# Keystone Online provider discovery specification

**Status:** documentation pending. This is a discovery record, not approval to connect, import, or write.

| Item | Required evidence before approval |
| --- | --- |
| Official API or export | Vendor-authored API documentation or supported export specification and version |
| Authentication | Vendor documentation for credential type, scopes, rotation and sandbox access |
| Rate limits | Published request, paging and retry limits |
| Permitted fields | Data-processing agreement and field-level export permissions |
| Source identifiers | Stable person, membership, Unit, Province and Order identifiers |
| Delta/deletion semantics | Change cursor, inactive/deleted records and reactivation rules |
| Controller/consent | Named controller decision, lawful basis, contact consent and retention rules |
| Support contact | Approved vendor support contact and escalation route |

No official source, credentials, rate limit, permitted-field list or support contact has been supplied to this repository. The fixture adapter is the only available adapter. A signed mapping decision and approved provider profile are mandatory before any import prompt can be enabled.

