OpenAPI 2.0

Guidance on authentication, transport security, request and response definitions, and references in OpenAPI 2.0 documents.

Documentation

Article Path
Body parameter is missing schema (OpenAPI 2.0) openAPI/2.0/body_parameter_without_schema
Invalid body parameter property (OpenAPI 2.0) openAPI/2.0/body_parameter_with_wrong_property
An OpenAPI 2.0 scheme uses the OAuth2 implicit flow openAPI/2.0/implicit_flow_oauth2
Global authentication uses the OAuth2 password flow openAPI/2.0/global_security_using_password_flow
Invalid OAuth2 authorization URL in OpenAPI 2.0 openAPI/2.0/invalid_oauth_authorization_url
Invalid OAuth2 token URL in OpenAPI 2.0 openAPI/2.0/invalid_oauth2_token_url
Unknown properties in an OpenAPI 2.0 object openAPI/2.0/unknown_property
Global OpenAPI schemes include HTTP openAPI/2.0/global_schemes_uses_http
Missing request media type for an operation openAPI/2.0/operation_object_without_consumes
Missing response media type for an operation openAPI/2.0/operation_object_without_produces
Review Basic authentication for an OpenAPI 2.0 operation openAPI/2.0/operation_using_basic_auth
An operation uses the OAuth2 implicit flow openAPI/2.0/operation_using_implicit_flow
An operation uses the OAuth2 password flow openAPI/2.0/operation_using_password_flow
An OpenAPI operation allows HTTP openAPI/2.0/path_scheme_accepts_http
Review the Basic authentication definition in OpenAPI 2.0 openAPI/2.0/security_definitions_using_basic_auth
OAuth2 password flow in security definitions openAPI/2.0/security_definitions_allows_password_flow
Review additional property policy in OpenAPI 2.0 openAPI/2.0/schema_with_additional_properties_set_as_boolean
Invalid location for collectionFormat: multi (OpenAPI 2.0) openAPI/2.0/multi_collectionformat_not_valid_in_parameter
Invalid basePath format (OpenAPI 2.0) openAPI/2.0/basepath_with_wrong_format
Non-body parameter uses schema (OpenAPI 2.0) openAPI/2.0/non_body_parameter_with_schema
Review enum constraints in OpenAPI 2.0 openAPI/2.0/constraining_enum_property
Invalid host format (OpenAPI 2.0) openAPI/2.0/host_with_invalid_pattern
Review operation summary length in OpenAPI 2.0 openAPI/2.0/operation_summary_too_long
Incorrect parameter object reference (OpenAPI 2.0) openAPI/2.0/parameter_object_incorrect_ref
Incorrect response object reference (OpenAPI 2.0) openAPI/2.0/response_object_incorrect_ref
Incorrect schema object reference (OpenAPI 2.0) openAPI/2.0/schema_object_incorrect_ref
Authentication schemes are missing from an OpenAPI 2.0 document openAPI/2.0/security_definitions_undefined_or_empty
OpenAPI 2.0 security references an undefined authentication scheme openAPI/2.0/security_requirement_not_defined_in_security_definition
Invalid media type syntax in OpenAPI 2.0 openAPI/2.0/invalid_media_type_value
Review media type prefixes in OpenAPI 2.0 openAPI/2.0/unknown_prefix
OAuth2 scopes used with non-OAuth2 authentication openAPI/2.0/non_oauth2_security_requirement_defining_oauth2_scopes
Unused global parameter definition (OpenAPI 2.0) openAPI/2.0/unused_parameter_definition
Unused global response definition (OpenAPI 2.0) openAPI/2.0/unused_response_definition
Unused global schema definition (OpenAPI 2.0) openAPI/2.0/unused_schema_definition
Response examples differ from produces in OpenAPI 2.0 openAPI/2.0/operation_example_mismatch_produces_mediatype
Undefined OAuth2 scope in operation security requirements openAPI/2.0/undefined_security_scope_security_operations
HTTP transport documented in OpenAPI 2.0 openAPI/2.0/schemes-http-vulnerabilities-iac-openapi-2.0-schemes_uses_http-copy-md
Undefined OAuth2 scope in global security requirements openAPI/2.0/undefined_security_scope_global_security
Parameter reference does not exist (OpenAPI 2.0) openAPI/2.0/json_reference_does_not_exists_parameter
Response reference does not exist (OpenAPI 2.0) openAPI/2.0/json_reference_does_not_exists_response
Schema reference does not exist (OpenAPI 2.0) openAPI/2.0/json_reference_does_not_exists_schema
Review model property names in OpenAPI 2.0 openAPI/2.0/property_not_unique
File parameter has an invalid location (OpenAPI 2.0) openAPI/2.0/parameter_file_type_not_in_formdata
Incorrect consumes format for file upload (OpenAPI 2.0) openAPI/2.0/file_parameter_with_wrong_consumes_property
Required properties missing from an OpenAPI 2.0 object openAPI/2.0/object_without_required_property
Multiple body parameters in one operation (OpenAPI 2.0) openAPI/2.0/multi_body_parameters_same_operation
Operation mixes body and formData parameters (OpenAPI 2.0) openAPI/2.0/operation_object_parameters_with_body_and_formatdata

Related pages47

Body parameter is missing schema (OpenAPI 2.0)

The schema describing the request body is missing

Invalid body parameter property (OpenAPI 2.0)

A body parameter property is neither a standard field nor a valid extension

An OpenAPI 2.0 scheme uses the OAuth2 implicit flow

The OAuth2 implicit flow sends an access token directly in the authorization response.

