An OpenAPI document has no global authentication requirement

Declare a shared authentication policy in global security and check operation-level exceptions.

Description

Without top-level security, the document declares no default authentication requirement for the API. Individual operations can still specify authentication, so a missing global setting alone does not mean authentication is missing.

Potential impact

Omitting a shared requirement can leave operations that should inherit it documented without authentication. Clients may then use a policy that differs from the server's.

Remediation

Define global security when the API has a shared policy. If requirements are managed per operation, check every operation that needs authentication. Define referenced schemes in OpenAPI 3.0 components.securitySchemes or 2.0 securityDefinitions, and enforce them on the server.

Examples

The example adds a default authentication requirement and the corresponding petstore_auth definition. Replace the example OAuth2 URLs with your provider's URLs.

Before

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "petstore_auth": [
        "write:pets",
        "read:pets"
      ]
    }
  ],
  "components": {
    "securitySchemes": {
      "petstore_auth": {
        "type": "oauth2",
        "flows": {
          "authorizationCode": {
            "authorizationUrl": "https://example.com/oauth/authorize",
            "tokenUrl": "https://example.com/oauth/token",
            "scopes": {
              "write:pets": "modify pets in your account",
              "read:pets": "read your pets"
            }
          }
        }
      }
    }
  }
}

References