generated: '2026-08-13' method: searched source: openapi/ + https://developer.sovrn.com/docs/authorization + https://www.sovrn.com/trust-center/ + https://www.sovrn.com/about-sovrn/security/ standards: - id: api-key-auth conforms: true evidence: All authenticated endpoints use apiKey security schemes — a site-specific Secret Key in the Authorization header ("secret {SECRET_KEY}") or a public API key `key` query parameter (Link Check / Bid Check). - id: oauth2 conforms: false evidence: No oauth2 securitySchemes in any harvested OpenAPI; no OAuth documented on the Sovrn Developer Center for Commerce APIs. - id: oidc conforms: false evidence: No openIdConnect schemes; /.well-known/openid-configuration returns 404 on all API hosts. - id: rfc9457-problem-details conforms: false evidence: Error responses are application/json envelopes (Google-style error envelope on Campaigns; message/exception/status/timestamp on Link Check) — no application/problem+json. - id: rate-limiting-documented conforms: true evidence: Published limits (1/60s reports, 1/10s merchant summaries) with 429 responses declared in the Merchant Group Summaries OpenAPI. - id: pagination conforms: true evidence: Merchant Group Summaries API paginates with page/pageSize parameters and totalItems/perPage response fields; Reports APIs window by date instead. - id: idempotency-keys conforms: false evidence: No idempotency-key contract documented. - id: mcp conforms: true evidence: Official hosted Commerce MCP server (beta) at https://mcp.sovrn.com/commerce with published tools, a prompt, and a resource (https://developer.sovrn.com/docs/mcp). - id: llms-txt conforms: true evidence: Docs host publishes https://developer.sovrn.com/llms.txt with per-endpoint OpenAPI definitions. - id: rfc9116-security-txt conforms: partial evidence: The operator serves an RFC 9116 security.txt at https://www.sovrn.com/.well-known/security.txt (HTTP 200) with Contact, Policy, Canonical and Preferred-Languages fields — but its Expires value is 2025-10-14T07:00:00.000Z, which had already passed at the 2026-08-13 probe. RFC 9116 says an expired file should not be relied upon. - id: tag-platinum conforms: true evidence: '"Sovrn maintains Trustworthy Accountability Group (TAG) Platinum status." (https://www.sovrn.com/about-sovrn/security/) — the only named industry certification on the public trust surface.' - id: gdpr conforms: true evidence: Sovrn publishes a Data Processing Addendum (Sovrn as Data Importer), Standard Contractual Clause selections and addendum, and a subprocessor list at https://www.sovrn.com/legal/subprocessors/ (https://www.sovrn.com/trust-center/). - id: ccpa conforms: true evidence: CCPA Metrics published at https://www.sovrn.com/privacy-policy/ccpa-metrics/ plus a Your Privacy Choices policy center (https://www.sovrn.com/trust-center/). - id: soc2 conforms: false evidence: No SOC 2 report, ISO 27001 certificate, PCI DSS attestation or downloadable audit evidence is named or offered on the Trust Center or the security page; the security page refers to "our industry certifications" without naming any beyond TAG. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and the legacy /.well-known/agent.json return 404 on developer.sovrn.com, www.sovrn.com, sovrn.com, mcp.sovrn.com and api.viglink.com (probed 2026-08-13). No agent card is published. - id: openapi-operationids conforms: false evidence: Only 4 of 16 harvested operations declare an operationId (link, getBid, campaigns, get_product_recommendations); the eight Real-Time Reports operations, both Merchant Group Summaries operations, Product Promo Codes and Price Comparisons declare none, so MCP tools cannot be resolved back to named contract operations. See mcp/viglink-tool-crosswalk.yml. - id: sdk-distribution conforms: false evidence: No first-party package on npm, PyPI, RubyGems, Packagist, Maven Central, NuGet, crates.io or pkg.go.dev (all probed 2026-08-13). The only first-party client library is the unversioned CDN script https://cdn.viglink.com/api/vglnk.js.