generated: '2026-09-11' method: searched source: live probes of Zillapi's well-known surface, OpenAPI, and docs, re-run 2026-09-11 (first run 2026-08-09) reverified: '2026-09-11' standards: - id: openapi-3.1 conforms: true evidence: >- https://zillapi.com/openapi.json returns a valid OpenAPI 3.1.0 document (Content-Type application/openapi+json) with 28 paths, 29 operations, 20 component schemas, and a unique operationId on every operation. - id: oauth2 conforms: true evidence: >- Authorization-code flow published at /.well-known/oauth-authorization-server with authorization, token, revocation and registration endpoints. - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported is ["S256"] and the MCP server card sets pkce_required true. - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with valid metadata on both hosts. - id: rfc9728-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 with resource, authorization_servers and scopes_supported on zillapi.com, www.zillapi.com and api.zillapi.com. Re-checked 2026-09-11: `resource` is now https://api.zillapi.com/mcp (was the bare host), which is the correct RFC 9728 resource identifier for the MCP endpoint it protects. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://api.zillapi.com/oauth/register; the metadata names RFC 7591 explicitly. - id: rfc9727-api-catalog conforms: true evidence: >- /.well-known/api-catalog returns 200 with Content-Type application/linkset+json and a linkset carrying service-desc, service-doc, service-meta, status and mcp-server relations. - id: mcp conforms: true evidence: >- Hosted MCP server at https://api.zillapi.com/mcp, streamable-http transport, protocolVersion 2025-06-18, with a SEP-1649 server card at /.well-known/mcp/server-card.json. - id: agent-skills-discovery conforms: true evidence: >- /.well-known/agent-skills/index.json conforms to the Cloudflare Agent Skills Discovery RFC v0.2.0 schema, listing four skills with hosted SKILL.md URLs and sha256 digests. - id: llms-txt conforms: true evidence: https://zillapi.com/llms.txt returns 200 text/plain in llms.txt format, plus an llms-full.txt. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {error:{code,message,request_id}} envelope with media type application/json, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both zillapi.com and api.zillapi.com. - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on both hosts. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 on both hosts (verified against a control URL that also 404s, so these are real misses, not SPA catch-alls). - id: asyncapi conforms: false evidence: >- No AsyncAPI document published; /asyncapi.yaml and /asyncapi.json 404. Webhooks are documented in prose only and the OpenAPI 3.1 `webhooks` object is empty. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy and no Sunset/Deprecation header support documented. - id: rfc4180-csv conforms: true evidence: >- The output-formats doc states CSV cells containing commas, quotes or newlines are quoted and embedded quotes doubled per RFC 4180. - id: ndjson conforms: true evidence: '?format=ndjson returns Content-Type application/x-ndjson with an X-Row-Count header.' - id: hmac-webhook-signing conforms: true evidence: >- X-Zillow-Signature carries t=,v1=."> with a documented 300-second replay window and constant-time comparison in all published verification samples. - id: aauth-resource conforms: false evidence: >- /.well-known/aauth-resource.json returns 404 on zillapi.com, www.zillapi.com and api.zillapi.com (checked 2026-09-11). No Agent Auth resource document is published; the provider's agent-auth affordances live inside the RFC 8414 metadata as a non-standard `agent_auth` object instead. - id: graphql conforms: false evidence: 'POST/GET https://api.zillapi.com/graphql returns 404 not_found (checked 2026-09-11). No GraphQL surface.' - id: soap-wsdl conforms: false evidence: >- No SOAP contract. https://api.zillapi.com/?wsdl returns 200 but the body is the REST service descriptor JSON, not a WSDL; https://zillapi.com/?wsdl returns the marketing HTML shell. The query string is simply ignored by both hosts (checked 2026-09-11). - id: grpc-protobuf conforms: false evidence: >- No .proto published anywhere in the provider's GitHub account and none referenced in the docs. CORRECTED 2026-09-11: the previous wording claimed zillow-skills was "the only public repo", which was false — https://api.github.com/users/ZeroPointRepo/repos lists 30 public repositories, six of them Zillapi-branded (zillow-api, zillow-mcp, zillow-plugin, zillow-skills, n8n-nodes-zillapi, property-scanner). All six were enumerated on 2026-09-11 and none contains a .proto or any gRPC service definition. - id: mcp-registry-server-json conforms: true found: '2026-09-11' evidence: >- ZeroPointRepo/zillow-mcp publishes a server.json validating against https://static.modelcontextprotocol.io/schemas/2025-09-29/server.schema.json — reverse-DNS name com.zillapi/zillow-mcp, version 1.0.0, websiteUrl https://zillapi.com, icons, and a remotes[] entry {type: streamable-http, url: https://api.zillapi.com/mcp}. Saved verbatim to mcp/zillapi-server.json. This is a SECOND, independent MCP discovery document alongside the SEP-1649 server card at /.well-known/mcp/server-card.json, and the two agree on the endpoint. - id: agent-plugins-1.0.0 conforms: true found: '2026-09-11' evidence: >- ZeroPointRepo/zillow-plugin ships plugin.json and mcp.json declaring https://agent-plugins.org/schemas/1.0.0/plugin.schema.json and .../1.0.0/mcp.schema.json, with a marketplace.json and parallel .claude-plugin/ and .cursor-plugin/ directories for the Claude and Cursor plugin marketplace formats. Author Zillapi , MIT. - id: rfc9116-security-txt-www conforms: false evidence: /.well-known/security.txt returns 404 on www.zillapi.com as well as the apex and API hosts. - id: npm-registry-distribution conforms: true found: '2026-09-11' evidence: >- n8n-nodes-zillapi v0.1.2 is published to the public npm registry (2026-08-11) by Zero Point Studio with homepage https://zillapi.com, declaring the n8n-community-node-package keyword and an n8n manifest block (apiVersion 1, one credential type, one node). It is the provider's only distribution with real registry metadata. - id: domain-standard-real-estate conforms: false applicable: true evidence: >- Reward-only check, honestly negative. Zillapi's market has real domain standards — RESO Data Dictionary and the RESO Web API (an OData 4.0 profile) are the U.S. residential-real-estate contract standards — and the Zillapi OpenAPI declares NONE of them. There is no $metadata surface, no OData query grammar, no RESO field naming (the property object uses Zillow's own `zpid`, `resoFacts`, `zestimate` shape, and a `resoFacts` sub-resource is a passthrough of Zillow's payload, not a RESO Data Dictionary contract). A buyer who already speaks RESO needs a bespoke connector for Zillapi. Recorded as measured, not penalised. checked: '2026-09-11' compliance_program: published: false certifications: [] trust_center: null probes: - {url: 'https://zillapi.com/trust/', status: 404, checked: '2026-09-11'} - {url: 'https://zillapi.com/security/', status: 404, checked: '2026-09-11'} - {host: 'trust.zillapi.com', status: NXDOMAIN, checked: '2026-09-11'} - {host: 'security.zillapi.com', status: NXDOMAIN, checked: '2026-09-11'} notes: >- Re-checked 2026-09-11, unchanged. No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR posture is published, and no trust or security center exists. No `Compliance` and no `TrustCenter` pointer is emitted, and no security/zillapi-trust-center.yml is written — conformance to technical standards is not a published compliance program, and an artifact asserting one would be a false claim.