overlay: 1.0.0 info: title: API Evangelist enhancements for the TrustArc Guardian API version: 1.0.0 extends: openapi/trustarc-guardian-openapi.yml x-provenance: generated: '2026-08-27' method: generated source: >- Derived from analysis of openapi/_original/trustarc-guardian-openapi.json, which was harvested verbatim from https://login.truste.com/v3/api-docs on 2026-08-27. This overlay records API Evangelist annotations only; it never mutates the harvested contract. actions: - target: $.info update: x-apievangelist-slug: trustarc x-apievangelist-harvested-from: https://login.truste.com/v3/api-docs x-apievangelist-harvested-on: '2026-08-27' x-apievangelist-product: TrustArc platform identity and access service ("Guardian") x-apievangelist-ownership-evidence: >- servers[] declares https://login.truste.com, the host TrustArc's own API guides name as the Auth Server; truste.com is TrustArc's legacy TRUSTe domain and login.truste.com is already listed as the TrustArc Login property. The same document is served from https://login.trustarc.com/v3/api-docs. x-apievangelist-spec-quality: operations: 276 paths: 205 schemas: 158 operations_with_unique_operation_id: 276 operations_with_summary: 6 operations_with_description: 0 operations_with_4xx_response: 1 operations_with_5xx_response: 5 note: >- Generated by springdoc with default settings. operationIds are machine-assigned (get_1, update_2, delete_3), almost no operation carries a summary or description, and error responses are essentially undocumented. The contract is complete on shape and thin on meaning. - target: $.servers update: - url: https://login.truste.com description: Production identity host (declared by the provider). - url: https://login.trustarc.com description: >- Serves the identical Guardian document (verified 2026-08-27, HTTP 200). Recorded by API Evangelist; not declared in the harvested spec. - target: $.info update: x-apievangelist-domain-standard: id: scim-2.0 conformant: true evidence: >- /external/api/v2/scim/Users, /Groups, /ServiceProviderConfig, /Schemas and /ResourceTypes are declared, and the PATCH body is the SCIM PatchOp message urn:ietf:params:scim:api:messages:2.0:PatchOp. x-apievangelist-auth-note: >- securitySchemes declares only the implicit flow, but the provider's published /.well-known/oauth-authorization-server advertises authorization_code, client_credentials, refresh_token and token-exchange, and every TrustArc API guide documents client_credentials. The spec understates the real auth surface. x-apievangelist-idempotency: none x-apievangelist-pagination: spring-data-page (page, size, sort)