Home
Aflac
Aflac API Rules
Aflac · API Governance Rules
Aflac API Rules
Spectral linting rules defining API design standards and conventions for Aflac.
30 Rules
error 14
warn 16
Rule Categories
error
get
info
no
openapi
operation
parameter
path
paths
query
response
schema
security
servers
Rules
error
info-title-required
API title must be present
$.info
warn
info-title-company-prefix
API title must start with "Aflac"
$.info.title
error
info-description-required
API info must have a description
$.info
error
info-version-required
API version must be present
$.info
error
openapi-version-3
OpenAPI version must be 3.x
$
error
servers-defined
Servers must be defined
$
error
servers-https
All server URLs must use HTTPS
$.servers[*].url
warn
servers-description
Server entries should have descriptions
$.servers[*]
warn
paths-kebab-case
Path segments should use kebab-case
$.paths[*]~
error
paths-no-trailing-slash
Paths must not have trailing slashes
$.paths[*]~
error
operation-summary-required
Every operation must have a summary
$.paths[*][get,post,put,patch,delete]
warn
operation-summary-company-prefix
Operation summaries must start with "Aflac"
$.paths[*][get,post,put,patch,delete].summary
warn
operation-description-required
Every operation must have a description
$.paths[*][get,post,put,patch,delete]
error
operation-operationid-required
Every operation must have an operationId
$.paths[*][get,post,put,patch,delete]
warn
operation-operationid-camel-case
OperationIds should use camelCase
$.paths[*][get,post,put,patch,delete].operationId
error
operation-tags-required
Every operation must have at least one tag
$.paths[*][get,post,put,patch,delete]
warn
parameter-description-required
All parameters must have descriptions
$.paths[*][get,post,put,patch,delete].parameters[*]
error
response-description-required
All responses must have descriptions
$.paths[*][get,post,put,patch,delete].responses[*]
warn
response-401-defined
Operations using auth should document 401 responses
$.paths[*][get,post,put,patch,delete].responses
warn
schema-description
Top-level schemas should have descriptions
$.components.schemas[*]
warn
schema-type-defined
Schemas should have a type
$.components.schemas[*]
error
security-schemes-defined
Security schemes must be defined
$.components
error
get-no-request-body
GET operations must not have request bodies
$.paths[*].get
error
no-empty-descriptions
Descriptions must not be empty
$..description
warn
servers-expected-domain
Server URLs should be on the aflac.com domain.
$.servers[*].url
warn
path-params-casing
Path parameters should be snake_case (the dominant convention in this API).
$.paths[*].parameters[?(@.in=='path')].name
warn
query-params-casing
Query parameters should be snake_case (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
warn
schema-names-casing
Component schema names should be PascalCase (the dominant convention in this API).
$.components.schemas
warn
schema-properties-casing
Schema properties should be snake_case (the dominant convention in this API).
$.components.schemas[*].properties
warn
error-schema-defined
A shared error schema (Error) should be defined for error payloads.
$.components.schemas
Spectral Ruleset
# authorship: generated by API Evangelist tooling. Stamped 2026-08-18
# on the file's own generator header (roadmap#64). An unmarked file is
# NOT assumed to be ours -- absence of evidence was never stamped.
x-method: generated
# aflac — Spectral ruleset (strengthened)
# Plain Spectral. Existing hand-authored rules preserved; measured rules added
# from this provider's own OpenAPI conventions by strengthen_ruleset.py,
# then self-validated against the spec.
#
# Provenance:
# - servers-https-only: 100% of servers already https (error)
# - servers-expected-domain: 2/2 servers on aflac.com
# - path-params-casing: snake @ 100% (n=6)
# - query-params-casing: snake @ 100% (n=13)
# - operationid-casing: camel @ 100% (n=13)
# - schema-names-casing: pascal @ 100% (n=14)
# - schema-properties-casing: snake @ 100% (n=71)
# - security: global (root) — NOT emitting operation-security-required
# - error-schema-defined: Error
# - pagination params observed: ['limit', 'offset']
# - merge: kept 24 existing, added 6 measured, upgraded 0
# - added: servers-expected-domain, path-params-casing, query-params-casing, schema-names-casing, schema-properties-casing, error-schema-defined
extends:
- spectral:oas
rules:
info-title-required:
description: API title must be present
severity: error
given: $.info
then:
field: title
function: truthy
info-title-company-prefix:
description: API title must start with "Aflac"
severity: warn
given: $.info.title
then:
function: pattern
functionOptions:
match: ^Aflac
info-description-required:
description: API info must have a description
severity: error
given: $.info
then:
field: description
function: truthy
info-version-required:
description: API version must be present
severity: error
given: $.info
then:
field: version
function: truthy
openapi-version-3:
description: OpenAPI version must be 3.x
severity: error
given: $
then:
field: openapi
function: pattern
functionOptions:
match: ^3\.
