.co.uk/help-centre-articles/about-papdis-files - id: uk-automatic-enrolment conforms: true regime: Pensions Act 2008 automatic enrolment evidence: >- The API models UK-specific auto-enrolment mechanics as first-class resources — assessment and eligibility, postponements (including automatic postponement periods), opt-in and opt-out requests, re-enrolment, staging/scheme start dates, and the employer pension scheme registration (regulator reference). The Introduction states the documentation is specific to the UK master trust because "local legislative rules often mean that there are unique requirements per platform". - id: iso-27001 conforms: true version: '2022' evidence: Listed on the Smart Group trust center at https://trust.smart.co/ with a 2025 certificate available on request. - id: soc2-type2 conforms: true evidence: Listed on the Smart Group trust center at https://trust.smart.co/ with a final report available on request. - id: gdpr-uk conforms: partial evidence: >- A UK privacy notice is published and the trust center records data-retention, data-classification and customer-data-deletion controls, but no GDPR/UK-GDPR attestation document is offered. - id: fapi conforms: false evidence: No FAPI profile, mTLS, PAR, JARM or sender-constrained token support is declared. - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface exists. Change detection is by polling (/companies/{company_id}/notifications and re-reading member records before a pay run), which the Flows guide documents as the intended pattern. compliance_program: published: true url: https://trust.smart.co/ certifications: [ISO 27001:2022, SOC 2 Type 2] detail: security/smart-pension-trust-center.yml x-evidence: fetched: '2026-08-05' sources: - url: https://trust.smart.co/ http_status: 200 - url: https://stoplight.io/api/v1/projects/smart-pension/smart-documentation-portal/nodes/swagger.json http_status: 200 - url: https://api.autoenrolment.co.uk/.well-known/openid-configuration http_status: 401 - url: https://www.smartpension.co.uk/.well-known/security.txt http_status: 404