Skip to content

Spotlight Rules

Spotlight Validator

A browser-based API governance playground — lint eleven artifact types (APIs.json, OpenAPI, MCP, Arazzo, AsyncAPI, JSON Schema, JSON Structure, JSON-LD, Plans, Rate Limits, FinOps) with Spotlight rules. Live at validator.spotlight-rules.com.

  • Search APIs.io and load real artifacts — pick an artifact type, search the APIs.io catalog, and load any result straight into the editor. The validator is a first-class internal consumer of the APIs.io API. (Requires the apis-io-aws deploy that enables CORS + the internal-tier origin.)
  • Toggle YAML ⇄ JSON — the editor converts the artifact in place.
  • A default Spotlight ruleset per artifact type — see rules/defaults/; OpenAPI/AsyncAPI/Arazzo extend the built-in Spotlight rulesets, the rest are starter rulesets to build on.
  • Powered by Spotlight, not Spectral — runs the published @spotlight-rules/spotlight-* engine entirely in the browser (no backend).
  • Best-of-breed rules compiled from the first-party API Evangelist OpenAPI governance ruleset plus public, redistribution-compatible Spectral rulesets (SPS Commerce, Adidas, Trimble, Paystack, DigitalOcean, Microcks, Baloise, Team Digitale, Schwarz IT — all Apache-2.0 or MIT). Attribution and vendored licenses are in THIRD_PARTY_NOTICES.md and rules/sources/. The AGPL-3.0 Italian Government ruleset is intentionally excluded.
  • Select rules by tag (source:*, category:*, format:*) or edit your own ruleset in a Monaco editor.

Develop

npm install
npm run compile-rules   # rebuild rules/spotlight-recommended.yaml + src/compiled-ruleset.json
npm run dev

Rules use built-in Spotlight functions only (so the compiled set runs with no custom JS); rules needing custom functions are kept in rules/sources/ for future curation. Deployed to GitHub Pages via .github/workflows/pages.yml.


Part of Spotlight Rules — a project of API Evangelist, maintained openly under API Commons.

Part of API Commons

A browser-first tool from API Commons — everything runs locally in your browser, so your tokens and data never leave it. See every tool at apicommons.org/tools and the machine-readable building blocks at apicommons.org.

Related tools

License

Apache-2.0.

API Commons licenses code under Apache-2.0 and artifacts — schemas, rulesets, examples and API descriptions — under CC BY-NC-SA 4.0.

About

The Spotlight rule catalog and validator — source of truth for the 740 rules published at apicommons.org/rules/. Restored after the original remote was lost.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages