Integration.app (Membrane) · OpenAPI Overlay 1.0.0
API Evangelist enhancements for the Membrane Platform API
10 actions
10 updates
update
Generated by API Evangelist
Written by API Evangelist tooling for Integration.app (Membrane)'s API. It is a proposal applied on top of the contract, not a document Integration.app (Membrane) publishes.
What the actions change
x-superseded-bycontactx-documentationx-changelogx-status-pagex-trust-centerx-rebranded-fromx-api-version-header
Targets 4
$.info
$
$.paths['/actions/{selector}/run'].post
$.paths['/connections'].get.parameters[?(@.name=='disconnected')]
OpenAPI Overlay
overlay: 1.0.0
info:
title: API Evangelist enhancements for the Membrane Platform API
version: 1.0.0
x-provenance:
generated: '2026-09-13'
method: generated
extends: openapi/integration-app-membrane-api-openapi.json
source: >-
Enhancements derived from the provider's own documentation (errors, limits, REST API guide,
security and privacy) applied over the untouched harvested spec. The original file is never
mutated. Every value below is quoted from a provider page named in the action description.
actions:
- target: $.info
description: >-
The harvested spec's info block is machine-generated and near-empty - description is "API
documentation for Membrane Engine" and contact is {}. Add the contact and licence facts the
provider publishes elsewhere.
update:
contact:
name: Membrane Support
email: support@getmembrane.com
url: https://docs.getmembrane.com
x-documentation: https://docs.getmembrane.com
x-changelog: https://changelog.getmembrane.com
x-status-page: https://status.getmembrane.com
x-trust-center: https://trust.getmembrane.com
x-rebranded-from: Integration.app
- target: $
description: >-
Declare the request-header versioning scheme the REST API guide documents. The spec itself
carries version "1.0" and no mention of API-Version, so a generated client has no way to pin.
update:
x-api-version-header:
name: API-Version
scheme: X.Y
example: '2.1'
semantics: major on breaking changes, minor on any update
source: https://docs.getmembrane.com/docs/ways-to-use-membrane/rest-api
- target: $
description: >-
Declare the error envelope. The spec declares no 4xx/5xx response on any of its 278 operations,
so the documented error model is invisible to every code generator reading it.
update:
x-error-envelope:
content_type: application/json
rfc9457: false
fields:
- type
- key
- message
- data
- causedByError
status_map:
'400': bad_request
'401': not_authenticated
'403': access_denied
'404': not_found
'429': rate_limit_exceeded
'500': internal
source: https://docs.getmembrane.com/reference/overview/errors
catalog: errors/integration-app-problem-types.yml
- target: $
description: Declare the published request/response envelope limits and the 429 behaviour.
update:
x-limits:
max_request_bytes: 10485760
max_response_bytes: 31457280
max_request_seconds: 60
rate_limit_headers_published: false
exhaustion_status: 429
source: https://docs.getmembrane.com/docs/managing-membrane/limits
catalog: rate-limits/integration-app-rate-limits.yml
- target: $
description: >-
Declare the reversibility model. DELETE archives rather than erases for 13 entity types, each
with a restore twin, and nothing in the spec says so - an agent reading only the contract will
treat every DELETE as final.
update:
x-reversibility:
grade: documented
model: DELETE archives; POST .../restore un-archives; includeArchived=true lists archived items
window_stated: false
irreversible_operations:
- deleteConnector
- deleteConnectorVersion
- deleteConnectorFile
- deleteConnectorDirectory
- deleteApp
- deleteDataLink
- deleteDataLinkTableLink
- deleteConnectedProduct
- deleteExternalEventSubscription
- disconnectConnection
catalog: conventions/integration-app-conventions.yml
- target: $
description: >-
Declare the absence of replay protection. This is a safety fact an agent needs before it retries
a write, and absence is not representable in OpenAPI.
update:
x-idempotency:
coverage: none
header: null
note: >-
No Idempotency-Key or equivalent is published. Retrying a POST creates or executes again.
POST /connections/ensure is find-or-create and is the only safe-retry write.
- target: $
description: Declare the cursor pagination contract uniformly.
update:
x-pagination:
style: cursor
request:
limit: 1-1000
cursor: opaque, from the previous response
response:
items: array
cursor: string
- target: $
description: >-
Declare the agent surfaces that front this API, so a reader of the contract can find the MCP
endpoint, the agent card and the published skills.
update:
x-agent-surfaces:
mcp: https://api.getmembrane.com/mcp/integrate-anything
mcp_auth: oauth (RFC 9728 protected resource metadata)
agent_card: https://docs.getmembrane.com/.well-known/agent-card.json
agent_skills: https://github.com/membranehq/agent-skills
llms_txt: https://docs.getmembrane.com/llms.txt
crosswalk: mcp/integration-app-tool-crosswalk.yml
- target: $.paths['/actions/{selector}/run'].post
description: >-
The operation is already deprecated:true in the spec but names no successor. Point at the
current entry point, and record that the provider's own published agent tools still call this
path.
update:
x-superseded-by: act
x-successor-path: POST /act
x-note: >-
github.com/membranehq/agent-skills tools/integrate-anything.ts still calls this deprecated
path from its run-tool definition as of 2026-09-13.
- target: $.paths['/connections'].get.parameters[?(@.name=='disconnected')]
description: The spec's own description marks this parameter deprecated in prose only.
update:
deprecated: true
x-superseded-by: connected