Spotlight Rules
Spotlight Rules is an openly-governed build of the Spectral API linter and, more importantly, the first attempt to publish the Spectral ruleset format as a standalone specification with its own portable JSON Schema — so that an organization's API governance rules stop being configuration for one vendor's CLI and become a durable, tool-independent artifact. Started in 2026 as a project of API Evangelist and maintained in the open under API Commons, it ships four public things: the specification and JSON Schema at spec.spotlight-rules.com, the reference implementation (api-commons/spotlight-tools), eight Apache-2.0 npm packages under the @spotlight-rules scope including the `spotlight` CLI, and a 332-rule best-of-breed governance ruleset compiled from public Spectral rulesets. It publishes no hosted API and no commercial tier — the stated position is open source permanently, funded by earmarked sponsorship rather than a paid version.
Spotlight Rules is profiled on the APIs.io network. Tagged areas include API Governance, API Linting, Spectral, Rulesets, and OpenAPI.
The Spotlight Rules catalog on APIs.io includes 1 Spectral governance ruleset.
Spotlight Rules’ developer surface includes documentation, CLI, engineering blog, support, and 15 more developer resources.
Kin Score
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Spotlight Rules Rate Limits
RATE LIMITSSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
Spotlight Rules API Rules
SPECTRALJSON Schema 1
Standalone JSON Schema definitions for this provider's data models.
Spectral Ruleset
JSON SCHEMASecurity Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 4
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.