Runa · API Governance Rules
Runa API Rules
Spectral linting rules defining API design standards and conventions for Runa.
18 Rules
error 2
warn 15
info 1
Rule Categories
error
no
operation
query
runa
schema
servers
Rules
warn
runa-operation-ids-camel-case
All operationIds must use camelCase naming convention.
$.paths.*[get,post,put,patch,delete].operationId
warn
runa-tags-title-case
All tags must use Title Case.
$.tags[*].name
warn
runa-api-key-header
All operations must use X-Api-Key apiKey authentication.
$.components.securitySchemes.apiKeyAuth
warn
runa-idempotency-key-on-orders
Order creation endpoint should document X-Idempotency-Key header.
$.paths.*.post.parameters[?(@.name=='X-Idempotency-Key')]
warn
runa-paths-kebab-case
All path segments must use kebab-case.
$.paths
error
runa-response-200-defined
All operations must define a 200 response.
$.paths.*[get,post,put,patch,delete].responses
warn
runa-401-defined
All secured endpoints must define a 401 response.
$.paths.*[get,post].responses
warn
runa-summaries-title-case
Operation summaries must use Title Case.
$.paths.*[get,post,put,patch,delete].summary
info
runa-versioned-api
API version should be expressed in the server URL path.
$.servers[*].url
error
servers-https-only
Server URLs must use HTTPS.
$.servers[*].url
warn
servers-expected-domain
Server URLs should be on the runa.io domain.
$.servers[*].url
warn
query-params-casing
Query parameters should be snake_case (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
warn
schema-names-casing
Component schema names should be PascalCase (the dominant convention in this API).
$.components.schemas
warn
schema-properties-casing
Schema properties should be snake_case (the dominant convention in this API).
$.components.schemas[*].properties
warn
operation-security-required
Every operation should declare its security requirements.
$.paths[*][get,post,put,patch,delete]
warn
error-schema-defined
A shared error schema (Error) should be defined for error payloads.
$.components.schemas
warn
operation-documents-401
Operations should document a 401 response (documented on 100% of this API's operations).
$.paths[*][get,post,put,patch,delete].responses
warn
no-empty-descriptions
Descriptions must not be empty strings.
$..description