name: Treasure Data Standards Conformance description: >- Which cross-cutting and industry standards the Treasure Data (Treasure AI) API estate actually conforms to, with the evidence for each. Derived from the eight published OpenAPI descriptions and the live /.well-known/ probes, and searched against the provider's published security and compliance posture. specificationVersion: '0.1' generated: '2026-08-13' method: searched source: >- openapi/*.yml, well-known/treasure-data-well-known.yml, well-known/treasure-data-openid-configuration.json, https://www.treasure.ai/security/, https://docs.treasure.ai/mcp standards: - id: openapi-3 conforms: true evidence: >- Eight OpenAPI descriptions published and downloadable from https://docs.treasure.ai/_bundle/apis/ — versions 3.0.0, 3.0.1 and 3.0.3. 405 operations total. - id: oauth2 conforms: true evidence: >- RFC 6749 authorization_code + refresh_token grants advertised at https://api.treasuredata.com/.well-known/oauth-authorization-server; issuer https://console.us01.treasuredata.com. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 200 application/json at /.well-known/oauth-authorization-server on api.treasuredata.com. - id: oidc conforms: true evidence: >- OpenID Connect discovery document served at /.well-known/openid-configuration with jwks_uri, userinfo_endpoint, RS256 id_token signing and the openid/email/profile scopes. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [plain, S256].' - id: saml-sso conforms: true evidence: >- Identity federation with per-user SSO enforcement documented at https://docs.treasure.ai/apis/td-api/identity-federation; multiple IdPs supported since April 2023. - id: json-api conforms: partial evidence: >- The cdp-api spec states "For historical reasons there are REST API endpoints and JSON:API endpoints. JSON:API endpoints are located under /entities", and ships JsonApiValidationError, JsonApiNotFoundError, JsonApiConflictError and six sibling error schemas. However no operation declares the application/vnd.api+json media type, so the resource/error shapes follow JSON:API while the content negotiation does not. - id: rfc9457-problem-details conforms: false evidence: Zero occurrences of application/problem+json across all eight specs. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation response header is declared in any spec, and no deprecation policy page exists. Deprecation is marked inside the spec (20 elements) and narrated in the monthly release notes. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt 404s on docs.treasure.ai, www.treasure.ai and treasuredata.com, and returns the console login HTML (soft 200) on api.treasuredata.com. - id: cursor-pagination conforms: partial evidence: >- cdp-api uses opaque cursors (page[after], page[size], pagination.nextPage); Treasure Workflow returns a next-page URL; the TD API uses a PaginatedResult envelope; some CDP endpoints take a numeric page. Four shapes, no single estate-wide convention. - id: idempotency conforms: partial evidence: >- idempotent_key on createTable, createTableWithTableType and transferTable, plus a domain_key on job submission with a dedicated GET /job/status_by_domain_key/{domain_key} lookup. No global Idempotency-Key header; the CDP, LLM, Workflow, DWH and ingestion APIs have none. - id: rate-limit-headers conforms: partial evidence: >- Only llm-api declares a 429 with a retry-after header. No RateLimit-* or X-RateLimit-* headers anywhere. - id: mcp conforms: true evidence: >- Live remote MCP server at https://docs.treasure.ai/mcp answered initialize with protocolVersion 2025-06-18 and returned 6 tools anonymously; the official product server @treasuredata/mcp-server 0.4.5 exposes 23 tools over stdio. - id: llms-txt conforms: true evidence: >- /llms.txt served 200 text/plain on both www.treasure.ai and docs.treasure.ai; the docs index is ~950 KB and links a .md variant of every documentation page. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or the legacy /.well-known/agent.json on any host. - id: asyncapi conforms: false evidence: >- No AsyncAPI document published. Treasure AI documents outbound webhook activations but ships no event contract. See asyncapi/treasure-data-webhooks.yml. - id: fhir conforms: false - id: scim conforms: false evidence: >- User provisioning is bespoke (/user/*, /access_control/users/*) rather than SCIM 2.0, despite SAML SSO being supported. - id: odata conforms: false - id: fapi conforms: false - id: psd2 conforms: false compliance: published: true url: https://www.treasure.ai/security/ detail: security/treasure-data-trust-center.yml certifications: - SOC 2 - ISO 27001 - ISO 27017 - ISO 27018 - HIPAA - GDPR - CSA STAR summary: conforms: 9 partial: 4 does_not_conform: 9 notes: - >- The strongest conformance story here is identity — OAuth 2.0, OIDC discovery, PKCE and SAML SSO are all real and all discoverable without credentials. The weakest is runtime semantics: no problem details, no sunset headers, no rate-limit headers, no security.txt, and four incompatible pagination styles across five APIs.