generated: '2026-08-13' method: derived source: openapi/_original/worldnewsapi-openapi-original.json docs: https://worldnewsapi.com/docs/ description: >- Which cross-cutting standards the World News API actually conforms to, derived from the provider's published OpenAPI 3 document and its documentation. World News API is a small read-only data API with API-key authentication; most identity, security-profile and enterprise interchange standards are simply not in play, and are recorded as false rather than omitted so the absence is legible. No compliance certification or trust program is published, so no Compliance pointer is emitted. standards: - id: openapi-3.0 conforms: true evidence: >- Provider-published OpenAPI 3.0.0 document at https://raw.githubusercontent.com/ddsky/world-news-api-clients/main/world-news-api-openapi-3.json, linked from https://worldnewsapi.com/sdks/. Nine operations, all with operationId, summary, description, tags and 200 examples. - id: mcp conforms: true evidence: >- First-party MCP server world-news-api-mcp 1.0.0 answering protocolVersion 2024-11-05 with eight tools over stdio; verified live 2026-08-13. See mcp/worldnewsapi-mcp.yml. - id: rss-2.0 conforms: true evidence: The newsWebsiteToRSSFeed operation (GET /feed.rss) emits RSS 2.0 XML. - id: iso-3166 conforms: true evidence: source-country parameters are documented as ISO 3166 alpha-2 codes; see https://worldnewsapi.com/docs/country-codes/. - id: iso-639-1 conforms: true evidence: language parameters are documented as ISO 639-1 codes; see https://worldnewsapi.com/docs/language-codes/. - id: http-status-semantics conforms: true evidence: >- Distinguishes 401 (bad key), 402 (quota exhausted), 403 (plan does not include the feature) and 429 (rate/concurrency exceeded) rather than collapsing them; all four are declared on every operation. - id: api-key-auth conforms: true evidence: components.securitySchemes apiKey (query api-key) and headerApiKey (header x-api-key), applied globally via security[]. - id: offset-limit-pagination conforms: true evidence: search-news exposes offset and number and returns offset, number and available. - id: oauth2 conforms: false evidence: No oauth2 security scheme in the specification; the docs state explicitly that no OAuth or token refresh is required. - id: oidc conforms: false evidence: No openIdConnect scheme; /.well-known/openid-configuration returns 404 on api.worldnewsapi.com. - id: rfc9457-problem-details conforms: false evidence: No error response declares a body or content type; application/problem+json is never used. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on the API host and a soft-404 HTML homepage on the website host. See well-known/worldnewsapi-well-known.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header is documented; deprecations are prose entries on the changelog page. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any host. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on either host. - id: asyncapi conforms: false evidence: No event, streaming, or webhook surface is published, so there is nothing for AsyncAPI to describe. - id: json-api conforms: false evidence: Responses are plain JSON objects with no JSON:API document structure. - id: odata conforms: false - id: scim conforms: false - id: fapi conforms: false - id: idempotency-key conforms: false evidence: No idempotency header; every operation is a GET. See conventions/worldnewsapi-conventions.yml. - id: ratelimit-headers-draft conforms: false evidence: >- The provider signals budget with proprietary X-API-Quota-Request / X-API-Quota-Used / X-API-Quota-Left headers rather than the IETF RateLimit-* fields. Real runtime signal, non-standard spelling. compliance_program: published: false certifications: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR certification is claimed anywhere on the site. probe-security-programs.py found no trust center and no vulnerability-disclosure program on 2026-08-13. Terms and the privacy policy are published as a single combined page at https://worldnewsapi.com/terms/. sources: - https://raw.githubusercontent.com/ddsky/world-news-api-clients/main/world-news-api-openapi-3.json - https://worldnewsapi.com/docs/ - https://worldnewsapi.com/docs/authentication/ - https://worldnewsapi.com/docs/quotas-and-rate-limiting/