Lakera · API Governance Rules
Lakera API Rules
Spectral linting rules defining API design standards and conventions for Lakera.
5 Rules
error 3
warn 2
Rule Categories
lakera
operation
Rules
warn
operation-summary-title-case
Operation summaries should be in Title Case.
$.paths.*[get,post,put,delete,patch]
error
operation-must-have-tags
Every operation must have at least one tag (Guard, Results, Policies, Projects).
$.paths.*[get,post,put,delete,patch]
warn
operation-must-have-description
Every operation must include a description that explains intent and detector behavior.
$.paths.*[get,post,put,delete,patch]
error
lakera-server-must-use-versioned-base
Lakera servers must use a /v2 versioned base path.
$.servers[*].url
error
lakera-security-bearer-required
Lakera APIs must use Bearer token authentication.
$.components.securitySchemes
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/lakera-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.