University of Melbourne · API Governance Rules

University of Melbourne API Rules

Spectral linting rules defining API design standards and conventions for University of Melbourne.

0 Rules
View Rules File View on GitHub

Spectral Ruleset

Raw ↑
x-generated: '2026-08-19'
x-method: derived
x-source: >-
  Derived from the observed behaviour of the University of Melbourne's
  institution-operated surfaces on 2026-08-19 (see errors/, conformance/ and
  lifecycle/). These are governance findings about surfaces the University
  actually runs; none of them is derived from a vendor contract.
x-operator: institution
description: >-
  Governance rules the University of Melbourne's own APIs are measured against,
  with the observed result for each. Written as findings, not as
  recommendations to a customer — nobody at the University asked for this and
  none of these surfaces claims to be a product.
rules:
  - id: machine-readable-contract-published
    severity: error
    applies_to: [sudo, minerva-access-rest, minerva-access-oai]
    result: fail
    finding: >-
      No OpenAPI, AsyncAPI or JSON Schema is published for any surface. GeoNode
      ships an OpenAPI route; on this deployment /api/v2/openapi and
      /api/v2/swagger.json both 404. The three OpenAPI documents in openapi/
      are ours, marked method: derived, and must never be read as the
      University's.
  - id: tls-hostname-matches-certificate
    severity: error
    applies_to: [sudo]
    result: fail
    finding: >-
      sudo.eresearch.unimelb.edu.au presents a certificate for
      staging.unimelb-sudo.cloud.edu.au and nothing else. A conformant client
      cannot reach a public research dataset API of 7,417 datasets without
      disabling certificate verification.
  - id: production-host-serves-production-instance
    severity: error
    applies_to: [sudo]
    result: fail
    finding: >-
      The HTML title served at the production hostname is
      "staging.unimelb-sudo.cloud.edu.au", consistent with the certificate.
      The production name appears to front a staging deployment.
  - id: errors-use-rfc9457-problem-details
    severity: warn
    applies_to: [sudo, minerva-access-rest]
    result: fail
    finding: >-
      Three surfaces, three error conventions, none of them Problem Details.
      See errors/university-of-melbourne-errors.yml.
  - id: error-status-distinguishable-at-http-layer
    severity: warn
    applies_to: [minerva-access-oai]
    result: fail
    finding: >-
      OAI-PMH returns HTTP 200 for protocol errors. Specification-correct, but
      it means a harvester that checks status codes rather than parsing the
      envelope cannot tell a failed harvest from a good one.
  - id: rate-limit-signalled
    severity: warn
    applies_to: [sudo, minerva-access-rest]
    result: fail
    finding: >-
      No RateLimit-* headers, no Retry-After, no published quota on any
      surface. The repository rate-limits/ artifact records this as unknown
      rather than unlimited.
  - id: cors-scoped
    severity: info
    applies_to: [sudo]
    result: pass-with-note
    finding: >-
      access-control-allow-origin: * with Access-Control-Allow-Credentials:
      false. Correct for an open read API; noted because the same host also
      sets a Django sessionid cookie on anonymous requests.
  - id: availability-consistent-across-collections
    severity: error
    applies_to: [sudo]
    result: fail
    finding: >-
      /api/v2/categories timed out at 60s while sibling collections answered
      in the same minute. Repeated across two attempts.
  - id: contract-attributed-to-its-actual-operator
    severity: error
    applies_to: [all]
    result: pass
    finding: >-
      No vendor contract is saved in this repository. melbourne.figshare.com,
      spatialdata-uom.opendata.arcgis.com and sso.unimelb.edu.au are recorded
      as x-operator: tenant relationships with no vendor specification copied
      under the University's slug.
  - id: soft-404-not-credited-as-a-surface
    severity: error
    applies_to: [findanexpert]
    result: pass
    finding: >-
      findanexpert.unimelb.edu.au/api returns HTTP 200 with a Vue SPA shell.
      Recorded in errors/ as a soft-404 and deliberately not listed as an API.

Work with this as data

Every ruleset here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for spectral rules

4 MCP tools reach this
  • find_rulesBrowse and filter every ruleset in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/university-of-melbourne-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.