Unused request body component (OpenAPI 3.0)

A shared request body definition is not connected to an API operation

Description

Bodies defined in components.requestBodies are used through an operation’s requestBody. A shared definition alone does not document that the operation accepts a body.

Potential impact

The relationship between an operation’s input and the shared definition may be unclear, adding unnecessary work when inputs change.

Remediation

Reference needed definitions from operations that accept a body, matching the content type and schema to actual requests. Remove unnecessary definitions only after checking external document use.

Examples

These POST examples reference MyObjectBody from the operation’s requestBody.

Before

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "Success",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MyObject"
                }
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "MyObject": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        }
      }
    },
    "requestBodies": {
      "MyObjectBody": {
        "description": "A JSON object containing my object information",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/MyObject"
            }
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API Overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "post": {
        "operationId": "listVersionsv2",
        "summary": "List API versions",
        "responses": {
          "200": {
            "description": "Success",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/MyObject"
                }
              }
            }
          }
        },
        "requestBody": {
          "$ref": "#/components/requestBodies/MyObjectBody"
        }
      }
    }
  },
  "components": {
    "schemas": {
      "MyObject": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        }
      }
    },
    "requestBodies": {
      "MyObjectBody": {
        "description": "A JSON object containing my object information",
        "content": {
          "application/json": {
            "schema": {
              "$ref": "#/components/schemas/MyObject"
            }
          }
        }
      }
    }
  }
}

References