generated: '2026-07-21' method: derived source: openapi/wetravel-partner-openapi.json note: >- Cross-cutting standards conformance derived from the harvested OpenAPI and the developer hub. WeTravel is a booking + payments platform; it does not publish a formal compliance program in its developer docs, so no Compliance pointer is emitted. standards: - id: openapi-3.0 conforms: true evidence: Partner API published as OpenAPI 3.0.1 (per-endpoint definitions). - id: oauth2 conforms: false evidence: Auth is a bearer JWT issued from a refresh-token API key + X-Api-Key; no OAuth2 authorization flows. - id: bearer-jwt conforms: true evidence: securityScheme bearerAuth type http scheme bearer bearerFormat JWT. - id: rfc9457-problem-details conforms: false evidence: Errors returned as application/json, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No documented Sunset/Deprecation header support; versioning is by URI path. - id: pagination conforms: true evidence: page + per_page query parameters on list endpoints. - id: idempotency conforms: false evidence: No idempotency-key mechanism documented. - id: webhooks conforms: true evidence: Documented webhook event catalog (9 event types) with per-account endpoint management. - id: rate-limiting conforms: true evidence: Global 200 req/min limit, 429 + Retry-After header.