generated: '2026-08-13' method: derived source: >- openapi/ specs in this repo plus the Sell docs (requests, errors, authentication, rate-limits) and https://www.zendesk.com/trust-center/ standards: - id: oauth2 conforms: true evidence: >- OpenAPI securitySchemes type oauth2; Zendesk documents authorization code, implicit, resource owner password credentials and refresh token grants with /oauth2/authorize, /oauth2/token, /oauth2/revoke and /oauth2/token/info. - id: rfc6750-bearer-token conforms: true evidence: 'Access via the Authorization: Bearer header, per the Sell authentication docs.' - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: https://api.getbase.com/.well-known/oauth-authorization-server returns 404. - id: openid-connect conforms: false evidence: No openid-configuration document and no id_token/openIdConnect scheme documented. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a Zendesk-specific {errors[].error, meta} envelope as application/json, not application/problem+json. See errors/zendesk-sell-problem-types.yml. - id: rfc9116-security-txt conforms: true evidence: >- PGP-signed security.txt served at https://www.zendesk.com/.well-known/security.txt (Contact, Policy, Encryption, Canonical, Expires 2027-04-16). - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support documented; no deprecation policy page. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header or equivalent replay contract is documented. See conventions/zendesk-sell-conventions.yml. - id: pagination conforms: true evidence: page/per_page (1-based, default 25, max 100) documented for all collections. - id: asyncapi conforms: false evidence: >- An event surface exists (Firehose v3 pull streams, Sync API) but no AsyncAPI document is published. See events/zendesk-sell-events.yml. - id: json-api conforms: false evidence: Custom data/meta envelope, not the JSON:API media type or structure. - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: iso8601 conforms: true evidence: All timestamps are ISO 8601 in UTC per the requests documentation. compliance_program: published: true url: https://www.zendesk.com/trust-center/ certifications: [SOC 2 Type II, ISO 27001, ISO 27018, ISO 27701, CSA STAR, FedRAMP, HIPAA, GDPR, C5] scope: Held by Zendesk, Inc. and covering Zendesk products including Sell. detail: security/zendesk-sell-trust-center.yml x-evidence: - url: https://www.zendesk.com/trust-center/ status: 200 - url: https://api.getbase.com/.well-known/oauth-authorization-server status: 404 - url: https://developer.zendesk.com/api-reference/sales-crm/errors/ status: 200