| Area | Standard | Notes |
|---|---|---|
| Contract | OpenAPI 3.1 | The API reference and client libraries are generated from it. |
| Auth | OAuth 2.0 client credentials (RFC 6749) | Scoped tokens, one client per environment. |
| Errors | RFC 9457 Problem Details | application/problem+json, plus code, param and request_id. |
| Idempotency | IETF Idempotency-Key | Keys are kept for 24 hours. A replay returns Idempotent-Replayed: true. |
| Tracing | W3C Trace Context | traceparent is accepted. Every response carries OJ-Request-Id. |
| Webhooks | Standard Webhooks | HMAC-SHA256 signatures, retries for 72 hours, replay from GET /events. |
| Streaming | Server-Sent Events | Resume with Last-Event-ID. |
| Per-referral push | JWT / JWKS or HMAC | Keys are published at /.well-known/jwks.json. |
| Agents | MCP | Works with Claude, ChatGPT, Google ADK, OpenAI Agents SDK and other MCP clients. |
| Agent-to-agent | A2A v1.0 | Coming soon. |
| Embed transport | JSON-RPC 2.0 over postMessage, Web Components | |
| Conventions | Prefixed ids, amounts in cents, cursor pagination |
Resources
Standards
The open standards the API follows.

