DEV Community

Jeff profile picture

Jeff

404 bio not found

Joined Joined on 
Validate HTTP requests and responses against OpenAPI at runtime: middleware, proxies, and fail-open vs fail-closed

Validate HTTP requests and responses against OpenAPI at runtime: middleware, proxies, and fail-open vs fail-closed

Comments
6 min read

Want to connect with Jeff?

Create an account to connect with Jeff. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
A2A streaming and the task lifecycle: SSE progress updates, artifacts, and push notifications

A2A streaming and the task lifecycle: SSE progress updates, artifacts, and push notifications

Comments
6 min read
Multiple security schemes in OpenAPI: AND vs OR, optional auth, and per-operation overrides

Multiple security schemes in OpenAPI: AND vs OR, optional auth, and per-operation overrides

Comments
5 min read
Health checks for APIs: /healthz, /readyz, /livez, version, and metrics in OpenAPI

Health checks for APIs: /healthz, /readyz, /livez, version, and metrics in OpenAPI

Comments
5 min read
OpenAPI docs renderers compared: Swagger UI, Redoc, Scalar, Stoplight Elements, and RapiDoc on one spec

OpenAPI docs renderers compared: Swagger UI, Redoc, Scalar, Stoplight Elements, and RapiDoc on one spec

Comments
6 min read
Enforce an API style guide in CI with Spectral: custom rules that stop bad OpenAPI before it merges

Enforce an API style guide in CI with Spectral: custom rules that stop bad OpenAPI before it merges

Comments
5 min read
OpenAPI servers and server variables: local, staging, production, regions, and per-tenant hosts from one spec

OpenAPI servers and server variables: local, staging, production, regions, and per-tenant hosts from one spec

Comments
5 min read
operationId and tags in OpenAPI: naming conventions that keep generated SDKs and docs usable

operationId and tags in OpenAPI: naming conventions that keep generated SDKs and docs usable

Comments
5 min read
Deprecating an API without breaking clients: Deprecation and Sunset headers, successor-version, and OpenAPI

Deprecating an API without breaking clients: Deprecation and Sunset headers, successor-version, and OpenAPI

Comments
5 min read
File downloads in OpenAPI: CSV, PDF, ZIP, images, Content-Disposition, and non-JSON responses

File downloads in OpenAPI: CSV, PDF, ZIP, images, Content-Disposition, and non-JSON responses

Comments
5 min read
Designing a search endpoint in OpenAPI: q, filters, sorting, sparse fieldsets, and pagination codegen understands

Designing a search endpoint in OpenAPI: q, filters, sorting, sparse fieldsets, and pagination codegen understands

Comments
5 min read
Long-running REST APIs: 202 Accepted, Location, job status polling, and webhooks in OpenAPI

Long-running REST APIs: 202 Accepted, Location, job status polling, and webhooks in OpenAPI

Comments
5 min read
Bulk and batch API endpoints: modeling create-many, partial success, and 207 Multi-Status in OpenAPI

Bulk and batch API endpoints: modeling create-many, partial success, and 207 Multi-Status in OpenAPI

Comments
5 min read
Idempotency-Key in practice: retrying POSTs safely, deduping concurrent requests, and documenting it in OpenAPI

Idempotency-Key in practice: retrying POSTs safely, deduping concurrent requests, and documenting it in OpenAPI

Comments
5 min read
Dates, times, and time zones in OpenAPI: date-time, date, duration, and the timezone mistakes that shift bookings

Dates, times, and time zones in OpenAPI: date-time, date, duration, and the timezone mistakes that shift bookings

Comments
5 min read
Modeling money and big integers in OpenAPI: int64 precision, decimal amounts, and why number fails for currency

Modeling money and big integers in OpenAPI: int64 precision, decimal amounts, and why number fails for currency

Comments
5 min read
readOnly and writeOnly in OpenAPI: one schema for create, response, and password fields

readOnly and writeOnly in OpenAPI: one schema for create, response, and password fields

Comments
5 min read
OpenAPI additionalProperties: modeling maps, dictionaries, labels, and free-form objects without losing types

OpenAPI additionalProperties: modeling maps, dictionaries, labels, and free-form objects without losing types

