Security
84 distinct extensions were invented to do this job. Each one is a provider deciding OpenAPI would not carry something and building their own way through. Where a job has many names and few uses each, nobody won — the problem was solved privately, over and over.
84 extensions
15982 occurrences
26 vendor-named
The extensions
| Extension | What it appears to do | Uses | Providers |
|---|---|---|---|
| x-fapi-interaction-id | `x-fapi-interaction-id` appears on header objects. Its value is a structured object. Used by 45 providers across 52 OpenAPI documents. Consistent with security — this is inferred from where the key ap | 6036 | 45 |
|
x-atlassian-oauth2-scopes
vendor |
`x-atlassian-oauth2-scopes` appears on operations. Its value is a list. Used by a single provider across 97 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by atl | 1929 | 1 |
|
x-atlassian-connect-scope
vendor |
`x-atlassian-connect-scope` appears on operations. Its value is a string. Used by a single provider across 95 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by a | 1468 | 1 |
| x-scopes | `x-scopes` appears on operations. Its value is a list. Used by 45 providers across 47 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, not | 725 | 45 |
| x-permission | `x-permission` appears on operations. Its value is a structured object. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what | 628 | 4 |
| x-permissions | `x-permissions` appears on operations. Its value is a list. Used by 5 providers across 5 OpenAPI documents. Observed values include `null`. Consistent with security — this is inferred from where the k | 560 | 5 |
| x-api-token-group | `x-api-token-group` appears on operations. Its value is a list. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carri | 544 | 4 |
| x-cfPermissionsRequired | `x-cfPermissionsRequired` appears on operations. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appear | 530 | 2 |
| x-encrypted | `x-encrypted` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the ke | 521 | 1 |
| x-rolesRequirements | `x-rolesRequirements` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what i | 452 | 1 |
| x-app-permission | `x-app-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ReadAccounts`, `EditAccounts`, `TeamMessaging`, `EditExte | 446 | 1 |
| x-required-permissions | `x-required-permissions` appears on operations. Its value is a structured object. Used by a single provider across 17 OpenAPI documents. Consistent with security — this is inferred from where the key | 268 | 1 |
|
x-ms-secret
vendor |
`x-ms-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 62 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined | 259 | 1 |
| x-user-permission | `x-user-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ConfigureEmergencyMaps`, `ReadExtensions`, `Meetings`, ` | 236 | 1 |
| x-appdirect-required-scopes | `x-appdirect-required-scopes` appears on operations. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the k | 165 | 1 |
| x-jws-signature | `x-jws-signature` appears on header objects. Its value is a structured object. Used by 4 providers across 11 OpenAPI documents. Consistent with security — this is inferred from where the key appears a | 157 | 4 |
| x-role-requirements | `x-role-requirements` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `Viewer or higher`, `Data Manager or higher`, `Admin`, | 146 | 1 |
| x-dct-toolkit-credential-field | `x-dct-toolkit-credential-field` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferre | 128 | 1 |
|
x-yba-api-authz
vendor |
`x-yba-api-authz` appears on operations. Its value is a list. Used by a single provider across 2 OpenAPI documents. It sits in the `x-yba-` namespace, so its meaning is defined by yba tooling rather t | 110 | 1 |
| x-scope | `x-scope` appears on operations. Its value is a string. Used by 2 providers across 2 OpenAPI documents. Observed values include `read`, `write`, `read:users`, `read:api_keys`. Consistent with security | 98 | 2 |
| x-restricted | `x-restricted` appears on operations. Its value is a boolean flag. Used by 3 providers across 9 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it ca | 63 | 3 |
|
x-obmcs-authz-declarations
vendor |
`x-obmcs-authz-declarations` appears on operations. Its value is a structured object. Used by a single provider across 14 OpenAPI documents. It sits in the `x-obmcs-` namespace, so its meaning is defi | 53 | 1 |
|
x-mastercard-api-encrypted
vendor |
`x-mastercard-api-encrypted` appears on operations. Its value is a boolean flag. Used by a single provider across 11 OpenAPI documents. It sits in the `x-mastercard-` namespace, so its meaning is defi | 41 | 1 |
| x-required-roles | `x-required-roles` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what it c | 35 | 1 |
|
x-ibm-permissions
vendor |
`x-ibm-permissions` appears on operations. Its value is a structured object. Used by a single provider across 5 OpenAPI documents. It sits in the `x-ibm-` namespace, so its meaning is defined by ibm t | 29 | 1 |
