05 · Platform · API
Making the Launch API public
A REST layer alongside the internal GraphQL API, a single merged OpenAPI surface, public domains, pen-tested and documented before exposure.
- 2
- services given REST layers
- 1
- merged OpenAPI spec
- 1
- InfoSec pen test before launch
The problem
Launch's API was GraphQL and internal. Customers automating deployments and cache invalidation had no supported surface, and 'public' is a different bar from 'works'.
What I built
A REST layer in both the management service and the logs service, their OpenAPI specs merged into one surface, a public domain to host the APIs, and the routing to make the OpenAPI path resolve correctly across cloud environments.
Then the assurance layer: an InfoSec penetration test on the new APIs, a documentation phase with the technical writing team, the round of fixes that followed real exposure, and addressing a project by its own UID rather than requiring the organisation UID on every call.