# Vendor facets — Kiota. Microsoft's open-source OpenAPI client generator (the engine behind the # Microsoft Graph SDKs). The headline: it is mostly a consumer-side tool, run by whoever calls an # API to build a client inside their own app. It moves a provider's score only when the provider # publishes and declares the generated clients, or a CLI from its `shell` target. vendor: kiota name: Kiota website: https://learn.microsoft.com/en-us/openapi/kiota/overview areas: - sdk-generation registry_keys: [] rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Kiota generates typed API clients for C#, Go, Java, PHP, Python, Ruby, Swift and TypeScript, plus a `shell` target. Maturity ranges from stable (C#, Go, PHP, Python) to experimental. Most Kiota clients are built by API consumers inside their own code, so they never reach the provider's surface. The score moves only when a provider publishes the clients and declares them as SDKs, or ships a shell CLI. Its pre-generation validation warnings (for example NoServerEntry) only help a contract the provider then fixes. Kiota has no docs, MCP, llms.txt or skill output. features: - id: client-generation name: API client generation description: >- Strongly typed clients built on a small core library, for C#, Go, Java, PHP, Python, Ruby, Swift and TypeScript, with maturity levels reported by `kiota info`. source: https://learn.microsoft.com/en-us/openapi/kiota/using tier: open-source - id: shell-target name: shell language target description: The generator accepts `shell` as a target language, producing a command-line client. source: https://learn.microsoft.com/en-us/openapi/kiota/using tier: open-source - id: validation-rules name: Pre-generation validation rules description: >- Warnings such as NoServerEntry, MultipleServerEntries, MissingDiscriminator, GetWithBody and DivergentResponseSchema, raised before a client is generated. source: https://learn.microsoft.com/en-us/openapi/kiota/using tier: open-source - id: path-filtering name: Path filtering and lock file description: >- Generates only the paths selected with include/exclude globs and records parameters and a description hash in kiota-lock.json. source: https://learn.microsoft.com/en-us/openapi/kiota/using tier: open-source - id: description-search name: API description search description: >- The `kiota search` and `kiota download` commands find API descriptions in registries such as APIs.guru and GitHub. source: https://learn.microsoft.com/en-us/openapi/kiota/using tier: open-source maps: - feature: client-generation check: sdk_count_1 layer: composite provider_must: >- Publish a generated client as a maintained package and declare it as an SDK entry. A client a consumer generates inside its own app never counts. catalog_pass_rate: 0.148 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.413 - feature: client-generation check: sdk_count_3 layer: composite provider_must: Publish and declare three or more language clients. catalog_pass_rate: 0.018 facet: developer_ergonomics points: 4 baseline_pass_rate: 0.043 - feature: shell-target check: cli_present layer: composite provider_must: Release the generated shell client as a CLI and declare it as a CLI entry. catalog_pass_rate: 0.063 facet: developer_ergonomics points: 3 baseline_pass_rate: 0.19 - feature: validation-rules check: servers_defined layer: composite conditional: true condition: >- NoServerEntry only warns. The provider has to add a real host to the published contract, and the API has to have one. catalog_pass_rate: 0.782 facet: contract_quality points: 3 baseline_pass_rate: 0.835 earns_nothing: - feature: description-search check: apis_json_self_hosted why: >- Kiota's search reads third-party registries. It publishes nothing about the provider and does not host an index for it. - feature: path-filtering check: contract_present why: Filtering a description produces a client for a subset of paths. It publishes no contract. - feature: client-generation check: idempotency layer: agent_readiness why: The client reflects the contract and adds no idempotency key to it. out_of_reach: checks: - documentation_present - api_reference_present - mcp_server - llms_txt_published - agent_skills - agent_skill_present - examples_present - postman_present - overlay_published note: The documented commands have no docs, MCP, llms.txt, skill, example or overlay output. unscored_practice: - feature: path-filtering why: >- A committed kiota-lock.json records exactly which contract version a client was built from. That is provenance no check reads. surface: contract_quality: reachable: 3.0 total: 211 developer_ergonomics: reachable: 10.0 total: 42 agent_readiness: reachable: 0 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://learn.microsoft.com/en-us/openapi/kiota/using measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8835 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 4.7 p75: 4.8 p90: 4.8 max: 4.8 mean_among_movers: 4.1 agent_readiness_lift: median: 0.0 p75: 0.0 p90: 0.0 max: 0.0 mean_among_movers: 0.0 facet_lift_median_among_movers: developer_ergonomics: 23.8 composite_band_moves: thin -> developing: 1410 developing -> strong: 733 emerging -> thin: 289 strong -> exemplar: 211 minimal -> emerging: 2 agent_readiness_band_moves: {} method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written