API Governance

Rulesets & conformance

7 min · 55 XP · Read → Check → Complete


Governance as code

Anypoint API Governance evaluates specs against rulesets and reports a conformance status. A ruleset is a set of machine-checkable rules — written in the Spectral-style format — applied to RAML or OAS specs in Exchange.

A small ruleset example

rules:
  resource-name-plural:
    message: Resource paths should use plural nouns
    severity: warning
    given: $.paths[*]~
    then:
      function: pattern
      functionOptions:
        match: "^/[a-z]+s(/.*)?$"
  response-must-describe-errors:
    message: Every operation must document a 4xx response
    severity: error
    given: $.paths[*][*].responses
    then:
      field: "400"
      function: truthy

How conformance works

  • Rulesets are published to Exchange and applied to a set of APIs.
  • Each API gets a conformance report — pass, warnings, or errors.
  • Governance gives a program-wide view of which APIs meet standards.

Coaching note

Introduce governance as warnings before errors. A ruleset that blocks on day one breeds resentment; one that surfaces gaps, then tightens over time, builds trust in the standard.

Check your understanding
  1. 1. What does an API Governance ruleset evaluate?

  2. 2. How should you coach a customer to introduce a new ruleset?