Routebase asks which copy of the spec is current, and its own governance scores 4.5

Routebase asks which copy of the spec is current, and its own governance scores 4.5

Routebase has reframed an argument most API teams think they settled. In Where Should Your OpenAPI Spec Live?, the post opens with a lobby wall of four clocks, all labelled with the same city and showing four different times. “Nobody standing in front of that wall asks which clock is broken. They ask which one is right.” That, it argues, “is the state of the API contract at most companies, and it is not fixed by deciding where the spec file goes.” Teams argue repo versus tool for an afternoon, pick the repo, and then someone counts: the YAML in Git, the portal generated from it in March, the Confluence page a solutions engineer maintains by hand, and the PDF a partner was emailed and has been building against ever since. “The storage question was answered. The contract still has four values.”

There are no numbers to discount, and the post is fair to the position it argues past. The case for the spec in Git is “strong and mostly correct”: it moves with the branch, review happens where review already happens, CI can gate on a breaking change, and “there is no lock-in worth the name.” “Anyone who tells you this is a bad setup is selling something.” Where it breaks is “at the first reader who cannot get to it,” the support engineer, the partner, the customer’s developer, and “increasingly the reader is not a person at all but an agent.” The sharpest sentence is the diagnosis: “The copies are not the failure. Copies are how a contract reaches the people who need it. The failure is that none of them carries the one piece of information that would make it safe to read, namely which version of the source it came from.”

The catalog knows Routebase through the product that answers the post’s own questions. The Routebase provider page lists 5 API pages, and three of them are the argument in API form: the Routebase API Specs API holds the contract, the Routebase Docs as Code API is the derived surface that has to be brought forward when it changes, and the Routebase CI & Test Runs API is the gate. The agentic access profile maps 37 operations, 15 of them acting, and the agent surface is unusually complete: MCP server, agent skills, delegated identity, protected resource metadata, and dynamic client registration are all lit.

The Kin Score is 64.3, strong band, carried by developer ergonomics at 80.4 and discoverability at 75.0, with access clarity at 63.2 and contract quality at 58.2. Contract governance is 4.5. That is the facet that reads the artifacts that govern a contract, the rulesets and vocabularies it is held to, and it is the lowest number on the record by 50.8 points. The post argues that a copy is only safe to read when it carries what it was derived from. On the catalog’s reading, Routebase’s own contract publishes almost none of the governance artifacts a reader could check it against. The Agent Readiness score is 52.9, agent-ready. Routebase has written the clearest statement of the stale-copy problem I have read. Its own clock is on the wall with the others, and it does not yet carry a label.

← Redocly builds the spec from traffic, and says exactly where the AI is allowed
The most programmable vendor in the Gartner Magic Quadrants is Harness, and seven quadrants go to a vendor Gartner did not name a Leader →