Invalid OAuth2 token URL in OpenAPI 3.0

An OAuth2 flow's tokenUrl must identify the provider's correct HTTPS token endpoint.

Description

In OpenAPI 3.0, an OAuth2 flow's tokenUrl identifies its token endpoint. Flows that require a token endpoint must use a valid URL and connect to the provider's actual token server over HTTPS.

Potential impact

An incorrect endpoint can prevent token issuance needed for authentication. Using HTTP or the wrong destination can expose credentials or tokens.

Remediation

Set the provider's official HTTPS tokenUrl on the applicable OAuth2 flow under components.securitySchemes. Omit URL fragments and check the client's actual destination and server certificate validation.

Examples

These examples change the token URL for the authorization code flow. The HTTP address with a fragment is replaced with the provider's correct HTTPS address.

Before

yaml
openapi: 3.0.0
components:
  securitySchemes:
    petstore_auth:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://api.my.company.com/oauth/authorize
          tokenUrl: http://example.com#@evil.com/
          scopes:
            read:api: read your apis

After

yaml
openapi: 3.0.0
components:
  securitySchemes:
    petstore_auth:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://api.my.company.com/oauth/authorize
          tokenUrl: https://api.my.company.com/oauth/token
          scopes:
            read:api: read your apis

References