An OpenAPI 3.0 scheme uses the OAuth2 password flow

The OAuth2 password flow exposes the user's password to the client.

Description

OpenAPI 3.0 OAuth2 flows.password defines a flow in which the client collects the user's password to request a token. RFC 9700 prohibits this flow because it exposes the user's credentials to the client.

Potential impact

A compromised client can expose the original password as well as access tokens. The flow is also unsuitable for multi-step or phishing-resistant authentication.

Remediation

For interactive user authorization, use authorizationCode with PKCE. Set HTTPS authorization and token URLs, update the actual clients and authorization server, then disable the password flow.

Examples

These excerpts change the flow definition for petstore_auth. Replace the URLs with your provider's endpoints. Check PKCE and the security requirements that apply this scheme in the actual configuration too.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "password": {
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "write:pets": "modify pets in your account",
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.org/api/oauth/dialog",
            "tokenUrl": "https://example.com/api/oauth/token",
            "scopes": {
              "write:pets": "modify pets in your account",
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References