Topic · topic
API Governance
API Governance is the practice of defining and enforcing the policies, standards, and processes that guide how APIs are designed, built, secured, versioned, and retired across an organization. This topic indexes the providers, tools, and open-source linters that operationalize spec governance, design governance, security governance, and lifecycle governance for the API estate.
Resources
-
Apiwiz API Governance
Federated API management platform with automated linting, build templates, policy enforcement, and multi-gateway governance for the full API lifecycle.
-
Treblle API Intelligence and Governance
API observability and governance platform that scores, monitors, and audits production APIs in real time, surfacing design and security issues against OpenAPI specifications.
-
42Crunch API Security Platform
Security-first API governance platform that audits OpenAPI contracts, runs 300+ conformance and security checks, performs automated fuzzing, and enforces policies from design through runtime.
-
APIContext (formerly Apimetrics)
API monitoring and governance service measuring availability, performance, and conformance of production APIs from distributed locations for SLA and regulatory reporting.
-
Postman API Governance
Governance product inside the Postman API platform combining a pre-built rule library, custom Spectral-compatible rules, CLI/CI enforcement, and a reporting dashboard for the API estate.
-
Stoplight Spaces and Style Guides
API design platform with built-in style guides, custom Spectral rulesets, and workspace-level governance, now offered as part of SmartBear's API Hub.
-
Spectral
Open-source JSON/YAML linter and style-guide enforcer for OpenAPI, AsyncAPI, and JSON Schema — the de facto standard rule engine behind most API governance products.
-
Vacuum
Open-source, Go-based OpenAPI linter that is 100% compatible with Spectral rulesets, supports OpenAPI 2 through 3.2, ships custom Go and JavaScript functions, and adds auto-fix and change-detection.
-
Redocly Reunite
Redocly's collaborative governance and documentation workspace with Git-backed previews, audit trails, and review workflows that wrap Redocly's OpenAPI linting and bundling toolchain.
-
Optic
Open-source and hosted tool that captures real API traffic, diffs it against the OpenAPI contract, and turns every change into a reviewable pull request with breaking-change detection.
-
Speakeasy Linter
OpenAPI linter shipped with the Speakeasy SDK generation platform offering 90+ rules across six categories — SDK generation, spec correctness, best practices, security, schema validation, and Speakeasy-specific checks.
-
Apicurio Registry
Open-source runtime registry that stores OpenAPI, AsyncAPI, GraphQL, Avro, Protobuf, JSON Schema, WSDL, and XSD artifacts and enforces validity, compatibility, and integrity rules across their lifecycle.
-
RepreZen API Studio
Historical commercial OpenAPI/RAPID-ML modeling IDE that drove contract-first API governance; the product line has been retired and the domain reprezen.com is no longer maintained.
-
Bump.sh
API documentation hub for OpenAPI and AsyncAPI with automatic changelog generation, breaking-change detection, and contract-level policy enforcement that feeds into governance workflows.
-
API Governance Program
Rules, vocabulary, JSON Schema, JSON-LD, and example records for an organizational API governance program covering spec, design, security, and lifecycle governance across the API estate.
-
Sensedia SMART API Governance
AI-powered federated governance platform delivering centralized visibility, contract validation, shadow API detection, and lifecycle policy enforcement across multi-cloud and multi-gateway estates.
Links
IssueTrackerReleasesCodeOfConductContributionGuideLicenseDomainSecurityReferenceReferenceReferenceReferenceReferenceReferenceGitHubOrganizationDeveloperPortal
Providers working in API Governance
Providers whose own tags share at least two of this topic's tags, most shared first — the top 30 of 80.
| Provider | About | Rating | APIs |
|---|---|---|---|
| Redocly | Redocly is a company that specializes in API documentation and governance tooling. Their platform helps organizations create, manage, and publish API documentation through Realm (the integrated lifecycle platform that unifies Redoc, Revel,… | exemplar | 4 |
| Stoplight | Stoplight is a collaborative, design-first API platform providing a visual editor for OpenAPI specifications, interactive hosted documentation, automatic mock servers, API style guides and governance, and open-source tools including Prism… | exemplar | 2 |
| Vacuum | Vacuum is the world's fastest and most versatile OpenAPI linter and toolkit, built in Go for validating and linting API specifications at scale. It is 100% compatible with Spectral rulesets and supports OpenAPI 3.0, 3.1, and 3.2. | emerging | 1 |
| Spotlight Rules | Spotlight Rules is an openly-governed build of the Spectral API linter and, more importantly, the first attempt to publish the Spectral ruleset format as a standalone specification with its own portable JSON Schema — so that an organizatio… | emerging | 0 |
| Postman | Postman is the world's leading API platform, used by 35+ million developers to design, build, test, document, mock, monitor, and govern APIs across the entire API lifecycle. The platform spans Collections, Workspaces, the API Client, Spec… | exemplar | 21 |
| anecdotes | anecdotes is an enterprise Governance, Risk and Compliance (GRC) platform, founded in 2020 and headquartered in Tel Aviv, that pairs a GRC data engine with AI agents to replace point-in-time audit cycles with continuous, evidence-backed co… | strong | 3 |
| Eclipse Foundation | The Eclipse Foundation is a non-profit (Belgian AISBL) that provides a global community of individuals and organizations with a mature, scalable and business-friendly environment for open source software collaboration and innovation. It is… | strong | 19 |
| Netcracker | Netcracker Technology is a Waltham, Massachusetts-based BSS/OSS and digital business software vendor and a wholly owned subsidiary of NEC Corporation. It sells cloud BSS, digital commerce and monetization, convergent charging, service and… | strong | 4 |
