The global security array is empty

An empty global security array declares no default authentication requirement.

Description

Top-level security: [] declares no default authentication requirement for the API. Individual operations can override it. This is valid for an intentionally public API, but an API that needs shared authentication should declare that requirement.

Potential impact

Protected operations that use this default are documented as callable without authentication. The declaration should match the server's actual authentication policy.

Remediation

Reference a defined scheme in global security when shared authentication is required, and make exceptions only for public operations. security: [] differs from security: [{exampleSecurity: []}]: the latter requires the named scheme, and an empty scope array is correct for API key authentication.

Examples

The example replaces the unauthenticated default with the exampleSecurity API key requirement.

Before

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

After

json
{
  "openapi": "3.0.0",
  "paths": {
    "/": {
      "get": {
        "responses": {
          "200": {
            "description": "ok"
          }
        }
      }
    }
  },
  "security": [
    {
      "exampleSecurity": []
    }
  ],
  "info": {
    "title": "Simple API overview",
    "version": "1.0.0"
  },
  "components": {
    "securitySchemes": {
      "exampleSecurity": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  }
}

References