generated: '2026-07-21' method: derived source: openapi/terminal-use-openapi-original.json + https://docs.terminaluse.com standards: - id: openapi-3.1 conforms: true evidence: Provider publishes an OpenAPI 3.1.0 document at docs.terminaluse.com/openapi.json (151 operations). - id: http-bearer-auth conforms: true evidence: Documented Authorization Bearer token (RFC 6750 style) auth; env var TERMINALUSE_API_KEY. - id: sse-streaming conforms: true evidence: Task output streamed via Server-Sent Events at GET /tasks/{id}/stream. - id: idempotency-key conforms: true evidence: Idempotency-Key request header supported on file-upload operations. - id: oauth2 conforms: false evidence: No oauth2 securityScheme declared in the OpenAPI; end-user access is bearer API key. (An internal OAuth/CLI-auth flow backs `tu login`.) - id: rfc9457-problem-details conforms: false evidence: Errors use the FastAPI validation envelope (application/json HTTPValidationError), not application/problem+json. - id: json-api conforms: false evidence: No JSON:API media type or document structure. - id: webhooks conforms: true evidence: Inbound webhook delivery with webhook-key verification (see asyncapi/terminal-use-webhooks.yml). compliance: published_certifications: [] note: >- No public trust center or named certifications (SOC 2 / ISO 27001 / etc.) were found; no `Compliance` pointer is emitted (would be fabrication).