Windsurf · API Governance Rules
Windsurf API Rules
Spectral linting rules defining API design standards and conventions for Windsurf.
8 Rules
error 3
warn 4
info 1
Rule Categories
windsurf
Rules
info
windsurf-post-only
All Windsurf Enterprise API endpoints use POST method
$.paths[*]
error
windsurf-operation-id-required
All operations must have an operationId
$.paths[*][get,post,put,delete,patch]
warn
windsurf-operation-id-camel-case
OperationIds should use camelCase
$.paths[*][*].operationId
error
windsurf-operation-tags-required
All operations must have at least one tag
$.paths[*][get,post,put,delete,patch]
error
windsurf-summary-required
All operations must have a summary
$.paths[*][get,post,put,delete,patch]
warn
windsurf-service-key-in-body
All Windsurf API requests should include service_key in body
$.paths[*].post.requestBody.content['application/json'].schema
warn
windsurf-schema-descriptions
Schema components should have descriptions
$.components.schemas[*]
warn
windsurf-auth-error-response
POST operations must define a 401 response
$.paths[*].post.responses
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/windsurf-enterprise-rules"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.