API governance is primarily a people and organizational challenge, not a technical one. The technical stack — OpenAPI, JSON Schema, Spectral rules, CI/CD pipelines — represents only 25% of the work. The other 75% involves building trust, managing resistance, facilitating alignment between Product, Engineering, Platform, and Consumers, and treating governance as an education and enablement function. Key lessons include: bounding the mandate early to defuse fear, owning artifacts (schemas, policies, rules) rather than tooling, making the compliant path the easiest path through scaffolding and incentives, and recognizing that inconsistent APIs are a symptom of an under-resourced, under-taught organization rather than a defiant one.

4m read timeFrom apievangelist.com
Post cover image
729 Impressions