Harness ships one contract, the catalog reads it as 488 APIs, and it scores 89.3

Harness ships one contract, the catalog reads it as 488 APIs, and it scores 89.3

Harness is listed with 488 APIs on apis.io. That number is ours, not theirs. The provider record says api_count: 1 on a published basis and source_spec_count: 1, split into 488 pages. Harness publishes one OpenAPI for its whole software delivery platform, and the catalog cuts it along resource lines so you can find the Pipelines API, the Chaos API or the Cloud Cost API without scrolling through a document the size of a novel.

The split is not a trick of the count. It is the honest shape of the surface: one contract, one auth model, one base, and a platform that spans CI, CD and GitOps, feature flags, chaos engineering, cloud cost management, security testing, an internal developer portal, code repositories and engineering insights. The score treats it that way. Harness sits at 89.3, exemplar, up 3.1 from 86.2 in the 2026-09-25 run.

Where the 89.3 comes from

Facet Score
Access clarity 100.0
Operational transparency 97.4
Developer ergonomics 79.8
Discoverability 70.0
Contract quality 64.5
Contract governance 31.8

Of 477 contracts in the record, 2 are derived and 100% are callable. Access is freemium and self-serve. Operational transparency at 97.4 is close to the ceiling, which is unusual for a platform this wide and exactly what you want from the company that runs your deploys.

Agent-native, with the caveat stated

Agent Readiness is 66.7, agent-native. The lit dimensions are the hard ones: delegated identity served, protected resource metadata verified, dynamic client registration, idempotency verified, error semantics verified, dry-run mode, reversibility documented, a first-party MCP server and 88 first-party agent skills. A delivery platform that exposes dry-run and documented reversibility is telling an agent it can rehearse a change before making it, and that is the right instinct for software that ships to production.

One thing I will not credit. The agentic access profile maps 2,889 operations, 1,382 acting and 70 human-in-the-loop, but the provenance marks it derived. We built that map. It is useful to integrators and it says nothing about what Harness published.

The same caution applies to the rubric’s coverage disclosure: of 70.5 catalog points earned, at least 24.0 came from artifacts Harness published itself. That is a floor, not the whole share, but it is the number to quote.

What holds it back

Contract governance at 31.8 is the weakest facet by a distance. Scopes read “OAuth 2.0, no documented scopes”, which on a platform with this many resources means an agent granted a token cannot be told what it may and may not touch. Consent identity is unlit, so there is no machine-readable way to mark which of those acting operations need a human sign-off. OpenAPI examples are only partial. There is no well-known API catalog and no agent card.

Takeaway

Harness earns its exemplar band on operations and access, the parts you cannot fake, and it already does the difficult identity work most providers have not started. What would move it past 89.3 is governance: documented OAuth scopes per resource, consent markers on the deploy, rollback and delete paths, and examples on every operation of that one large contract. The full record is at apis.io/providers/harness/, and the entry points worth starting from are the Pipelines API and the Pipeline Execution API.

← The GraphQL index points at 352 providers and shows none of their schemas
Maritime has 67 providers on apis.io and not one scores above developing →