Every API team has a postmortem that starts with "we didn't think that was a breaking change." A field that was always present becomes optional; an enum gains a value clients treat as exhaustive; a response code changes from 200 to 201; a query parameter that used to be ignored is now required. None of these show up in code review as dangerous, because code review shows the server diff, not the contract diff. The fix is boring and extremely effective: diff the OpenAPI document against the last r...