Comments
5 min read
Recursive and cyclic schemas in OpenAPI: self-referencing $ref for trees, nested comments, and graphs

Recursive and cyclic schemas in OpenAPI: self-referencing $ref for trees, nested comments, and graphs

Comments
5 min read
OpenAPI enums vs const: closed lists, open-ended strings, and how to add a value without breaking clients

OpenAPI enums vs const: closed lists, open-ended strings, and how to add a value without breaking clients

Comments
5 min read
Optional, nullable, or omitted? Modeling missing data in OpenAPI 3.1 without lying to clients

Optional, nullable, or omitted? Modeling missing data in OpenAPI 3.1 without lying to clients

Comments
5 min read
PUT vs JSON Merge Patch vs JSON Patch: modeling partial updates in OpenAPI without the null ambiguity

PUT vs JSON Merge Patch vs JSON Patch: modeling partial updates in OpenAPI without the null ambiguity

Comments
5 min read
OpenAPI callbacks vs webhooks: modeling async request/reply with runtime expressions

OpenAPI callbacks vs webhooks: modeling async request/reply with runtime expressions

Comments
5 min read
The JSON Schema constraints that actually work in OpenAPI: format, pattern, ranges, and what codegen and AI mocks do with them

The JSON Schema constraints that actually work in OpenAPI: format, pattern, ranges, and what codegen and AI mocks do with them

Comments
5 min read
Model polymorphism in OpenAPI 3.1: oneOf, anyOf, allOf, and discriminator without breaking clients

Model polymorphism in OpenAPI 3.1: oneOf, anyOf, allOf, and discriminator without breaking clients

Comments
4 min read
Document rate limits in OpenAPI so clients actually back off: 429, Retry-After, and rate-limit headers

Document rate limits in OpenAPI so clients actually back off: 429, Retry-After, and rate-limit headers

Comments
5 min read
Prevent lost updates with ETag and If-Match: optimistic concurrency in OpenAPI

Prevent lost updates with ETag and If-Match: optimistic concurrency in OpenAPI

Comments
4 min read
File uploads in OpenAPI: multipart/form-data, raw binary, and multiple files done right

File uploads in OpenAPI: multipart/form-data, raw binary, and multiple files done right

Comments
5 min read
Stop letting examples lie: make your OpenAPI spec the single source of truth for docs, mocks, and agents

Stop letting examples lie: make your OpenAPI spec the single source of truth for docs, mocks, and agents

Comments
4 min read
REST API versioning in 2026: paths vs headers, additive changes, and OpenAPI diffs in CI

REST API versioning in 2026: paths vs headers, additive changes, and OpenAPI diffs in CI

Comments 3
4 min read
Document API authentication in OpenAPI 3.1: Bearer, API keys, OAuth 2, and mTLS without the usual mistakes

Document API authentication in OpenAPI 3.1: Bearer, API keys, OAuth 2, and mTLS without the usual mistakes

Comments
4 min read
Reusable JSON Schema components in OpenAPI: DRY models without $ref spaghetti

Reusable JSON Schema components in OpenAPI: DRY models without $ref spaghetti

Comments 1
4 min read
AST vs AI for reverse-engineering OpenAPI: where static analysis stops and the model earns its place

AST vs AI for reverse-engineering OpenAPI: where static analysis stops and the model earns its place

Comments
5 min read
Generate OpenAPI from FastAPI and Django REST without decorating every view

Generate OpenAPI from FastAPI and Django REST without decorating every view

Comments
4 min read
Generate OpenAPI from Express and NestJS code without writing annotations by hand

Generate OpenAPI from Express and NestJS code without writing annotations by hand

Comments 2
5 min read
Bridge an existing HTTP API to A2A agents: JSON-RPC, REST, and gRPC from one handler

Bridge an existing HTTP API to A2A agents: JSON-RPC, REST, and gRPC from one handler

Comments
5 min read
The A2A Agent Card explained: discovery, supported interfaces, and signature verification

The A2A Agent Card explained: discovery, supported interfaces, and signature verification

Comments
5 min read
A2A vs MCP in 2026: when agents should talk to agents instead of calling tools

