1. Identify resources and operations. 2. Define request and response shapes. 3. Specify validation and error semantics. 4. Consider authentication and authorization boundaries. 5. Define pagination, filtering, idempotency, and versioning only when needed. 6. Add examples and verification cases.