Important references used to anchor terminology and current standards include the following primary sources. This list is not exhaustive, and each organisation retains responsibility for its own material.
Interface and event specifications
- OpenAPI Specification — machine-readable descriptions of HTTP APIs.
- AsyncAPI Specification — descriptions of message-driven APIs, channels, operations and bindings.
- CloudEvents — a common format for describing event data.
Data and provenance
- W3C PROV Overview — a framework for provenance information.
Security
- OWASP API Security Project — current API security risks and defensive guidance.
Using sources responsibly
A standard describes a common model or interface; it does not decide whether a design suits a particular business, regulatory environment or threat model. Readers should confirm the current version, normative wording and relevant organisational requirements.