Review the HTTP authentication scheme

Check that the HTTP authentication scheme in OpenAPI 3.0 matches the implementation and supported tooling.

Description

For type: http in OpenAPI 3.0, scheme identifies the HTTP authentication method used in the Authorization header. Names registered with IANA are recommended for interoperability.

Potential impact

A typo or an unsupported authentication method can cause incorrect header generation or client integration failures.

Remediation

Match scheme to the server's actual authentication method and check the IANA registry name. If a custom method is needed, document its protocol and verify support in clients and related tools.

Examples

The after example assumes the server uses Basic authentication. Specify the corresponding scheme if the server uses another method. Send credentials over HTTPS.

Before

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "http",
        "scheme": "test"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "http",
        "scheme": "basic"
      }
    }
  }
}

References