generated: '2026-07-26' method: searched source: https://developers.street.co.uk/docs/street-open-api/guides/jsonapi-standard + openapi/*.yml summary: >- Street.co.uk's one explicit, provider-claimed standard is JSON:API — all three APIs declare conformance to it and the docs point developers at the JSON:API implementations directory. Everything else is derived from the harvested OpenAPI 3.1 contracts. There is no OAuth/OIDC, no RFC 9457 problem details, no RFC 8594 sunset signalling, and — as expected for a UK estate agency platform — no RESO Data Dictionary or Web API conformance, since the UK has no MLS or RESO regime. standards: - id: jsonapi-1.x conforms: true claimed_by_provider: true evidence: >- "Our API adheres to the JSON:API standard" (Street Open API getting started); Property Feed and Spectre docs repeat the claim; all responses use media type application/vnd.api+json; schemas are {id, type, attributes, relationships} with a top-level included[]/meta/links. docs: https://developers.street.co.uk/docs/street-open-api/guides/jsonapi-standard - id: openapi-3.1 conforms: true evidence: three published OpenAPI 3.1.0 documents, downloadable as JSON from https://developers.street.co.uk/docs//api-reference/openapi.json - id: http-bearer-rfc6750 conforms: true evidence: 'components.securitySchemes {type: http, scheme: bearer} in all three specs, applied globally via a root security requirement' - id: pagination-page-based conforms: true evidence: 'page[number] / page[size] (max 100) with meta.pagination and links.first/prev/next/last — the JSON:API page-based profile' - id: oauth2 conforms: false evidence: no oauth2 security scheme in any spec; /.well-known/oauth-authorization-server 404 on every host. A third-party supplier directory claims Street offers "OAuth" — unverified and contradicted by the published contracts. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on street.co.uk, demo.street.co.uk, api.spectre.uk.com and spectre.uk.com - id: rfc9457-problem-details conforms: false evidence: zero occurrences of application/problem+json across 1.6 MB of harvested contract; errors use the JSON:API errors[] object instead - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation response header documented or declared; deprecations are announced only on the updates page - id: idempotency-key conforms: false evidence: zero occurrences of "idempoten" in the docs or any spec - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on all hosts - id: reso-data-dictionary conforms: false evidence: no RESO reference anywhere on Street.co.uk's public surface; the UK has no MLS/RESO regime (see review.yml sectorPosture) - id: reso-web-api conforms: false evidence: not certified; no OData $metadata document is served - id: odata conforms: false evidence: no $metadata endpoint, no OData query syntax; filtering is JSON:API filter[] - id: fhir-r4 conforms: false - id: scim-2.0 conforms: false compliance_program: published: false certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI DSS or Cyber Essentials claim is published on street.co.uk, and no trust or compliance page exists (probed: /security, /trust, /compliance, trust.street.co.uk — all 404 or no DNS). UK GDPR obligations are addressed only inside the general privacy policy at https://street.co.uk/privacy.