A2A vs MCP in 2026: when agents should talk to agents instead of calling tools

Comments
5 min read
LLM Structured Outputs and JSON Schema: Tool Calling That Never Drifts

LLM Structured Outputs and JSON Schema: Tool Calling That Never Drifts

Comments 2
5 min read
One MCP Gateway for All Your Internal APIs: The Aggregation Pattern

One MCP Gateway for All Your Internal APIs: The Aggregation Pattern

Comments
5 min read
MCP Security in Practice: Prompt Injection, Least Privilege, and Audit Logs

MCP Security in Practice: Prompt Injection, Least Privilege, and Audit Logs

1
Comments 2
5 min read
MCP Tools vs Resources vs Prompts: What to Expose to an AI Agent

MCP Tools vs Resources vs Prompts: What to Expose to an AI Agent

Comments
4 min read
Versioning MCP Tools Without Breaking the Agents That Call Them

Versioning MCP Tools Without Breaking the Agents That Call Them

Comments 1
4 min read
MCP Clients Compared: Claude Desktop, Cursor, VS Code, Windsurf, Cline, and Zed

MCP Clients Compared: Claude Desktop, Cursor, VS Code, Windsurf, Cline, and Zed

Comments 1
4 min read
Designing APIs for AI Agents: Idempotency, Machine-Readable Errors, and 202 + Webhooks

Designing APIs for AI Agents: Idempotency, Machine-Readable Errors, and 202 + Webhooks

Comments
5 min read
How to Test and Debug an MCP Server: From the Inspector to Automated Tool Tests

How to Test and Debug an MCP Server: From the Inspector to Automated Tool Tests

Comments
5 min read
MCP stdio vs Remote Transports: Run It Locally or Host It?

MCP stdio vs Remote Transports: Run It Locally or Host It?

Comments 2
5 min read
MCP Authentication Explained: OAuth 2.1 for Remote MCP Servers

MCP Authentication Explained: OAuth 2.1 for Remote MCP Servers

Comments
5 min read
Connect Cursor and Claude Code to your internal API over MCP (step by step)

Connect Cursor and Claude Code to your internal API over MCP (step by step)

Comments
5 min read
MCP vs function calling vs ChatGPT plugins: what API teams actually need in 2026

MCP vs function calling vs ChatGPT plugins: what API teams actually need in 2026

Comments
5 min read
API contract testing without Pact's overhead: a lighter workflow for small teams

API contract testing without Pact's overhead: a lighter workflow for small teams

Comments
4 min read
Detect breaking API changes in CI with OpenAPI diffs (before your customers do)

Detect breaking API changes in CI with OpenAPI diffs (before your customers do)

Comments
5 min read
Generate a TypeScript client from OpenAPI: openapi-typescript vs openapi-generator vs openapi-fetch

Generate a TypeScript client from OpenAPI: openapi-typescript vs openapi-generator vs openapi-fetch

Comments
5 min read
Mocking APIs for frontend development: MSW vs Prism vs spec-driven mocks

Mocking APIs for frontend development: MSW vs Prism vs spec-driven mocks

Comments
5 min read
How to document webhooks in OpenAPI 3.1 (with signatures, retries, and examples)

How to document webhooks in OpenAPI 3.1 (with signatures, retries, and examples)

Comments
4 min read
How to test WebSocket APIs: handshakes, auth, reconnection, and repeatable scenarios

How to test WebSocket APIs: handshakes, auth, reconnection, and repeatable scenarios

Comments
5 min read
How to test Server-Sent Events endpoints: curl, Postman, and spec-driven SSE testing

How to test Server-Sent Events endpoints: curl, Postman, and spec-driven SSE testing

Comments
4 min read
REST error responses in 2026: RFC 9457 Problem Details vs the envelope you invented

REST error responses in 2026: RFC 9457 Problem Details vs the envelope you invented

Comments
4 min read
Cursor vs offset pagination: what to actually put in your OpenAPI spec

Cursor vs offset pagination: what to actually put in your OpenAPI spec

Comments
4 min read
How to organize a large OpenAPI spec: multi-file structure, $ref rules, and CI checks

How to organize a large OpenAPI spec: multi-file structure, $ref rules, and CI checks

Comments 2
5 min read
loading...