generated: '2026-09-17' method: searched source: >- openapi/statsig-console-api-openapi.json, well-known/statsig-well-known.yml, https://docs.statsig.com/access-management/sso/overview, https://docs.statsig.com/access-management/scim/overview, https://www.statsig.com/legal/security, https://trust.statsig.com/ description: >- Standards and cross-cutting conformance for Statsig, asserted only where a fetched document or the published contract shows it. Statsig's strongest conformance is on the agent-access side: it serves RFC 8414 and RFC 9728 OAuth discovery metadata and speaks MCP Streamable HTTP with a correctly-formed challenge. Its REST contract is conventional OpenAPI 3.0 with no problem+json and no declared rate-limit semantics. conformance: - id: openapi-3.0 conforms: true evidence: https://api.statsig.com/openapi/20240601.json detail: >- First-party OpenAPI 3.0.0 document, 208 paths / 324 operations / 186 component schemas, maintained per the Console API docs and versioned 20240601.0.0. - id: oauth2 conforms: true evidence: https://api.statsig.com/.well-known/oauth-authorization-server detail: >- Authorization Code with PKCE (S256) and the device-code grant, token endpoint at /v1/oauth/access_token. Scoped to the MCP endpoint; the REST Console API is API-key only. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://api.statsig.com/.well-known/oauth-authorization-server detail: Served on both api.statsig.com and statsigapi.net, HTTP 200, with issuer and endpoints. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://api.statsig.com/.well-known/oauth-protected-resource/v1/mcp detail: >- Resource metadata for the MCP endpoint, and the 401 from POST /v1/mcp carries a WWW-Authenticate challenge whose resource_metadata parameter points at exactly this document. This is the RFC 9728 round trip working end to end. - id: rfc7591-dynamic-client-registration conforms: true evidence: https://api.statsig.com/.well-known/oauth-authorization-server detail: registration_endpoint https://api.statsig.com/v1/oauth/register is advertised. - id: mcp conforms: true evidence: https://docs.statsig.com/api/mcp detail: >- Two Streamable HTTP servers. The public Docs server answered a live initialize with protocolVersion 2025-06-18 and serverInfo statsig-docs 1.1.0, and returned 5 tools with JSON Schema draft-07 inputSchema. The authenticated server at api.statsig.com/v1/mcp answered an anonymous tools/list with a conformant 401 challenge. - id: oidc conforms: true evidence: https://docs.statsig.com/access-management/sso/overview detail: >- Single Sign-On is offered via OIDC for Enterprise organizations. Statsig is the relying party here; it serves no /.well-known/openid-configuration of its own (probed on 7 hosts, all 404). - id: scim conforms: true evidence: https://docs.statsig.com/access-management/scim/overview detail: >- SCIM user and group provisioning with Okta — Push Users, Import Users, Import Groups, Push Groups, plus SCIM group aliases and a dedicated key with a `scim` prefix. caveat: >- Claimed in documentation, NOT declared in the contract. No urn:ietf:params:scim:schemas:* URN and no /scim/v2 path appears in the published OpenAPI, so an integrator cannot discover the SCIM surface from the contract — only from the Okta app. - id: hmac-webhook-signing conforms: true evidence: https://docs.statsig.com/integrations/event_webhook detail: >- HMAC-SHA256 over a versioned basestring (v0:{timestamp}:{body}), delivered in X-Statsig-Signature with X-Statsig-Request-Timestamp — the Slack-style scheme, including the timestamp in the signed material, which is what makes replay detection possible. - id: rfc9457-problem-details conforms: false evidence: openapi/statsig-console-api-openapi.json detail: >- All 411 declared 4xx responses use a custom {"status","message"} envelope with Content-Type application/json. No application/problem+json anywhere. - id: pagination conforms: true evidence: openapi/statsig-console-api-openapi.json detail: >- Uniform page/limit request params with a pagination metadata object carrying itemsPerPage, pageNumber, nextPage, previousPage and totalItems on every list operation. - id: idempotency conforms: false evidence: openapi/statsig-console-api-openapi.json detail: >- No idempotency key on any mutating operation; the string does not occur in the contract. See conventions/statsig-conventions.yml (idempotency.coverage = none). - id: rfc8594-sunset-header conforms: false evidence: https://docs.statsig.com/console-api/introduction detail: No Sunset or Deprecation header, and no operation marked deprecated in the contract. - id: rfc9116-security-txt conforms: false evidence: well-known/statsig-well-known.yml detail: No /.well-known/security.txt on any of the 7 hosts probed. - id: grpc-protobuf conforms: true evidence: https://github.com/statsig-io/api-interface-definitions detail: >- proto3 service definitions published for the Statsig Forward Proxy (StatsigForwardProxy.getConfigSpec / StreamConfigSpec) plus the gRPC health-check and data adapter contracts. A real, second machine-readable contract alongside the OpenAPI. - id: llms-txt conforms: true evidence: https://docs.statsig.com/llms.txt detail: >- A curated 114-line /llms.txt with section groupings, plus /llms-full.txt, per-page markdown via an Accept: text/markdown header or a .md suffix, and a /api/content/ retrieval route. One of the more complete agent-documentation postures in the catalog. - id: agent-skills conforms: true evidence: https://github.com/statsig-io/agent-skills detail: >- Three provider-authored Agent Skills with SKILL.md frontmatter (name + description), reference material and executable helper scripts, installable with `npx skills add statsig-io/agent-skills`. Provider-published, not derived. - id: a2a-agent-card conforms: false evidence: well-known/statsig-well-known.yml detail: >- No /.well-known/agent-card.json and no legacy /.well-known/agent.json on any host. Statsig's agent surface is MCP, not A2A. domain_standards: note: >- Feature management and experimentation has no ratified interchange standard — there is no OpenFeature-style contract Statsig could declare in its own spec, and OpenFeature's Statsig provider is authored by the OpenFeature contrib project, not by Statsig. Reward-only: nothing is asserted here rather than inventing a fit. candidates_checked: - {standard: OpenFeature, present_in_contract: false, note: 'dev.openfeature.contrib.providers:statsig exists on Maven Central but is a community contrib artifact, not first-party.'} - {standard: 'SCIM (urn:ietf:params:scim:schemas)', present_in_contract: false, note: 'Documented capability; no URN or /scim path in the spec.'} - {standard: OData, present_in_contract: false} - {standard: 'JSON:API', present_in_contract: false} compliance: certifications: ['SOC 2 Type II', 'ISO 27001', 'GDPR'] hipaa: 'eligible under BAA (Enterprise tier)' evidence: [https://www.statsig.com/legal/security, https://trust.statsig.com/, https://www.statsig.com/pricing] see: security/statsig-trust-center.yml