generated: '2026-07-21' method: derived source: openapi/speccheck-openapi.yml standards: - id: oauth2 conforms: false evidence: >- Uses a custom POST /v1/oauth/token client-credentials exchange returning a bearer token, but does not declare an oauth2 securityScheme or scopes. - id: bearer-token conforms: true evidence: http bearer securityScheme; Authorization Bearer . - id: rfc9457-problem-details conforms: false evidence: 'Custom error envelope with an error object (type, message, code, param); not application/problem+json.' - id: idempotency-key conforms: true evidence: Idempotency-Key header on all POST requests with stored-result replay. - id: cursor-pagination conforms: true evidence: starting_after / ending_before / limit with has_more, on listOrders. - id: rfc3339-timestamps conforms: false evidence: Timestamps are integer Unix epoch seconds, not RFC 3339 strings. - id: openapi conforms: true evidence: Reconstructed OpenAPI 3.1 at openapi/speccheck-openapi.yml (from docs). - id: fhir-r4 conforms: false - id: scim2 conforms: false notes: >- Standards asserted from the OpenAPI and docs. No published third-party compliance certifications (SOC 2 / ISO 27001 / HIPAA) were found in public docs, so no Compliance pointer is emitted.