servers-defined:
description: Servers must be defined
severity: error
given: $
then:
field: servers
function: truthy
servers-https:
description: All server URLs must use HTTPS
severity: error
given: $.servers[*].url
then:
function: pattern
functionOptions:
match: ^https://
servers-description:
description: Server entries should have descriptions
severity: warn
given: $.servers[*]
then:
field: description
function: truthy
paths-kebab-case:
description: Path segments should use kebab-case
severity: warn
given: $.paths[*]~
then:
function: pattern
functionOptions:
match: ^(/[a-z0-9{}/_-]+)+$
paths-no-trailing-slash:
description: Paths must not have trailing slashes
severity: error
given: $.paths[*]~
then:
function: pattern
functionOptions:
notMatch: /$
operation-summary-required:
description: Every operation must have a summary
severity: error
given: $.paths[*][get,post,put,patch,delete]
then:
field: summary
function: truthy
operation-summary-company-prefix:
description: Operation summaries must start with "Aflac"
severity: warn
given: $.paths[*][get,post,put,patch,delete].summary
then:
function: pattern
functionOptions:
match: ^Aflac
operation-description-required:
description: Every operation must have a description
severity: warn
given: $.paths[*][get,post,put,patch,delete]
then:
field: description
function: truthy
operation-operationid-required:
description: Every operation must have an operationId
severity: error
given: $.paths[*][get,post,put,patch,delete]
then:
field: operationId
function: truthy
operation-operationid-camel-case:
description: OperationIds should use camelCase
severity: warn
given: $.paths[*][get,post,put,patch,delete].operationId
then:
function: pattern
functionOptions:
match: ^[a-z][a-zA-Z0-9]+$
operation-tags-required:
description: Every operation must have at least one tag
severity: error
given: $.paths[*][get,post,put,patch,delete]
then:
field: tags
function: truthy
parameter-description-required:
description: All parameters must have descriptions
severity: warn
given: $.paths[*][get,post,put,patch,delete].parameters[*]
then:
field: description
function: truthy
response-description-required:
description: All responses must have descriptions
severity: error
given: $.paths[*][get,post,put,patch,delete].responses[*]
then:
field: description
function: truthy
response-401-defined:
description: Operations using auth should document 401 responses
severity: warn
given: $.paths[*][get,post,put,patch,delete].responses
then:
function: schema
functionOptions:
schema:
type: object
required:
- '401'
schema-description:
description: Top-level schemas should have descriptions
severity: warn
given: $.components.schemas[*]
then:
field: description
function: truthy
schema-type-defined:
description: Schemas should have a type
severity: warn
given: $.components.schemas[*]
then:
field: type
function: truthy
security-schemes-defined:
description: Security schemes must be defined
severity: error
given: $.components
then:
field: securitySchemes
function: truthy
get-no-request-body:
description: GET operations must not have request bodies
severity: error
given: $.paths[*].get
then:
field: requestBody
function: falsy
no-empty-descriptions:
description: Descriptions must not be empty
severity: error
given: $..description
then:
function: pattern
functionOptions:
match: .+
servers-expected-domain:
description: Server URLs should be on the aflac.com domain.
severity: warn
given: $.servers[*].url
then:
function: pattern
functionOptions:
match: aflac\.com
path-params-casing:
description: Path parameters should be snake_case (the dominant convention in this API).
severity: warn
given: $.paths[*].parameters[?(@.in=='path')].name
then:
function: casing
functionOptions:
type: snake
query-params-casing:
description: Query parameters should be snake_case (the dominant convention in this API).
severity: warn
given: $.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
then:
field: name
function: casing
functionOptions:
type: snake
schema-names-casing:
description: Component schema names should be PascalCase (the dominant convention in this API).
severity: warn
given: $.components.schemas
then:
field: '@key'
function: casing
functionOptions:
type: pascal
schema-properties-casing:
description: Schema properties should be snake_case (the dominant convention in this API).
severity: warn
given: $.components.schemas[*].properties
then:
field: '@key'
function: casing
functionOptions:
type: snake
error-schema-defined:
description: A shared error schema (Error) should be defined for error payloads.
severity: warn
given: $.components.schemas
then:
field: Error
function: truthy
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/aflac-spectral-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.