generated: '2026-07-22' method: derived source: openapi/tiingo-openapi.yml + https://www.tiingo.com/documentation/general/overview standards: - id: oauth2 conforms: false evidence: 'Authentication is a single account API token (query or Authorization: Token header); no OAuth 2.0 surface.' - id: oidc conforms: false evidence: No /.well-known/openid-configuration on either host (404). - id: rfc9457-problem-details conforms: false evidence: Errors are provider-specific; no application/problem+json. - id: pagination conforms: true evidence: limit/offset pagination on the News endpoint (limit default 100, max 1000) and limit on asset search; date-window filtering (startDate/endDate) on historical endpoints. - id: rate-limit-signaling conforms: true evidence: 429 responses when hourly/daily/monthly usage limits are exceeded; limits documented in docs 1.1.3 Usage Limits. - id: csv-and-json-content-negotiation conforms: true evidence: Most REST endpoints return JSON by default and CSV via the format=csv parameter. - id: websockets conforms: true evidence: Real-time feeds at wss://api.tiingo.com/{iex,crypto,fx,boats,equity/intraday} with a documented subscribe/unsubscribe protocol and messageType contract. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both hosts.