AppstoreSpy · API Governance Rules
AppstoreSpy API Rules
Spectral linting rules defining API design standards and conventions for AppstoreSpy.
12 Rules
error 3
warn 5
info 4
Rule Categories
appstorespy
Rules
error
appstorespy-operation-security
Every operation declares the security it requires. AppstoreSpy meters and bills per call, so an operation with no declared scheme is either a contract error or an unbilled surface.
$.paths[*][get,put,post,delete,patch]
error
appstorespy-no-credential-in-query
The API key travels in the API-KEY request header, never in the query string, where it would land in server, proxy and referrer logs.
$.components.securitySchemes[?(@.type == 'apiKey')]
error
appstorespy-operation-error-response
Every operation documents at least one failure response. Callers integrate against the error path as much as the success path.
$.paths[*][get,put,post,delete,patch].responses
warn
appstorespy-operation-description
Every operation carries a description. The summary names the operation; the description is what a consumer, or an agent choosing between 37 operations, actually reads.
$.paths[*][get,put,post,delete,patch]
warn
appstorespy-store-tag
Every operation is tagged with the surface it belongs to, so the reference groups into navigable sections instead of one flat list.
$.paths[*][get,put,post,delete,patch]
warn
appstorespy-path-namespace
Paths live under one of the three published namespaces: /play for Google Play, /ios for the App Store, /jobs for asynchronous crawl jobs.
$.paths
warn
appstorespy-fields-param-documented
The `fields` parameter selects which columns come back and takes a comma-separated list. Its description has to say so, because the shape is not inferable from the type.
$.paths[*][*].parameters[?(@.name == 'fields')]
warn
appstorespy-query-param-snake-case
Query parameter names are snake_case across the whole surface.
$.paths[*][*].parameters[?(@.in == 'query')]
info
appstorespy-sort-param-example
Sorting uses a `-field` prefix for descending order. A `sort` parameter carries an example, because the convention is not discoverable from the type alone.
$.paths[*][*].parameters[?(@.name == 'sort')]
info
appstorespy-summary-length
Summaries stay short enough to render in a reference index.
$.paths[*][get,put,post,delete,patch].summary
info
appstorespy-info-version-released
info.version identifies a released contract rather than a framework default. The callable surface is pinned at /v1 in servers[0].url.
$.info
info
appstorespy-problem-details
Failure responses should carry application/problem+json (RFC 9457) rather than a bare vendor envelope. Recorded as guidance: the surface is on vendor JSON today and moving is a breaking change for existing callers.
$.paths[*][*].responses[?(@property.match(/^4/))].content
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.