Any API or SDK

If your code depends on it, Mendward can watch it.

OpenAI, Stripe, Twilio and Supabase are presets, not the boundary. A customer should be able to point Mendward at a company it has never heard of, and that should be configuration, not a code change.

Live OpenAPI sources today. In development The universal source system described on this page.

Add a source in under a minute.

A preview of the flow. Pick a kind, give it an address, and see the observation Mendward would record. Nothing here leaves your browser.

Source kind
Fetched through an allowlisted, redirect-checked client. Credentials are stored apart from the source, never in it.
Check every
sources/acmeunknownapi.yamlDraft

One spine for every source.

01

Source

Anything with a stable address: a spec URL, a package, a repository, a schema, a changelog, or a webhook you call. A preset is just a source someone already configured.

source:
  id: src_acme_ledger
  kind: openapi
  url: https://api.acme.dev/openapi.json
  credentials: none

02

Observation

What was fetched, when, and from where, with the raw bytes and their SHA-256. Provenance is never thrown away: the extractor, its version and every parse warning come along.

observation:
  fetchedAt: 2026-10-05T09:14:02Z
  contentSha256: 9f3c4a1e...b07de21a
  status: 200
  bytes: 421,880
  extractor: openapi@3

03

Contract

Every dialect compiles into one interface model: operations, types, properties, enums, requiredness, auth. From here on, nothing knows which company published it.

contract:
  operations: 86
  types: 140
  LedgerEntry:
    entry_id: string, required
    amount: integer, required

04

Semantic change

Two contracts in, typed changes out. Each one keeps its evidence: a pointer into the source, the before and after, and how sure the differ is.

change:
  kind: property_renamed
  from: LedgerEntry.entryRef
  to: LedgerEntry.entry_id
  direction: response
  evidence: #/components/schemas/...

Changes, in a vocabulary your code understands.

An OpenAPI rename, a GraphQL field removal and an SDK export change all land as the same primitive, with the same evidence, so the rest of the pipeline never needs to know where they came from.

  • endpoint_addedA new operation exists.
  • endpoint_removedAn operation you may call is gone.
  • operation_changedSame path, different contract.
  • symbol_renamedAn exported name moved.
  • symbol_removedAn export you import no longer exists.
  • property_renamedA field kept its meaning and lost its name.
  • property_removedA field your code reads is gone.
  • requiredness_changedOptional became required, or the reverse.
  • parameter_addedA call now needs one more argument.
  • parameter_renamedSame argument, new key.
  • type_narrowedFewer values are accepted.
  • type_widenedMore values can come back.
  • enum_member_addedA new status your switch does not handle.
  • enum_member_removedA value you send is refused.
  • response_changedThe shape that comes back moved.
  • auth_requirement_changedA call now needs a different scope.

In development

The test with a company that does not exist.

AcmeUnknownAPI appears nowhere in Mendward's source code. It is added the way a customer would add it, by configuration, and it has to travel the whole way: observe, diff, impact, migration, verification and evidence. Until that test is green, "any API" is a direction. When it is, it is a fact.

  1. 1Observe
  2. 2Diff
  3. 3Impact
  4. 4Migration
  5. 5Verify
  6. 6Evidence

Tell us which API keeps breaking your code.

Beta teams shape which presets, formats and ecosystems arrive first.

Request access
0:00 / 1:08
UpDown to moveEnter to runType / for a few more