Over the last eighteen days we introduced one API Commons tool per day. This post gathers the whole run in one place. None of these tools is a platform you adopt — each is a small, open, single-purpose thing you can pick up on its own — but read together they form a complete governance and discovery stack that is Spectral underneath and portable all the way through.
The Full Run
- API Validator — lint OpenAPI, AsyncAPI, Arazzo, and JSON Schema in the browser.
- API Discovery — a browser-first registry for API artifacts.
- API Documentation — standalone docs from APIs.json, with OpenAPI and Arazzo.
- API Reusability — discover, inventory, and score API reusability.
- Spectral Reporter — Spectral runs as self-contained HTML reports.
- Spectral Ruleset Studio — turn prose style guides into grounded rulesets.
- Ruleset Commons — a registry of provenanced rulesets by region and industry.
- Spectral OWASP Ruleset — the OWASP API Security Top 10 as grounded rules.
- Governance Pipeline — a reference PR-gating pipeline blueprint.
- Governance Pipeline Auditor — score your Spectral CI setup against a maturity rubric.
- Governance Coverage — measure how much of an API your rules actually examine.
- Governance Waivers — sanctioned, owned, expiring exceptions.
- API Governance Graph — bind the building blocks into one navigable graph.
- API Certification — issue and verify tamper-evident governance certificates.
- API Governance MCP — the same ruleset as an MCP server an agent can call.
- Agent Rule Export — turn a ruleset into agent-native guidance.
- MCP Install — a universal install interface for MCP servers.
- Context Gate — govern what agents are allowed to consume.
One Idea, Many Surfaces
The arc runs from the everyday acts of checking and finding an API, through the machinery of writing, running, and measuring governance, and out to the newest frontier: governing what agents produce and what they are allowed to consume. What holds it together is that a spectral- ruleset is the portable artifact every tool shares — the rules are the product, and each tool is just another surface for the same rules.
Everything is open and Apache-2.0, most of it runs entirely in your browser, and all of it lives on the API Commons tools page alongside whatever we ship next. Thanks for reading along, one day at a time.