OpenAPI 3.0

Guidance on security settings, schemas, media types and component references in OpenAPI 3.0 documents.

Documentation

Article Path
Incorrect callback object reference (OpenAPI 3.0) openAPI/3.0/callback_object_incorrect_ref
Unused OpenAPI 3.0 callback component openAPI/3.0/components_callback_definition_unused
Unused example component (OpenAPI 3.0) openAPI/3.0/components_example_definition_unused
Unused header component (OpenAPI 3.0) openAPI/3.0/components_header_definition_unused
Unused OpenAPI 3.0 link component openAPI/3.0/components_link_definition_unused
Invalid OpenAPI 3.0 component name openAPI/3.0/components_object_fixed_field_key_improperly_named
Unused parameter component (OpenAPI 3.0) openAPI/3.0/components_parameter_definition_unused
Unused request body component (OpenAPI 3.0) openAPI/3.0/components_request_body_definition_unused
Unused response component (OpenAPI 3.0) openAPI/3.0/components_response_definition_unused
Unused schema component (OpenAPI 3.0) openAPI/3.0/components_schema_definition_unused
Review empty arrays in OpenAPI 3.0 openAPI/3.0/empty_array
Misplaced Content-Type in OpenAPI 3.0 encoding openAPI/3.0/encoding_header_content_type_improperly_defined
OpenAPI 3.0 encoding key does not match a schema property openAPI/3.0/encoding_map_key_mismatch_schema_defined_properties
Incorrect example object reference (OpenAPI 3.0) openAPI/3.0/example_json_reference_outside_components_examples
Review protection for OpenAPI HTTP Basic authentication openAPI/3.0/security_scheme_using_http_basic
Review HTTP Digest authentication (OpenAPI 3.0) openAPI/3.0/security_scheme_using_http_digest
Review HTTP Negotiate authentication (OpenAPI 3.0) openAPI/3.0/security_scheme_using_http_negotiate
Review the HTTP authentication scheme openAPI/3.0/security_schemes_http_unknown_scheme
Incorrect header object reference (OpenAPI 3.0) openAPI/3.0/header_object_with_incorrect_ref
Missing header value definition openAPI/3.0/header_object_without_schema
Missing schema for API body content openAPI/3.0/media_type_object_without_schema
Review the legacy OAuth security scheme openAPI/3.0/security_schemes_using_oauth
Invalid OAuth2 authorization URL in OpenAPI 3.0 openAPI/3.0/invalid_oauth_authorization_url
Invalid OAuth2 token URL in OpenAPI 3.0 openAPI/3.0/invalid_oauth2_token_url
An OpenAPI 3.0 scheme uses the OAuth2 implicit flow openAPI/3.0/oauth2_with_implicit_flow
An OpenAPI 3.0 scheme uses the OAuth2 password flow openAPI/3.0/oauth2_with_password_flow
Undefined OAuth2 scope in an OpenAPI 3 operation openAPI/3.0/undefined_security_scope_security_operations
Undefined OAuth2 scope in global OpenAPI 3 security requirements openAPI/3.0/undefined_security_scope_global_security
Review OpenAPI property names and placement openAPI/3.0/unknown_property
Required property missing from an OpenAPI 3.0 object openAPI/3.0/object_without_required_property
Additional properties are too restrictive (OpenAPI 3.0) openAPI/3.0/additional_properties_too_restrective
Additional properties are too permissive (OpenAPI 3.0) openAPI/3.0/additional_properties_too_permissive
Review transport protection for Basic authentication on an OpenAPI 3.0 operation openAPI/3.0/cleartext_credentials_with_basic_auth_for_operation
Missing parameter value definition openAPI/3.0/parameter_object_without_schema
An OpenAPI operation server uses HTTP openAPI/3.0/path_server_uses_http
Missing security scheme definition openAPI/3.0/security_scheme_undefined
TRACE success response is undefined (OpenAPI 3.0) openAPI/3.0/success_response_code_undefined_trace_operation
Review parameter allowEmptyValue applicability openAPI/3.0/property_allow_empty_value_ignored
