Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with the MLS’s data-use rules and the exact feed the platform must handle. Then verify the specific MLS system’s standards fit, watch how the product enforces access, and assess the data-sharing model and operational evidence. RESO certification is useful interoperability evidence, not proof that a platform meets every security, privacy, or contractual obligation.

Start with the MLS’s rules, feeds, and authority

Before comparing platform feature lists, document what data the system will handle, which feeds are involved, the permitted uses, who needs access, and which written agreements govern the data. The MLS or its provider controls access and local terms: RESO says it does not provide MLS data, property records, or API credentials. Data recipients obtain access from the MLS or provider after agreeing to applicable data-use and licensing policies. See RESO’s Web API overview.

Ask the MLS for feed-request instructions, an explanation of the available feeds and their contents, and the right administrative and technical contacts. NAR’s MLS Best Practices calls for MLSs to provide this information. A platform cannot make an otherwise unauthorized data use permissible.

Verify the exact MLS system’s standards fit

Ask which transport method the particular MLS supports and request the current RESO Web API and Data Dictionary certification record for that exact MLS system. Do not infer that a vendor’s certification for one system covers every MLS it serves. RESO tests systems for conformance to ratified standards and makes certification reports available; its certification information and certification FAQ explain why status is system-specific.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Certification can help establish that a system follows relevant interoperability standards. It does not, by itself, establish compliance with a local data agreement or certify a complete cybersecurity, privacy, or organizational compliance program. Treat it as one item of evidence, not a security verdict.

RESO’s certification page reports 484 functioning MLS systems in the United States and says at least 90% of MLSs in the industry have RESO-certified Web API services. Those are figures stated on that page, whose data was updated October 2, 2026; they are not a measure of any particular platform’s security.

Watch how identity, credentials, and permissions work

Request a live or documented walkthrough of how users and services authenticate, how permissions are assigned, how MLS-issued credentials are handled, and how access is changed or reviewed. The RESO Web API is REST-based, uses JSON, and uses OAuth for authentication and authorization, as described in the Web API overview and Web API FAQ. This describes the standard, not proof that a particular product implements it correctly or maps it to your MLS’s entitlements.

  • Have the vendor show how a user or integration receives only the data and actions allowed under the MLS agreement.
  • Ask how access is removed when a person changes roles, leaves an organization, or loses authorization.
  • Confirm who provisions, stores, rotates, and revokes MLS-issued credentials, and whether credentials are shared among users or services.
  • Ask for evidence tied to the product and deployment you would actually use, rather than relying on a general statement that the product is secure.

Compare the data-sharing architecture

RESO describes different sharing approaches, including reciprocal access and shared aggregator views. Reciprocal access may use partner credentials, links, or single sign-on; an aggregator places data in a third-party system. The model changes where data flows and which parties operate the access path. See RESO’s data-sharing overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the model under consideration, establish who provisions and revokes access, where data is stored, which users can see it, and which organization is responsible for investigating suspected misuse. Confirm these details against the actual agreement and deployment rather than assuming that one sharing model is inherently compliant.

Ask for operational security evidence

The standards and policy materials cited here do not establish a universal MLS checklist for audit logging, incident response, data retention, encryption, or independent security attestations. Resolve those questions against the MLS’s risk requirements and the contract. Request product- and deployment-specific evidence for the controls that matter to your use case, and establish who will notify whom and handle investigation if an incident occurs.

Include other applicable MLS and NAR policies

Platform scope may extend beyond data feeds. If lock-box systems are involved, review the NAR lock-box security policy dated January 1, 2026, and confirm local implementation with the relevant MLS or association. The policy makes insurance-program eligibility contingent on specified security measures, requires non-duplicative keys, and calls for mobile-device software controls that allow access only to authorized users. These lock-box provisions should not be treated as universal requirements for every MLS data platform. See NAR’s lock-box security policy.

Organizational rule enforcement is also distinct from API certification. NAR’s MLS Best Practices says, “Enforcement of mandatory MLS policies and rules is a responsibility delegated to each local MLS.” Determine which local rules apply and how the MLS enforces them; a technical standards certificate does not resolve that governance question.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use these comparison points for a shortlist

Area Evidence to request Why it matters
Local authorization and contract fit MLS feed documentation, permitted-use terms, and credential issuance process The MLS or provider controls access and local terms. NAR MLS Best Practices; RESO Web API overview.
RESO interoperability Certification record for the exact system, supported Web API and Data Dictionary versions, and relevant fields or reports Certification tests standards conformance, and status must be checked system by system. RESO certification; RESO certification FAQ.
Authentication and permissions Demonstration of API authentication where applicable, role behavior, credential handling, and access changes tied to local entitlements The standard describes OAuth; product behavior still needs validation. RESO Web API FAQ.
Sharing architecture Whether access is reciprocal or aggregated, plus identity, storage, revocation, and responsibility details Different data flows create different operational questions. RESO data-sharing overview.
Operational security Product-specific security documentation, incident process, and evidence requested by the MLS The cited standards and policies do not certify named vendors against a complete security checklist.
Policy applicability Applicable NAR and local MLS rules, including lock-box policy if in scope Requirements depend on the product and local implementation. NAR lock-box security policy; NAR MLS Best Practices.

Make the decision on evidence, not labels

Choose only after the MLS confirms the permitted access model and the vendor demonstrates how its product fits that model. A useful evaluation keeps three questions separate: whether the system interoperates with the relevant standards, whether the deployed product enforces the required access controls, and whether the organization can meet its contractual and policy obligations. The cited sources do not establish a universal vendor ranking or identify a platform that satisfies every MLS’s requirements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.