Medplum · API Governance Rules
Medplum API Rules
Spectral linting rules defining API design standards and conventions for Medplum.
5 Rules
warn 4
info 1
Rule Categories
fhir
medplum
no
operation
Rules
warn
operation-summary
Operations should have a Title Case summary.
$.paths[*][get,put,post,delete,patch]
warn
medplum-bearer-security
Medplum FHIR REST API operations must require bearer-token security.
$.components.securitySchemes
warn
medplum-resource-path
Medplum FHIR R4 paths must start with /fhir/R4/{resourceType}.
$.paths
warn
no-trailing-slash
Paths must not end with a trailing slash.
$.paths
info
fhir-r4-schema-ref
Request and response bodies should reference R4 component schemas.
$.paths[*][get,post,put,patch].responses.200.content.application/fhir+json.schema
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/medplum-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.