Global authentication uses the OAuth2 password flow

The OAuth2 password flow makes the client handle the user's password directly.

Invalid OAuth2 authorization URL in OpenAPI 2.0

An incorrect OAuth2 authorization URL in OpenAPI 2.0 can prevent login and consent.

Invalid OAuth2 token URL in OpenAPI 2.0

tokenUrl must identify the OAuth2 provider's correct token endpoint.

Unknown properties in an OpenAPI 2.0 object

Correct misspelled standard fields and use supported extension forms.

Global OpenAPI schemes include HTTP

HTTP in global schemes advertises unencrypted API communication.

Missing request media type for an operation

Check that the media type accepted by an API request body is documented.

Missing response media type for an operation

Check that response body media types are specified in OpenAPI 2.0.

Review Basic authentication for an OpenAPI 2.0 operation

Check transport protection and credential reuse risks for operation-level Basic authentication.

An operation uses the OAuth2 implicit flow

The client receives an access token directly in the authorization response when an operation uses the OAuth2 implicit flow.

An operation uses the OAuth2 password flow

Using the OAuth2 password flow for an operation makes clients submit the user's password directly.

An OpenAPI operation allows HTTP

HTTP in operation-level schemes advertises plaintext communication for that operation.

Review the Basic authentication definition in OpenAPI 2.0

Check where the Basic authentication definition is used and how credentials are protected.

OAuth2 password flow in security definitions

The OAuth2 password flow gives the client the user's password and must not be used.

Review additional property policy in OpenAPI 2.0

Choose additionalProperties to match the data contract.

Invalid location for collectionFormat: multi (OpenAPI 2.0)

An array uses multi outside query or formData

Invalid basePath format (OpenAPI 2.0)

The API’s shared path does not start with a slash

Non-body parameter uses schema (OpenAPI 2.0)

A query, path, header, or formData parameter specifies schema

Review enum constraints in OpenAPI 2.0

Check that constraints used with enum preserve the intended allowed values.

Invalid host format (OpenAPI 2.0)

The API host contains a path, scheme, or another invalid element

Review operation summary length in OpenAPI 2.0

Keep the operation summary concise and put details in description.

Incorrect parameter object reference (OpenAPI 2.0)

A parameter reference points to the wrong kind of object

Incorrect response object reference (OpenAPI 2.0)

A response references a data schema or another incorrect object

Incorrect schema object reference (OpenAPI 2.0)

A schema location references a response or another incorrect object

Authentication schemes are missing from an OpenAPI 2.0 document

Define and apply the authentication schemes required by an API in securityDefinitions and security.

OpenAPI 2.0 security references an undefined authentication scheme

Authentication names in security must match definitions in securityDefinitions.

Invalid media type syntax in OpenAPI 2.0

Use valid media types in consumes and produces.

Review media type prefixes in OpenAPI 2.0

Write media type names with the correct type and subtype.

OAuth2 scopes used with non-OAuth2 authentication

Basic and API key authentication in OpenAPI 2.0 require an empty scope array in security requirements.

Unused global parameter definition (OpenAPI 2.0)

A reusable parameter is not referenced where it is needed

Unused global response definition (OpenAPI 2.0)

A shared response definition is not connected to an operation

Unused global schema definition (OpenAPI 2.0)

A shared model remains without use in requests or responses

Response examples differ from produces in OpenAPI 2.0

Align response example media types with the formats supported by the operation.

Undefined OAuth2 scope in operation security requirements

An OpenAPI 2.0 operation references an undefined OAuth2 scope in its security requirements.

HTTP transport documented in OpenAPI 2.0

Check the documented API transport together with the actual HTTPS configuration.

Undefined OAuth2 scope in global security requirements

Global security requirements in OpenAPI 2.0 reference an undefined OAuth2 scope.

Parameter reference does not exist (OpenAPI 2.0)

A referenced shared parameter is missing

Response reference does not exist (OpenAPI 2.0)

A shared response reference does not match an existing definition

Schema reference does not exist (OpenAPI 2.0)

A reference points to a model missing from definitions

Review model property names in OpenAPI 2.0

Name properties for their meaning within each model and avoid unnecessary API contract changes.

File parameter has an invalid location (OpenAPI 2.0)

A type: file parameter is outside formData

Incorrect consumes format for file upload (OpenAPI 2.0)

The request media type does not match a file parameter

Required properties missing from an OpenAPI 2.0 object

Provide the properties required for each object type and configuration.

Multiple body parameters in one operation (OpenAPI 2.0)

An API operation defines more than one in: body parameter

Operation mixes body and formData parameters (OpenAPI 2.0)

One API operation uses both body and form parameters