allowReserved is set for an inapplicable parameter location openAPI/3.0/property_allow_reserved_improperly_defined
Review Encoding Object allowReserved applicability openAPI/3.0/property_allow_reserved_encoding_object_ignored
Review Encoding Object explode applicability openAPI/3.0/property_explode_encoding_object_ignored
Review Encoding Object style applicability openAPI/3.0/property_type_encoding_object_ignored
Incorrect link object reference (OpenAPI 3.0) openAPI/3.0/link_object_incorrect_ref
OpenAPI link defines both operationId and operationRef openAPI/3.0/link_object_with_both_operation_id_and_operation_ref
OpenAPI link operationId has no matching operation openAPI/3.0/link_object_operation_id_does_not_target_an_operation_object
Operation security requirement references an undefined scheme openAPI/3.0/security_operation_field_undefined
Incorrect parameter object reference (OpenAPI 3.0) openAPI/3.0/parameter_object_incorrect_ref
Parameter object defines both schema and content openAPI/3.0/parameter_object_schema_content
Parameter object lacks schema or content openAPI/3.0/parameter_object_undefined_type
Multiple content entries in an OpenAPI 3.0 parameter openAPI/3.0/parameter_object_content_with_multiple_entries
Incorrect request body reference (OpenAPI 3.0) openAPI/3.0/request_body_incorrect_ref
Request body encoding conflicts with its media type openAPI/3.0/request_body_object_with_incorrect_media_type
Incorrect response object reference (OpenAPI 3.0) openAPI/3.0/response_object_incorrect_ref
Incorrect schema object reference (OpenAPI 3.0) openAPI/3.0/schema_object_incorrect_ref
Schema property has conflicting readOnly and writeOnly settings openAPI/3.0/schema_with_both_read_only_and_write_only
Scopes specified for an incompatible security scheme openAPI/3.0/security_requirement_object_with_wrong_scopes
Server URL variable definition is missing openAPI/3.0/server_url_uses_undefined_variables
Review the base address of a relative server URL openAPI/3.0/server_url_not_absolute
Review the default OpenAPI server address openAPI/3.0/servers_undefined
Review the OpenAPI media type prefix openAPI/3.0/unknown_prefix
Review content type for multiple file uploads in OpenAPI 3.0 openAPI/3.0/invalid_content_type_for_multiple_files_upload
Invalid media type syntax in OpenAPI 3.0 openAPI/3.0/invalid_media_type_value
Review the reusable Basic authentication definition in OpenAPI 3.0 openAPI/3.0/global_security_scheme_using_basic_authentication
Review HTTPS use for global OpenAPI servers openAPI/3.0/global_server_uses_http
Global security requirement references an undefined scheme openAPI/3.0/security_field_undefined
Review API key authentication (OpenAPI 3.0) openAPI/3.0/api_key_exposed_in_global_security_scheme
Server variable is not used in the URL openAPI/3.0/server_object_variable_not_used
Missing OpenAPI 3.0 callback reference target openAPI/3.0/json_reference_does_not_exists_callback
Missing OpenAPI 3.0 example reference target openAPI/3.0/json_reference_does_not_exists_example
Missing OpenAPI 3.0 header reference target openAPI/3.0/json_reference_does_not_exists_header
Missing OpenAPI 3.0 link reference target openAPI/3.0/json_reference_does_not_exists_link
Missing OpenAPI 3.0 parameter reference target openAPI/3.0/json_reference_does_not_exists_parameter
Missing OpenAPI 3.0 request body reference target openAPI/3.0/json_reference_does_not_exists_request_body
Missing OpenAPI 3.0 response reference target openAPI/3.0/json_reference_does_not_exists_response
Missing OpenAPI 3.0 schema reference target openAPI/3.0/json_reference_does_not_exists_schema

