generated: '2026-07-21' method: derived source: >- Derived from openapi/usertesting-results-v2-openapi.yml, openapi/usertesting-legacy-v1-openapi.yml, the Authorization guide (https://developer.usertesting.com/docs/authorization), the Okta authorization-server metadata saved in well-known/, and the trust center (https://trust.usertesting.com/). standards: - id: oauth2 conforms: true evidence: >- OAuth 2.0 client_credentials grant against https://auth.usertesting.com/oauth2/aus1p3vtd8vtm4Bxv0h8/v1/token (Okta); APIs accept the resulting bearer JWT (OpenAPI securityScheme http/bearer, bearerFormat JWT). - id: rfc8414-authorization-server-metadata conforms: true evidence: >- /.well-known/oauth-authorization-server returns 200 on the Okta custom authorization server (saved as well-known/usertesting-oauth-authorization-server.json). - id: oidc conforms: true evidence: >- /.well-known/openid-configuration returns 200 on the same authorization server (saved as well-known/usertesting-openid-configuration.json); openid/profile/email scopes supported. The APIs themselves use plain OAuth2 bearer tokens, not OIDC identity flows. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere in the published OpenAPI; v1 uses a custom {errorCode, errorMessage} envelope and v2 documents status codes only. - id: pagination conforms: true evidence: >- Offset/limit query parameters with a meta.pagination {limit, offset, totalCount} response envelope on GET /api/v2/sessionResults. - id: idempotency-key conforms: false evidence: Published surface is read-only GET; no Idempotency-Key contract documented. - id: rate-limit-signaling conforms: true evidence: >- x-ratelimit-limit / x-ratelimit-remaining / x-ratelimit-reset response headers and documented 429 (10 requests/minute) in the v2 OpenAPI. - id: webvtt conforms: true evidence: >- GET /api/v2/sessionResults/{sessionId}/transcript returns transcripts in Web Video Text Tracks (WebVTT) format. - id: hsts conforms: true evidence: >- Strict-Transport-Security max-age=31536000; includeSubDomains documented as a response header in the v2 OpenAPI. - id: soc2 conforms: true evidence: SOC 2 item on https://trust.usertesting.com/ (SafeBase trust center). - id: iso27001 conforms: true evidence: >- ISO 27001:2022 accredited third-party audit by CoalFire; certificate award document dated 2025-12-05 listed on the trust center. - id: iso27701 conforms: true evidence: ISO 27701 certificate award document listed on the trust center. - id: csa-star conforms: true evidence: CSA STAR item on the trust center. - id: gdpr conforms: true evidence: GDPR item on the trust center and GDPR policy page on usertesting.com. - id: hipaa conforms: true evidence: HIPAA item on the trust center. - id: ccpa conforms: true evidence: CCPA item on the trust center. - id: fhir conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false