TROLIE · API Governance Rules

TROLIE API Rules

Spectral linting rules defining API design standards and conventions for TROLIE.

5 Rules warn 5
Published by TROLIE Served by the provider at https://github.com/trolie/spec/blob/39741d03365cb430ab5d7e677312759a7f4a6d14/.spectral.yaml; the copy below was fetched from there.
View Rules File View on GitHub

Rule Categories

owasp:api3:2019 owasp:api4:2019 should

Rules

warn
owasp:api3:2019-define-error-responses-500
OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[get,put,post,patch,delete].responses
warn
owasp:api3:2019-define-error-responses-500-head
OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[head].responses
warn
owasp:api3:2019-define-error-responses-401
OWASP API Security recommends defining schemas for all responses, even errors. The 401 describes what happens when a request is unauthorized, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
$.paths.*[get,put,post,patch,delete].responses
warn
owasp:api4:2019-rate-limit-responses-429
$.paths..responses
warn
should-have-422
$.paths.*[put,post,patch].responses

Spectral Ruleset

Raw ↑
# harvested from https://github.com/trolie/spec/blob/39741d03365cb430ab5d7e677312759a7f4a6d14/.spectral.yaml on 2026-10-09 — a Spectral ruleset published in the provider's own GitHub repository (trolie/spec); found by GitHub code search, fetched verbatim
x-method: harvested
x-stamped: 2026-10-09
x-source-url: https://github.com/trolie/spec/blob/39741d03365cb430ab5d7e677312759a7f4a6d14/.spectral.yaml
extends:
  - spectral:oas
  # note this only covers the 2019 top ten https://github.com/stoplightio/spectral-owasp-ruleset/issues/47
  - https://unpkg.com/@stoplight/spectral-owasp-ruleset@1.4.3/dist/ruleset.mjs

  # 2.0.0 breaks the build throwing the following error:
  # "scope.sandbox.value.match is not a function"
  #- https://unpkg.com/@stoplight/spectral-owasp-ruleset@2.0.0/dist/ruleset.mjs
rules:
  # override a couple of rules that erroneously apply to HEAD requests
  "owasp:api3:2019-define-error-responses-500":
    message: "Operation is missing {{property}}."
    description: OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
    given: $.paths.*[get,put,post,patch,delete].responses
    then:
      - field: "500"
        function: truthy
      - field: "500.content"
        function: truthy

  "owasp:api3:2019-define-error-responses-500-head":
    message: "Operation is missing {{property}}."
    description: OWASP API Security recommends defining schemas for all responses, even errors. The 500 describes what happens when a request fails with an internal server error, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces.
    given: $.paths.*[head].responses
    then:
      - field: "500"
        function: truthy

  "owasp:api3:2019-define-error-responses-401":
    message: "Operation is missing {{property}}."
    description: "OWASP API Security recommends defining schemas for all responses, even errors. The 401 describes what happens when a request is unauthorized, so its important to define this not just for documentation, but to empower contract testing to make sure the proper JSON structure is being returned instead of leaking implementation details in backtraces."
    given: $.paths.*[get,put,post,patch,delete].responses
    then:
      - field: "401"
        function: truthy
      - field: "401.content"
        function: truthy

  # we do not require content for rate limiting
  "owasp:api4:2019-rate-limit-responses-429":
    given: $.paths..responses
    then:
      - field: "429"
        function: truthy

  "should-have-422":
    message: "Operation is missing {{property}}."
    description: ""
    given: $.paths.*[put,post,patch].responses
    then:
      - field: "422"
        function: truthy
      - field: "422.content.application/problem+json"
        function: truthy
overrides:
  - files:
      # the created response's headers are used but
      # since the bodies are not empty, the entire
      # response is not used anywhere. However, for consistency
      # and to keep the individual responses DRY, we want
      # to keep the 201 in the root openapi file, so we
      # disable the unused component rule for this response
      - "docs/openapi-1.0.yaml#/components/responses/201"
    rules:
      oas3-unused-component: "off"

Work with this as data

Every ruleset here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for spectral rules

4 MCP tools reach this
  • find_rulesBrowse and filter every ruleset in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/trolie-spec-spectral-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.