generated: '2026-07-21' method: derived source: >- openapi/sonarsource-web-api-openapi.yml and the service catalog at https://sonarcloud.io/api/webservices/list. standards: - id: oauth2 conforms: false evidence: The classic Web API authenticates with user tokens (Bearer/Basic), not OAuth2 flows. - id: openid-connect conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors use a custom envelope {"errors":[{"msg":...}]}, not application/problem+json. - id: bearer-token-auth conforms: true evidence: securitySchemes include http bearer (user token). - id: http-basic-auth conforms: true evidence: securitySchemes include http basic (token as username, empty password). - id: pagination conforms: true evidence: List/search endpoints use p/ps page-number parameters with a paging response object. - id: idempotency conforms: false evidence: No idempotency-key mechanism is documented. - id: openapi conforms: true evidence: A machine-readable service catalog is published and converts faithfully to OpenAPI 3.0. compliance_note: >- No verified public trust center or named certifications (SOC 2 / ISO 27001 / etc.) were confirmed on the public developer surface during this pass; therefore no Compliance pointer is asserted. This is a standards-conformance derivation only.