Skip to content
All case studies

05 · Platform · API

Making the Launch API public

A REST layer alongside the internal GraphQL API, a single merged OpenAPI surface, public domains, pen-tested and documented before exposure.

2
services given REST layers
1
merged OpenAPI spec
1
InfoSec pen test before launch

The problem

Launch's API was GraphQL and internal. Customers automating deployments and cache invalidation had no supported surface, and 'public' is a different bar from 'works'.

What I built

A REST layer in both the management service and the logs service, their OpenAPI specs merged into one surface, a public domain to host the APIs, and the routing to make the OpenAPI path resolve correctly across cloud environments.

Then the assurance layer: an InfoSec penetration test on the new APIs, a documentation phase with the technical writing team, the round of fixes that followed real exposure, and addressing a project by its own UID rather than requiring the organisation UID on every call.