compliance-api
Runtime request/response validation against OpenAPI specifications. Called by the gateway during API traffic to check whether actual HTTP payloads conform to the API contract. Produces scored violation reports covering path, method, query parameters, headers, request bodies, response status codes, and payloads. Results are persisted for audit and analytics. Supports dual JWT authentication — service-to-service (issuer: apiway.net) and gateway-origin requests (issuer: gateway.apiway.net).