RSC · API Governance Rules
RSC API Rules
Spectral linting rules defining API design standards and conventions for RSC.
18 Rules
error 2
warn 14
info 2
Rule Categories
no
operation
path
query
rsc
schema
security
servers
Rules
warn
rsc-operation-ids-camel-case
All operationIds must use camelCase naming convention.
$.paths.*[get,post,put,patch,delete].operationId
warn
rsc-tags-title-case
All tags must use Title Case.
$.tags[*].name
warn
rsc-api-key-auth
All operations must use apiKeyAuth security unless explicitly public.
$.paths.*[get,post,put,patch,delete]
warn
rsc-request-body-json
POST request bodies must use application/json content type.
$.paths.*.post.requestBody.content
info
rsc-filter-endpoints-return-query-id
Filter endpoints should return a queryId for async polling.
$.paths['/filter/*'].post.responses.200.content.application/json.schema
warn
rsc-paths-kebab-case
All path segments must use kebab-case.
$.paths
error
rsc-response-200-defined
All operations must define a 200 response.
$.paths.*[get,post,put,patch,delete].responses
warn
rsc-401-defined-for-secured
Secured operations should define a 401 response.
$.paths.*[get,post].responses
error
servers-https-only
Server URLs must use HTTPS.
$.servers[*].url
warn
servers-expected-domain
Server URLs should be on the rsc.org domain.
$.servers[*].url
warn
path-params-casing
Path parameters should be camelCase (the dominant convention in this API).
$.paths[*].parameters[?(@.in=='path')].name
warn
query-params-casing
Query parameters should be snake_case (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
warn
schema-names-casing
Component schema names should be PascalCase (the dominant convention in this API).
$.components.schemas
info
schema-properties-casing
Schema properties should be camelCase (the dominant convention in this API).
$.components.schemas[*].properties
warn
security-schemes-defined
Security schemes should be defined in components.
$.components
warn
operation-security-required
Every operation should declare its security requirements.
$.paths[*][get,post,put,patch,delete]
warn
operation-documents-401
Operations should document a 401 response (documented on 100% of this API's operations).
$.paths[*][get,post,put,patch,delete].responses
warn
no-empty-descriptions
Descriptions must not be empty strings.
$..description