Related pages75

Incorrect callback object reference (OpenAPI 3.0)

A callback reference does not point to a valid callback definition

Unused OpenAPI 3.0 callback component

Reference needed callbacks from operations and remove unnecessary definitions.

Unused example component (OpenAPI 3.0)

A reusable example is not connected to the API description

Unused header component (OpenAPI 3.0)

A shared header definition is not connected to where it is used

Unused OpenAPI 3.0 link component

Reference needed links from responses and remove unnecessary definitions.

Invalid OpenAPI 3.0 component name

Use letters, digits, periods, hyphens and underscores in component names.

Unused parameter component (OpenAPI 3.0)

A reusable parameter is not applied to a path or operation

Unused request body component (OpenAPI 3.0)

A shared request body definition is not connected to an API operation

Unused response component (OpenAPI 3.0)

A shared response definition is not connected to an operation’s responses

Unused schema component (OpenAPI 3.0)

A model definition remains outside the actual data contract

Review empty arrays in OpenAPI 3.0

Check each field’s meaning instead of filling every empty array.

Misplaced Content-Type in OpenAPI 3.0 encoding

Use encoding contentType for the media type of a multipart part.

OpenAPI 3.0 encoding key does not match a schema property

Match encoding keys to properties defined in the schema.

Incorrect example object reference (OpenAPI 3.0)

An example references a schema or another wrong object type

Review protection for OpenAPI HTTP Basic authentication

Protect credentials and connections that use HTTP Basic authentication.

Review HTTP Digest authentication (OpenAPI 3.0)

Check transport protection and password strength for Digest authentication

Review HTTP Negotiate authentication (OpenAPI 3.0)

Check environment compatibility and transport protection for Negotiate

Review the HTTP authentication scheme

Check that the HTTP authentication scheme in OpenAPI 3.0 matches the implementation and supported tooling.

Incorrect header object reference (OpenAPI 3.0)

A response header reference does not point to a valid Header Object

Missing header value definition

Define an OpenAPI 3.0 header's value using schema or content.

Missing schema for API body content

Define schemas that communicate the structure of request and response bodies.

Review the legacy OAuth security scheme

Review support for legacy OAuth and the authentication flow actually used by the API.

Invalid OAuth2 authorization URL in OpenAPI 3.0

Check that the OAuth2 authorization URL in OpenAPI 3.0 identifies the correct authorization server endpoint.

Invalid OAuth2 token URL in OpenAPI 3.0

An OAuth2 flow's tokenUrl must identify the provider's correct HTTPS token endpoint.

An OpenAPI 3.0 scheme uses the OAuth2 implicit flow

The OAuth2 implicit flow returns an access token in the authorization response, increasing leakage risks.

An OpenAPI 3.0 scheme uses the OAuth2 password flow

The OAuth2 password flow exposes the user's password to the client.

Undefined OAuth2 scope in an OpenAPI 3 operation

An OpenAPI 3.0 operation requires a scope absent from its OAuth2 definition.

Undefined OAuth2 scope in global OpenAPI 3 security requirements

Global security requirements in OpenAPI 3.0 do not match the OAuth2 scope definitions.

Review OpenAPI property names and placement

Check the property names and locations allowed by each object.

Required property missing from an OpenAPI 3.0 object

Include the required properties for each OpenAPI object.

Additional properties are too restrictive (OpenAPI 3.0)

An additional-property restriction rejects fields that the API should allow

Additional properties are too permissive (OpenAPI 3.0)

An object intended to accept only defined fields permits additional properties

Review transport protection for Basic authentication on an OpenAPI 3.0 operation

Check that an operation using Basic authentication actually connects over HTTPS.

Missing parameter value definition

Specify an OpenAPI 3.0 parameter's type and representation using schema or content.

An OpenAPI operation server uses HTTP

An HTTP operation server address can send that API call over a plaintext connection.

Missing security scheme definition

Check that an API requiring authentication defines its scheme in OpenAPI 3.0.

TRACE success response is undefined (OpenAPI 3.0)

A supported TRACE operation lacks a documented success response

Review parameter allowEmptyValue applicability

Check where allowEmptyValue applies and how empty values are actually handled.

allowReserved is set for an inapplicable parameter location

Use parameter allowReserved only for query parameters.

Review Encoding Object allowReserved applicability

Use encoding.allowReserved only with the applicable URL-encoded form body.

Review Encoding Object explode applicability

Match encoding.explode to the body format and value type.

Review Encoding Object style applicability

Choose an applicable serialization style for URL-encoded form fields.

Incorrect link object reference (OpenAPI 3.0)

A link describing a subsequent API operation has an invalid reference

OpenAPI link defines both operationId and operationRef

Identify a link target with either operationId or operationRef.

OpenAPI link operationId has no matching operation

Match the link’s operationId to a unique operation ID defined in the document.

Operation security requirement references an undefined scheme

Make operation-level security requirements refer to the correct scheme.

Incorrect parameter object reference (OpenAPI 3.0)

A parameter reference points to the wrong kind of definition

Parameter object defines both schema and content

Define either schema or content for a parameter.

Parameter object lacks schema or content

Describe the parameter value with schema or content.

Multiple content entries in an OpenAPI 3.0 parameter

Specify one media type in parameter content.