An OpenAPI operation has no declared authentication requirement

Declare authentication for protected operations through global or operation-level security.

Description

When both an operation and the top-level document omit security, the specification declares no authentication requirement for that operation. This can be appropriate for an intentionally public operation, but a protected operation needs an explicit requirement.

Potential impact

Developers or client generators using the specification may implement calls without credentials. Whether the server actually enforces authentication must be checked separately.

Remediation

Define the actual authentication scheme and reference it in global or operation-level security. Distinguish public operations from protected ones and align the specification with the server's policy.

Examples

The example defines an API key scheme named exampleSecurity and applies it to the operation through global security.

Before

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "exampleSecurity": []
    }
  ],
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

References