API Catalog

RFC 9727 /.well-known/api-catalog lets agents discover available APIs.

Standard
Recommended

What it checks

The extension fetches /.well-known/api-catalog, the location RFC 9727 defines for a list of a publisher’s APIs. It passes when the response is successful, non-empty, and JSON: the Content-Type mentions json (RFC 9727 uses application/linkset+json), or the body starts with { or [. The contents are not otherwise validated.

Results

Status When
Pass /.well-known/api-catalog returns a JSON document
N/A The path is missing or does not return JSON

How to fix

If you publish APIs, serve a linkset at /.well-known/api-catalog that links to each API’s description documents:

{
  "linkset": [
    {
      "anchor": "https://api.example.com/v1",
      "service-desc": [
        { "href": "https://api.example.com/v1/openapi.json", "type": "application/json" }
      ],
      "service-doc": [{ "href": "https://example.com/docs/api", "type": "text/html" }]
    }
  ]
}

Serve it with Content-Type: application/linkset+json.

Related: OAuth Authorization Server discovery.