x-spotify-policy-list
`x-spotify-policy-list` appears on operations. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-spotify-` namespace, so its meaning is defined by spotify tooling rather than by OpenAPI. Consistent with size & shape — this is inferred from where the key appears and what it carries, not from any published definition.
Where it appears
| Location in the document | Occurrences | |
|---|---|---|
| operation | 41 | |
| schema | 4 |
What its value looks like
| Value shape | Occurrences |
|---|---|
| object | 35 |
| array | 10 |
Providers publishing it
All 1.
Why this is not in OpenAPI
Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the data & schema semantics job.