Zitadel · API Governance Rules
Zitadel API Rules
Spectral linting rules defining API design standards and conventions for Zitadel.
7 Rules
error 3
warn 4
Rule Categories
zitadel
Rules
warn
zitadel-summary-prefix
All operation summaries must start with "Zitadel"
$.paths.*[get,post,put,delete,patch].summary
error
zitadel-operation-id
Every operation must have an operationId
$.paths.*[get,post,put,delete,patch]
warn
zitadel-operation-tags
Every operation must have at least one tag
$.paths.*[get,post,put,delete,patch]
warn
zitadel-operation-description
Every operation must have a description
$.paths.*[get,post,put,delete,patch]
error
zitadel-bearer-auth
Bearer auth security scheme must be defined
$.components.securitySchemes.bearerAuth
warn
zitadel-no-numeric-error-codes
Error responses must include 401, 403 references
$.paths.*[get,post,put,delete,patch].responses
error
zitadel-server-defined
Servers must be defined
$.servers
Spectral Ruleset
Work with this as data
Every ruleset here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for spectral rules
4 MCP tools reach this
find_rulesBrowse and filter every ruleset in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This ruleset
curl "https://apis.io/api/v1/rules/zitadel-spectral"
All spectral rules
curl "https://apis.io/api/v1/rules?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.