Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Eighteen Tools for Open API Governance, One a Day

July 25th, 2026 · Kin Lane
Eighteen Tools for Open API Governance, One a Day

For the last eighteen days I have introduced one API Commons tool each morning, and this is the map of the whole run. I did it as a drip on purpose, because looking at the tools one at a time makes a point that a single big announcement would have buried: none of these is a platform you adopt, each is a small, sharp, open thing you can pick up on its own. Put them side by side, though, and they add up to a full governance and discovery stack that is Spectral underneath and portable all the way through. Here is every stop, in the order I published them.

  • API Validator — lint OpenAPI, AsyncAPI, Arazzo, and JSON Schema in the browser, with nothing leaving the page.
  • API Discovery — a browser-first registry for the API artifacts you depend on.
  • API Documentation — standalone docs generated from APIs.json, with OpenAPI and Arazzo.
  • API Reusability — discover, inventory, and score how reusable your API estate really is.
  • Spectral Reporter — turn a Spectral run into a self-contained HTML report people actually read.
  • Spectral Ruleset Studio — turn a prose style guide into an owned, grounded Spectral ruleset.
  • Ruleset Commons — a registry of adoptable, provenanced rulesets by region and industry.
  • Spectral OWASP Ruleset — the OWASP API Security Top 10 expressed as grounded Spectral rules.
  • Governance Pipeline — a reference PR-gating pipeline blueprint for governance in CI/CD.
  • Governance Pipeline Auditor — score your existing Spectral CI setup against a maturity rubric.
  • Governance Coverage — measure how much of your API description your rules actually examine.
  • Governance Waivers — make exceptions sanctioned, owned, and expiring instead of ad-hoc.
  • API Governance Graph — bind the governance building blocks into one navigable graph.
  • API Certification — issue and verify tamper-evident governance certificates.
  • API Governance MCP — the same ruleset as an MCP server an agent can call mid-task.
  • Agent Rule Export — turn a ruleset into agent-native guidance so agents follow it while authoring.
  • MCP Install — a universal install interface for MCP servers across every client.
  • Context Gate — govern what agents are allowed to consume, not just what you produce.

Read down that list and you can see the arc I have been building toward. It starts with the everyday acts of checking and finding an API, moves through the machinery of writing, running, and measuring governance, and ends where I think the real work is now: governing what agents produce and, with Context Gate, what they are allowed to consume. Every one of these is open, most run entirely in your browser, and all of them treat a spectral- ruleset as the portable artifact that travels between them. If you only remember one thing from the series, let it be that the rules are the product, and the tools are just different surfaces for the same rules.

You can find all of them, and whatever I ship next, on the API Commons tools page. Thanks for following along, one morning at a time.