generated: '2026-09-04' method: searched source: https://developers.welcomekit.co/ (Authentication, Scopes, Errors and Status, Jobs, FAQ), https://solutions.welcometothejungle.com/en/privacy-policy, and live probes of the API host 2026-09-04 api: Welcome to the Jungle Solutions API summary: 'Standards posture of the Welcome to the Jungle Solutions API, asserted only where the published documentation or a live response actually carries the signature. The documented REST API borrows OAuth 2.0 vocabulary without implementing the protocol''s discovery or grant surface, uses a vendor error envelope rather than RFC 9457, and declares no interoperability standard for the recruiting market. The one substantial published compliance program is data protection: a GDPR / UK GDPR / DPA 2018 privacy program with a named Data Protection Officer, identified supervisory authorities and Standard Contractual Clauses for transfers.' conformance: - id: oauth2 conforms: false partial: true evidence: https://developers.welcomekit.co/authentication note: 'Uses OAuth 2.0 bearer-token transport and the OAuth scope model (citing draft-ietf-oauth-v2-31 §3.3), but publishes no authorization endpoint, no token endpoint, no grant type and no refresh flow. Tokens are issued administratively through a help form. This is OAuth vocabulary over an out-of-band credential, not an OAuth 2.0 authorization server.' - id: rfc8414-oauth-metadata conforms: false evidence: 'Probed 2026-09-04: /.well-known/oauth-authorization-server returns 404 on www.welcomekit.co, api.welcomekit.co and developers.welcomekit.co.' - id: oidc conforms: false evidence: 'Probed 2026-09-04: /.well-known/openid-configuration returns 404 on every Welcome to the Jungle host.' - id: rfc9457 conforms: false evidence: https://developers.welcomekit.co/errors-and-status note: 'Errors are a two-field vendor envelope {error, error_description} served as application/json. No type URI, no title/detail/instance members, no application/problem+json media type.' - id: pagination conforms: true evidence: https://developers.welcomekit.co/jobs-api/jobs/list-jobs note: 'Page-number pagination via page and per_page query parameters, with the total count exposed in an X-Total response header (documented at https://developers.welcomekit.co/faq). No Link header and no cursor.' - id: idempotency conforms: false evidence: 'The complete documentation set contains no idempotency mechanism; see conventions/welcome-to-the-jungle-conventions.yml (coverage: none).' - id: rest conforms: true partial: true evidence: https://developers.welcomekit.co/ note: 'Resource-oriented URI design with GET/POST/PUT over JSON and a documented 405 for wrong methods. No DELETE anywhere on the surface, no hypermedia, no conditional requests (ETag / If-Match).' - id: cors conforms: true evidence: 'Observed live 2026-09-04 on https://www.welcomekit.co/api/v1/external/jobs — access-control-allow-origin: *, access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS, access-control-allow-headers including Authorization.' - id: gdpr conforms: true evidence: https://solutions.welcometothejungle.com/en/privacy-policy note: 'The privacy policy states it is drawn up in compliance with GDPR (EU 2016/679), UK GDPR and the UK Data Protection Act 2018; names an appointed Data Protection Officer reachable at privacy@welcometothejungle.com; identifies CNIL (France) and the ICO (UK) as supervisory authorities; and states that international transfers rely on adequacy decisions or Standard Contractual Clauses, with copies of the transfer instruments available on request.' - id: graphql conforms: true evidence: https://api.welcomekit.co/api/v1/graphql note: 'A spec-compliant GraphQL service with introspection enabled (95 types, 36 queries, 11 mutations, captured 2026-09-04 into graphql/welcome-to-the-jungle.graphql). Enforces a query-complexity budget of 150. Undocumented on the developer portal.' - id: scim conforms: false evidence: 'No urn:ietf:params:scim:schemas:* URN, no /Users or /Groups resource and no SCIM media type appears anywhere in the published API surface.' - id: odata conforms: false evidence: No $metadata surface and no OData query grammar. domain_standard: declared: false candidates_checked: - standard: HR Open Standards (HR-XML) result: not-declared evidence: 'No HR Open message type, namespace or schema reference appears in the documentation. The job payload is a bespoke Welcome to the Jungle shape (name, profile, contract_type, experience_level, education_level, remote, salary object, cms_sites_references).' - standard: schema.org/JobPosting result: not-declared evidence: 'The API returns bare vendor JSON with no JSON-LD, @context or @type. The consumer job pages on www.welcomekit.co / welcometothejungle.com render client-side and served no application/ld+json block when fetched 2026-09-04, so no structured-data signature could be observed either.' - standard: SCIM result: not-declared evidence: Not applicable to this surface — the API carries candidates and job offers, not identity provisioning. note: 'Recruiting has a nominal interoperability standard (HR Open Standards) with, per the rubric''s own 2026-08-17 census, zero detectable adoption across the catalog. Welcome to the Jungle declares none, and this check is reward-only, so nothing is asserted here to fill the slot. The enumerations the API does publish through GET /jobs/dependencies (contract_types, experience_levels, education_levels, remote_levels, salary_currencies, salary_periods) are a vendor vocabulary, not a standard.' certifications: security: [] note: 'No ISO 27001, SOC 2, PCI DSS, HIPAA or FedRAMP claim was found on the developer, product, legal or privacy pages, and no trust center exists (probed 2026-09-04: trust.welcometothejungle.com does not resolve; probe-security-programs.py returned vdp=none trust=none). The company holds a B Corp certification from B Lab, which is a social/environmental impact certification and is deliberately not recorded here as a security or compliance certification.'