API Extractor supports Spring Boot with comprehensive route extraction capabilities for REST APIs.
| Framework | Version | Detection Method | Real-World Tested |
|---|---|---|---|
| Spring Boot | 2.x, 3.x | pom.xml, build.gradle, imports, annotations |
✅ Spring Boot RealWorld |
@RestControllerand@Controllerdetection- Mapping annotations (
@GetMapping,@PostMapping, etc.) @RequestMappingwith method arrays- Path variables and request parameters
- Maven and Gradle project support
Enterprise-grade framework for building production-ready Spring applications.
package com.example.api;
import org.springframework.web.bind.annotation.*;
import java.util.List;
@RestController
@RequestMapping("/api/users")
public class UserController {
@GetMapping
public List<User> getAllUsers() {
return userService.findAll();
}
@GetMapping("/{id}")
public User getUser(@PathVariable Long id) {
return userService.findById(id);
}
@PostMapping
public User createUser(@RequestBody CreateUserRequest request) {
return userService.create(request);
}
@PutMapping("/{id}")
public User updateUser(
@PathVariable Long id,
@RequestBody CreateUserRequest request
) {
return userService.update(id, request);
}
@DeleteMapping("/{id}")
public void deleteUser(@PathVariable Long id) {
userService.delete(id);
}
@GetMapping("/search")
public List<User> searchUsers(
@RequestParam String query,
@RequestParam(required = false) Integer limit
) {
return userService.search(query, limit);
}
}Detection: pom.xml/build.gradle dependencies, imports, @RestController annotations
Validated on: Spring Boot RealWorld (12 paths, 19 endpoints)
- ✅
@RestControllerand@Controllerclass annotations - ✅ Class-level
@RequestMappingfor path prefixes - ✅ Method-level mappings:
@GetMapping,@PostMapping,@PutMapping,@DeleteMapping,@PatchMapping - ✅
@PathVariablefor path parameters (e.g.,{id}) - ✅
@RequestParamfor query parameters (includingrequired = false) - ✅
@RequestBodyfor request body detection - ✅ Multiple path parameters per endpoint
- ✅ Java type mapping to OpenAPI types (String, Integer, Long, Boolean, List, etc.)
- ✅ Path constraint normalization (
{id:int}→{id}) - ✅ DTO and model extraction
Spring Boot uses annotations to bind request data to method parameters:
@GetMapping("/users/{id}")
public User getUser(
@PathVariable Long id, // Path parameter
@RequestParam(required = false) String include // Optional query param
) {
return userService.findById(id);
}
@PostMapping("/users")
public User createUser(@RequestBody UserCreateDto dto) { // Request body
return userService.create(dto);
}# Detect and extract from Spring Boot project
api-extractor extract /path/to/spring-boot/project# Extract from Maven project (looks for pom.xml)
api-extractor extract /path/to/maven-project --output spring-api.json# Extract from Gradle project (looks for build.gradle)
api-extractor extract /path/to/gradle-project --output spring-api.yaml --format yaml# Show detailed extraction progress
api-extractor extract /path/to/spring-boot-app --verboseFor the example controller above, the extractor generates:
{
"openapi": "3.1.0",
"info": {
"title": "Extracted API",
"version": "1.0.0"
},
"paths": {
"/api/users": {
"get": {
"tags": ["spring_boot"],
"operationId": "getAllUsers",
"responses": {
"200": { "description": "Success" }
}
},
"post": {
"tags": ["spring_boot"],
"operationId": "createUser",
"responses": {
"200": { "description": "Success" }
}
}
},
"/api/users/{id}": {
"get": {
"tags": ["spring_boot"],
"operationId": "getUser",
"parameters": [
{
"name": "id",
"in": "path",
"required": true,
"schema": { "type": "string" }
}
],
"responses": {
"200": { "description": "Success" }
}
},
"put": {
"tags": ["spring_boot"],
"operationId": "updateUser",
"parameters": [
{
"name": "id",
"in": "path",
"required": true,
"schema": { "type": "string" }
}
],
"responses": {
"200": { "description": "Success" }
}
},
"delete": {
"tags": ["spring_boot"],
"operationId": "deleteUser",
"parameters": [
{
"name": "id",
"in": "path",
"required": true,
"schema": { "type": "string" }
}
],
"responses": {
"200": { "description": "Success" }
}
}
},
"/api/users/search": {
"get": {
"tags": ["spring_boot"],
"operationId": "searchUsers",
