---
title: "API Catalog · Sitebulb Labs"
description: "RFC 9727 /.well-known/api-catalog lets agents discover available APIs."
url: https://labs.sitebulb.com/docs/checks/protocol-discovery/api-catalog/
---

# API Catalog

RFC 9727 /.well-known/api-catalog lets agents discover available APIs.

- Category

  [Protocol discovery](https://labs.sitebulb.com/docs/checks/protocol-discovery)

- Standard

  Recommended

## What it checks

The extension fetches `/.well-known/api-catalog`, the location RFC 9727 defines for a list of a publisher’s APIs. It passes when the response is successful, non-empty, and JSON: the `Content-Type` mentions `json` (RFC 9727 uses `application/linkset+json`), or the body starts with `{` or `[`. The contents are not otherwise validated.

## Results

| Status   | When                                               |
| -------- | -------------------------------------------------- |
| **Pass** | `/.well-known/api-catalog` returns a JSON document |
| **N/A**  | The path is missing or does not return JSON        |

## How to fix

If you publish APIs, serve a linkset at `/.well-known/api-catalog` that links to each API’s description documents:

```json
{
  "linkset": [
    {
      "anchor": "https://api.example.com/v1",
      "service-desc": [
        { "href": "https://api.example.com/v1/openapi.json", "type": "application/json" }
      ],
      "service-doc": [{ "href": "https://example.com/docs/api", "type": "text/html" }]
    }
  ]
}
```

Serve it with `Content-Type: application/linkset+json`.

Related: [OAuth Authorization Server discovery](https://labs.sitebulb.com/docs/checks/protocol-discovery/oauth-discovery).
