generated: '2026-07-25' method: searched source: openapi/telia-lso-sonata-site-management.yml also_searched: - https://lso.teliacompany.com/apis - https://camara.teliacompany.com/ - https://cdn.messaging.teliacompany.com/documents/developer/index.html - https://tunnistus.telia.fi/.well-known/openid-configuration notes: >- Telia's standards lineage is unusually explicit for a carrier - the one anonymously downloadable specification states in its own description that it "forms part of MEF 122", implements MEF 79 business requirements, and is derived from TM Forum TMF674 under Apache 2.0. What Telia does NOT publish is any certification evidence: no TM Forum Open API conformance certificate and no CAMARA conformance artefact were found. Design lineage is documented; certification is unevidenced. No Compliance pointer is emitted for this file because Telia publishes no certification programme of its own for these APIs. standards: - id: mef-122 conforms: true evidence: the harvested OpenAPI info.description states "This file forms part of MEF 122" scope: LSO Sonata Geographic Site Management - id: mef-79 conforms: true evidence: the harvested OpenAPI states it "implements Business Requirements described in MEF 79" scope: LSO Sonata Geographic Site Management - id: tmforum-tmf674-geographic-site conforms: true evidence: the spec is derived from the TM Forum Geographic Site API (TMF674 v4.0.0), modified by MEF Forum, Apache 2.0 licensed scope: LSO Sonata Geographic Site Management - id: tmforum-tmf673-geographic-address conforms: partial evidence: named as the template for the LSO Sonata Geographic Address Management API on the public LSO portal; specification not retrievable anonymously - id: tmforum-tmf679-product-offering-qualification conforms: partial evidence: named as the template for the LSO Sonata Product Offering Qualification API on the public LSO portal - id: tmforum-tmf648-quote conforms: partial evidence: named as the template for the LSO Sonata Quote Management API on the public LSO portal - id: tmforum-tmf622-product-order conforms: partial evidence: named as the template for the LSO Sonata Order Management API on the public LSO portal - id: tmforum-open-api-conformance-certification conforms: false evidence: no TM Forum conformance certificate found for Telia Company - id: camara conforms: partial evidence: Telia operates a branded CAMARA portal naming Quality on Demand and Device Location, but the anonymous catalog returns zero API documents, so no CAMARA specification, scope or endpoint could be verified - id: gsma-open-gateway conforms: true evidence: Telia's own CAMARA portal copy describes the programme as GSMA Open Gateway; recorded from first-party published copy, not from the GSMA roster (which returns HTTP 403 to automated clients) - id: oauth2 conforms: true evidence: OpenAPI securitySchemes declare oauth2 clientCredentials flows for both production and test environments - id: oauth2-client-credentials conforms: true evidence: token endpoints at /v4/oauth/client_credential/accesstoken on both api-garden hosts - id: oidc-discovery conforms: true evidence: https://tunnistus.telia.fi/.well-known/openid-configuration returns 200 anonymously with issuer https://tunnistus.telia.fi/uas scope: Telia Tunnistus identification broker (Telia Finland) - id: oidc-ciba conforms: false evidence: the Tunnistus discovery document advertises no backchannel_authentication_endpoint; CIBA is the grant CAMARA specifies for network-based authorization, so its absence is material - id: saml2-bearer-grant conforms: true evidence: urn:ietf:params:oauth:grant-type:saml2-bearer listed in grant_types_supported on Tunnistus - id: rfc9457-problem-details conforms: false evidence: error responses use the TM Forum code/reason/message object as application/json, never application/problem+json - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any Telia host probed - id: rfc8594-sunset-header conforms: false evidence: no deprecation or sunset policy or header documented - id: rfc9727-api-catalog conforms: false evidence: no /.well-known/api-catalog on any Telia host probed - id: smpp-3.4 conforms: partial evidence: Telia documents the Bulk Messaging SMPP interface against SMPP 3.4 (interface_version 0x34) with an explicit per-field FC/PC/NC compliance table and three vendor-specific command status codes - id: e164 conforms: true evidence: MSISDNs required in E.164 form with + prefix and country code, max 15 digits - id: iso-8601 conforms: true evidence: all Bulk Messaging timestamps are ISO-8601, example 2024-07-01T14:00:00.000Z - id: grpc-proto3 conforms: true evidence: proto/telia-ace-audio-stream-forwarding-v1.proto, package ace.audio_stream_forwarding.v1, bidirectional streaming service - id: mutual-tls conforms: true evidence: the ACE Audio Stream Forwarding API authenticates with client certificates - id: jwt-hs256-request-signing conforms: true evidence: ACE Knowledge contact-method webhooks sign requests with an HMAC SHA256 JWT in X-ACE-Signature carrying a content_hash claim - id: 3gpp-nef-scef conforms: false evidence: no NEF or SCEF exposure surface is published; 5G exposure reaches developers through Nokia Network as Code in the Telia Finland Sirius programme - id: iso-27001 conforms: partial evidence: Telia's public Supplier Security Directive states alignment with ISO 27001/27002:2022, but this is a requirement Telia places on suppliers rather than a published certification of Telia's own API platform source: https://www.teliacompany.com/assets/u5c1v3pt22v8/3hKQp1pJJJZ4EpquWVZ9rk/17d86f87acc6cf544b38f1a70ce2f069/Supplier_Security_Directive_8.0_2024-09-11.pdf - id: graphql conforms: false evidence: no /graphql surface; Apigee portals report graphqlSchema null for every catalogued API - id: asyncapi conforms: false evidence: three real event surfaces, none described with AsyncAPI (see asyncapi/telia-webhooks.yml)