Trellix Web Gateway · API Governance Rules
Trellix Web Gateway API Rules
Spectral linting rules defining API design standards and conventions for Trellix Web Gateway.
19 Rules
error 3
warn 12
info 4
Rule Categories
no
operation
path
query
schema
servers
twg
Rules
warn
twg-operation-id-camel-case
Operation IDs must use camelCase
$.paths[*][*].operationId
warn
twg-summary-title-case
Operation summaries must use Title Case
$.paths[*][*].summary
error
twg-security-defined
All non-login operations must define security requirements
$.paths[?(!@path.match('/login$'))][get,post,put,patch,delete]
error
twg-response-200-get
All GET operations must define a 200 response
$.paths[*].get
warn
twg-response-401-defined
Authenticated operations should define a 401 response
$.paths[*][get,post,put,delete]
warn
twg-tag-defined
All operations must have at least one tag
$.paths[*][get,post,put,patch,delete]
warn
twg-server-variables
Server URLs with variables must define those variables
$.servers[*].variables[*]
info
twg-cookie-auth
Web Gateway uses session cookie authentication via JSESSIONID
$.components.securitySchemes.cookieAuth
warn
twg-path-kebab-case
API paths should use lowercase letters and hyphens
$.paths[*]~
warn
twg-delete-response
DELETE operations should return 200 or 204
$.paths[*].delete
warn
twg-post-request-body
POST operations that create resources should define a request body
$.paths[*].post
info
twg-xml-content-type
Configuration endpoints use XML content type
$.paths['/configuration'].get.responses.200.content
error
servers-https-only
Server URLs must use HTTPS.
$.servers[*].url
warn
path-params-casing
Path parameters should be camelCase (the dominant convention in this API).
$.paths[*].parameters[?(@.in=='path')].name
info
query-params-casing
Query parameters should be snake_case (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
warn
schema-names-casing
Component schema names should be PascalCase (the dominant convention in this API).
$.components.schemas
info
schema-properties-casing
Schema properties should be snake_case (the dominant convention in this API).
$.components.schemas[*].properties
warn
operation-documents-401
Operations should document a 401 response (documented on 98% of this API's operations).
$.paths[*][get,post,put,patch,delete].responses
warn
no-empty-descriptions
Descriptions must not be empty strings.
$..description
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/trellix-web-gateway-spectral-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.