#287 · Developer Tool

OpenAPI Security Scheme Inspector

Inspect declared OpenAPI security schemes and see where they apply. The report lists each scheme’s type and relevant fields, then classifies every operation as inherited, overridden, explicitly public, or unspecified. It also flags security requirement names that do not match a component definition. This distinction matters because an empty security array disables inherited requirements, while an absent operation field may inherit the root policy.

Developer Input

OpenAPI JSON
Ad space

How to use this developer tool

  1. Paste a JSON-formatted API document or load the included sample.
  2. Check that the document shape matches the label above the editor.
  3. Select “Inspect Security” or press Ctrl/Cmd + Enter.
  4. Review the summary and download the copy-ready result.

What this developer tool does

The inspector combines components.securitySchemes with root and operation security requirements to show effective declarations.

Operation security overrides root security. An empty array is treated as explicitly public; missing root and operation fields are reported as unspecified.

The page audits declarations only. It cannot verify tokens, scopes, TLS, or server enforcement.

Example

The Sample button loads a small specification chosen for this operation. Running it produces the same structured fields shown in the output panel.

{
  "openapi": "3.0.3",
  "info": {
    "title": "Private API",
    "version": "1"
  },
  "components": {
    "securitySchemes": {
      "bearerAuth": {
        "type": "http",
        "scheme": "bearer",
        "bearerFormat": "JWT"
      },
      "apiKey": {
        "type": "apiKey",
        "in": "header",
        "name": "X-API-Key"
      }
    }
  },
  "security": [
    {
      "bearerAuth": []
    }
  ],
  "paths": {
    "/public": {
      "get": {
        "security": [],
        "responses": {}
      }
    },
    "/private": {
      "get": {
        "responses": {}
      }
    }
  }
}

Use cases

  • Review an API contract during a pull request.
  • Prepare documentation or deterministic test fixtures.
  • Find migration work before changing generators or clients.
  • Export a focused report without sharing the source document.

Tips for reliable output

  • Bundle remote references before running the page.
  • Keep operation IDs stable across published versions.
  • Prefer explicit examples for domain-specific values.
  • Validate the complete document after applying generated output.
  • Commit the original specification before a conversion.

Processing details

Scheme details include HTTP scheme, bearer format, API-key location and name, and OAuth flow names. Requirement references are checked by exact name.

The inspector does not evaluate OpenID metadata URLs, OAuth authorization servers, or runtime access control.

Frequently asked questions

Does this page accept YAML OpenAPI files?

No. This browser-only implementation accepts JSON so parsing behavior stays predictable without loading an external YAML library. Convert YAML to JSON first.

Are external $ref URLs resolved?

No. Local JSON Pointer references are handled where the operation needs them, but remote references are not fetched.

Does the result replace a full OpenAPI validator?

No. OpenAPI Security Scheme Inspector performs its documented transformation or audit. Use a standards-aware validator before publishing a specification.

Is the specification uploaded to a server?

No. Processing runs in the current browser tab. The page does not send the pasted document to an API.

Can I download the result?

Yes. Run the tool, then use Download for the primary output or the JSON and CSV buttons when those structured exports are available.

Input contract

ItemRequirement
FormatJSON object
ExecutionLocal browser
Remote refsNot fetched

API & GraphQL Tools

Browse contract inspection, conversion, request, response, and schema utilities.

Open category hub