"responses": {
"200": { "description": "Success" }
}
}
}
}
}Spring Boot uses OpenAPI-compliant path parameters:
@GetMapping("/{id}")→/api/users/{id}@GetMapping("/{userId}/posts/{postId}")→/api/users/{userId}/posts/{postId}
Path constraints are automatically normalized:
{id:int}→{id}{slug:.*}→{slug}
Multiple ways to define routes:
// Method-specific annotations (preferred)
@GetMapping("/users")
@PostMapping("/users")
@PutMapping("/users/{id}")
@DeleteMapping("/users/{id}")
@PatchMapping("/users/{id}")
// Generic RequestMapping with method array
@RequestMapping(value = "/users", method = {RequestMethod.GET, RequestMethod.POST})
// Class-level prefix
@RequestMapping("/api")
public class UserController {
@GetMapping("/users") // Results in /api/users
}API Extractor can extract validation schemas from common Java libraries:
| Framework | Validation Libraries |
|---|---|
| Spring Boot | Hibernate Validator (JSR-380), Jackson Annotations |
Tested against Spring Boot RealWorld (https://github.com/gothinkster/spring-boot-realworld-example-app):
- ✅ 19 endpoints successfully extracted
- ✅
@RestControllerand@Controllerdetection - ✅ Class-level
@RequestMappingpath prefixes - ✅ Method-level mappings (
@GetMapping,@PostMapping, etc.) - ✅ Path variables with
@PathVariable(single and multiple) - ✅ Query parameters with
@RequestParam(required and optional) - ✅ Request body handling with
@RequestBody - ✅ Full RealWorld API specification (users, articles, profiles, comments, favorites, tags)
| HTTP Method | Path | Description |
|---|---|---|
| POST | /api/users |
Register user |
| POST | /api/users/login |
Login user |
| GET | /api/user |
Get current user |
| PUT | /api/user |
Update user |
| GET | /api/profiles/{username} |
Get profile |
| POST | /api/profiles/{username}/follow |
Follow user |
| DELETE | /api/profiles/{username}/follow |
Unfollow user |
| GET | /api/articles |
List articles |
| GET | /api/articles/feed |
Get feed |
| GET | /api/articles/{slug} |
Get article |
| POST | /api/articles |
Create article |
| PUT | /api/articles/{slug} |
Update article |
| DELETE | /api/articles/{slug} |
Delete article |
| POST | /api/articles/{slug}/comments |
Add comment |
| GET | /api/articles/{slug}/comments |
Get comments |
| DELETE | /api/articles/{slug}/comments/{id} |
Delete comment |
| POST | /api/articles/{slug}/favorite |
Favorite article |
| DELETE | /api/articles/{slug}/favorite |
Unfavorite article |
| GET | /api/tags |
Get tags |
- Dynamic routes: Routes defined programmatically (e.g., using custom route builders) cannot be extracted
- WebFlux: Functional routing with
RouterFunctionis not currently supported (only annotation-based controllers) - Complex path patterns: Regex-based path matchers are not fully supported
- Ensure you're running the extractor on the source directory (
src/main/java/), not compiled classes (target/orbuild/) - Check that the framework is correctly detected with
--verboseflag - Verify that controllers use
@RestControlleror@Controllerannotations
- Check that controller classes are annotated with
@RestControlleror@Controller - Verify that methods use mapping annotations (
@GetMapping,@PostMapping, etc.) - Ensure class-level
@RequestMappingis properly formatted
- Check that parameters use
@PathVariableannotation - Verify path syntax uses curly braces:
/{id}not/:id
When extracting from Docker images:
| Status | Notes |
|---|---|
| ❌ Decompilation required | .class files → .java source |
Spring Boot applications are compiled to .class files (bytecode) in Docker images. To extract API definitions:
- Extract JAR/WAR from Docker image
- Decompile using tools like:
- JD-CLI - Command-line Java decompiler
- fernflower - IntelliJ IDEA's decompiler
- Procyon - Modern Java decompiler
# Extract JAR from Docker image
docker cp container-id:/app/application.jar ./
# Extract JAR contents
unzip application.jar -d extracted/
# Decompile with fernflower
java -jar fernflower.jar extracted/BOOT-INF/classes/ decompiled/
# Run API Extractor on decompiled source
api-extractor extract decompiled/ --output api.jsonNote: Decompiled code may have formatting differences and missing comments, but API annotations are preserved.