| Amazon Config | AWS Config provides a detailed view of the configuration of AWS resources in your AWS account. This includes how the resources are related to one another and how they were configured in the past, enabling assessment, auditing, and evaluati… | strong | 1 |
| ETSI | ETSI, the European Telecommunications Standards Institute, is a not-for-profit standards development organisation headquartered in Sophia Antipolis, France, and one of only three bodies officially recognised by the European Union as a Euro… | strong | 24 |
| Amazon CloudTrail | AWS CloudTrail enables governance, compliance, operational auditing, and risk auditing of your AWS account by tracking user activity and API usage across AWS environments, hybrid setups, and multicloud deployments with immutable audit trai… | strong | 1 |
| Amazon Organizations | AWS Organizations is an account management service that enables you to consolidate multiple AWS accounts into an organization that you create and centrally manage. | developing | 1 |
| Sweep | Sweep is the agentic layer for enterprise systems. By connecting to platforms like Salesforce, Snowflake, ServiceNow, and HubSpot, Sweep reads live metadata and gives AI agents the context they need to understand, plan, and govern changes… | developing | 2 |
| Bump.sh | Bump.sh is "the modern API doc platform" — automatic, diff-aware documentation for OpenAPI and AsyncAPI specifications, plus a managed Model Context Protocol (MCP) platform that compiles Flower or Arazzo workflow documents into determinist… | developing | 1 |
| 3GPP | 3GPP (the 3rd Generation Partnership Project) is the global standards partnership that writes the technical specifications for mobile networks — GSM, UMTS, LTE, 5G and the ongoing 6G work — through seven regional Organizational Partners (A… | developing | 116 |
| Amazon Backup | AWS Backup is a fully managed backup service that centralizes and automates the backup of data across AWS services, enabling you to configure backup policies, monitor backup activity, and restore resources with a single, unified console an… | developing | 1 |
| Torii | Torii is the market leading SaaS Management Platform built to bring all your software into one place. Discover shadow IT, enforce governance, cut costs, and operationalize every app. Torii integrates with 180+ SaaS applications to provide… | developing | 1 |
| Goethena | Ethena (goethena.com) is an AI-powered compliance training and ethics platform used by 2,000+ organizations to run harassment prevention, code of conduct, data privacy, anti-bribery, and regulatory compliance programs across their workforc… | developing | 1 |
| Vanta | Vanta is a trust management platform that automates security compliance for frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. The Vanta API enables organizations to programmatically manage their compliance posture, automate… | developing | 2 |
| OpenPages | IBM OpenPages is an AI-driven, unified governance, risk, and compliance (GRC) platform delivered as a managed service on IBM Cloud. Originally founded as OpenPages Inc. (a Matrix Partners portfolio company) and acquired by IBM in 2010, it… | developing | 1 |
| Azure Policy | Azure Policy is a service that enables you to create, assign, and manage policies that enforce rules and effects over your Azure resources. It helps with compliance, governance, and consistency by evaluating resources against business stan… | developing | 2 |
| Wegalvanize | Wegalvanize.com is the former web home of Galvanize, the governance, risk, and compliance (GRC) software company behind the HighBond platform; Galvanize was acquired by Diligent and wegalvanize.com now redirects to diligent.com. The HighBo… | developing | 1 |
| Amazon Control Tower | AWS Control Tower provides the easiest way to set up and govern a secure, multi-account AWS environment based on best practices. It establishes a landing zone with pre-configured governance and guardrails, enabling organizations to maintai… | developing | 4 |
| Google Cloud Assured Workloads | Google Cloud Assured Workloads enables organizations to create and manage compliance-controlled environments on Google Cloud. It provides guardrails for regulatory compliance frameworks such as FedRAMP, HIPAA, CJIS, ITAR, and others by enf… | developing | 1 |
| Nudge Security | Nudge Security is a SaaS and AI security management platform that discovers all SaaS and cloud applications used across an organization, helps security teams manage OAuth grants, enforce security policies, monitor app-to-app integrations,… | developing | 1 |
| Kion | Kion is a cloud operations platform that provides automated governance and FinOps capabilities across AWS, Azure, GCP, and OCI through a self-hosted deployment model. The platform consolidates multiple point solutions into a comprehensive… | thin | 1 |
| Open Policy Agent | Open Policy Agent (OPA) is an open-source project that provides a flexible and powerful policy engine for cloud-native environments. OPA enables users to define and enforce policies across their infrastructure, applications, and services t… | thin | 7 |
| MontyCloud | MontyCloud is a Bellevue, Washington software company whose DAY2 platform is a no-code, autonomous CloudOps product for AWS-focused managed service providers and enterprise cloud teams. DAY2 connects to customer AWS (and Azure) accounts th… | thin | 2 |
| Ketryx | Ketryx is an AI-native application lifecycle management (ALM) and compliance platform for regulated medical-device and life-sciences software teams. It integrates with developer tools such as Jira and GitHub to automate the documentation,… | thin | 1 |
| LAPIS | LAPIS (Lightweight API Specification for Intelligent Systems) is a compact, LLM-native API description format authored by Daniel Garcia (cr0hn). It is designed as the format you convert your OpenAPI specifications to when the consumer is a… | thin | 1 |
Tags
GovernancePoliciesRulesSpectralLintingLifecycleComplianceStandardsOpenAPIAsyncAPI