generated: '2026-08-29' method: probed source: probe:https://api.swiftconnect.io + https://swiftconnect.io/developer-api/ note: >- Assessed without a machine-readable contract — SwiftConnect publishes no OpenAPI and its reference is password-protected. Only standards that could be established from the provider's own published examples or from live response behaviour are marked true. Everything unestablished is recorded as such rather than guessed, and the domain-standard slot is left empty because no physical-access standard (OSDP, PSIA, ONVIF, SIA, BACnet, Apple/Google wallet credential profiles) is declared in any surface we can read. standards: - id: json-rest conforms: true evidence: 'Responses are application/json over HTTPS REST resources (probe: /credentials).' - id: bearer-token-rfc6750 conforms: true evidence: >- Authorization: Bearer credentials, per the provider's published curl examples and the live 401 "Invalid JWT" response. - id: jwt-rfc7519 conforms: true evidence: The API names its token format as a JWT in its own 401 error message. - id: vendor-media-type-versioning conforms: true evidence: 'Accept: application/vnd.swiftconnect.v2+json, per the provider''s published examples.' - id: hsts-rfc6797 conforms: true evidence: 'strict-transport-security: max-age=31536000; includeSubDomains on api.swiftconnect.io.' - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom {code,message,client_error_code} envelope with content-type application/json, not application/problem+json. - id: oauth2 conforms: unknown evidence: >- No authorization-server metadata is served (/.well-known/oauth-authorization-server 404s on the API host). How the JWT is issued is documented only behind the password wall. - id: oidc conforms: unknown evidence: /.well-known/openid-configuration returns 404 on every reachable SwiftConnect host. - id: scim conforms: unknown evidence: >- Not established. SwiftConnect markets directory/IdP integration for people and access provisioning, which is the classic SCIM use case, but no /scim/v2 route responds on api.swiftconnect.io and no SCIM schema URN appears in anything public. - id: rate-limit-retry-after conforms: true evidence: Retry-After is explicitly exposed via access-control-expose-headers. domain_standards: [] domain_standards_note: >- Reward-only slot, left empty on purpose. The physical-access market does have standards (OSDP / SIA, ONVIF, PSIA, and the wallet credential profiles SwiftConnect brokers), but none is DECLARED in a contract we can read, and a marketing mention would not qualify. No Compliance pointer is emitted: no certification program (SOC 2, ISO 27001) is published on any reachable page.