generated: '2026-07-21' method: derived source: openapi/socotra-openapi-original.json note: >- Standards conformance derived from the OpenAPI definition and Socotra docs. Security/compliance certifications (ISO 27001, SOC 1, HIPAA, GDPR, CCPA/CPRA) are captured separately in security/socotra-trust-center.yml. standards: - id: openapi-3.0 conforms: true evidence: Published OpenAPI 3.0.1 definition with 722 operations and 629 component schemas. - id: oauth2 conforms: true evidence: OAuth 2.1 authorization-code flow used for interactive/agent access (MCP server, UI login). - id: oidc conforms: true evidence: OIDC identity providers supported (addOIDCIdentityProvider). - id: saml2 conforms: true evidence: SAML 2.0 identity providers supported (addSAMLIdentityProvider) for workforce SSO. - id: rest conforms: true evidence: Resource-oriented HTTP+JSON API with locator-addressed resources. - id: pagination-offset conforms: true evidence: Offset/count pagination with a ListPageResponse envelope. - id: idempotency-key conforms: partial evidence: X-Idempotency-Key header supported on migration operations (optional). - id: rfc9457-problem-details conforms: false evidence: No application/problem+json responses declared in the OpenAPI. - id: webhooks conforms: true evidence: Tenant webhook subscription management under /event/{tenantLocator}/webhooks. - id: acord conforms: unknown evidence: Insurance data model is Socotra-native; no explicit ACORD standard claim found.