http(s) URL, or git:<ref>:<path>, read via git show with no checkout. Both sides are normalized first, so OpenAPI 3.x, Swagger 2.0 and Postman collections all diff, even against each other. A spec split across files works when the source is a file or a git ref. Remote and absolute $refs are always refused. Needs no config file.