| x-auth-type | `x-auth-type` appears on operations. Its value is a string. Used by 2 providers across 6 OpenAPI documents. Observed values include `Application & Application User`, `Application`, `None`, `OAuth 1.0a | 27 | 2 |
| x-korbit-permission | `x-korbit-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `readOrders`, `readDeposits`, `readWithdrawals`, `write | 24 | 1 |
|
x-vault-sudo
vendor |
`x-vault-sudo` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vault tooling | 24 | 1 |
|
x-ms-request-server-encrypted
vendor |
`x-ms-request-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is d | 23 | 1 |
|
x-ms-encryption-scope
vendor |
`x-ms-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by | 18 | 1 |
| x-scope3-semantic-validation | `x-scope3-semantic-validation` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is infer | 18 | 1 |
|
x-vault-unauthenticated
vendor |
`x-vault-unauthenticated` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau | 18 | 1 |
|
x-ms-encryption-key-sha256
vendor |
`x-ms-encryption-key-sha256` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defin | 17 | 1 |
|
x-vault-createSupported
vendor |
`x-vault-createSupported` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau | 14 | 1 |
| x-roles | `x-roles` appears on operations. Its value is a list. Used by a single provider across 3 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, | 13 | 1 |
|
x-ms-file-permission-key
vendor |
`x-ms-file-permission-key` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined | 11 | 1 |
|
x-amz-signature
vendor |
`x-amz-signature` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 6 providers across 6 OpenAPI documents. It sits in the `x-amz-` namespace, | 10 | 6 |
| x-fapi-auth-date | `x-fapi-auth-date` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the key appea | 10 | 3 |
| x-fapi-customer-ip-address | `x-fapi-customer-ip-address` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the | 10 | 3 |
|
x-amz-credential
vendor |
`x-amz-credential` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 5 providers across 5 OpenAPI documents. It sits in the `x-amz-` namespace | 9 | 5 |
|
x-ms-server-encrypted
vendor |
`x-ms-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined b | 9 | 1 |
| x-guarded-string | `x-guarded-string` appears on schema objects and properties. Its value is a string. Used by a single provider across 2 OpenAPI documents. Observed values include `true`. Consistent with security — thi | 8 | 1 |
| x-scopes-required-access-tier | `x-scopes-required-access-tier` appears on security schemes. Its value is a structured object. Used by a single provider across 8 OpenAPI documents. Consistent with security — this is inferred from wh | 8 | 1 |
| x-secret | `x-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key ap | 6 | 1 |
|
x-vault-displayAttrs
vendor |
`x-vault-displayAttrs` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its mean | 6 | 1 |
|
x-amz-server-side-encryption
vendor |
`x-amz-server-side-encryption` appears on header objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. It sits in the `x-amz-` namespace, so its meaning is defined | 5 | 2 |
| x-forbid-unknown-cookie | `x-forbid-unknown-cookie` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 5 | 1 |
| x-forbid-unknown-header | `x-forbid-unknown-header` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 5 | 1 |
| x-forbid-unknown-path | `x-forbid-unknown-path` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 5 | 1 |
| x-forbid-unknown-query | `x-forbid-unknown-query` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 5 | 1 |
| x-app-secret | `x-app-secret` appears on operations and on security schemes. It is used as a marker with no value. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred fro | 4 | 1 |
| x-auth | `x-auth` appears on response objects. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `authvalue`, `keith`. Consistent with security — this is infer | 4 | 1 |
| x-cog-secret | `x-cog-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke | 3 | 1 |
| x-auth-id-alias | `x-auth-id-alias` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 2 | 1 |
| x-auth-token | `x-auth-token` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appears | 2 | 1 |
| x-fapi-financial-id-Param | `x-fapi-financial-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the k | 2 | 2 |
| x-fapi-interaction-id-Param | `x-fapi-interaction-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the | 2 | 2 |
| x-redlock-auth | `x-redlock-auth` appears on security schemes. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key app | 2 | 1 |
| x-Auth-Token | `x-Auth-Token` appears in the info block. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `{{ACCESS_TOKEN}}`. Consistent with security — this is inf | 1 | 1 |
| x-accelerate-signature | `x-accelerate-signature` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke | 1 | 1 |
|
x-ads-role
vendor |
`x-ads-role` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ads-` namespace, so its meaning is defined by ads tooli | 1 | 1 |
| x-allowed-roles | `x-allowed-roles` appears at the root of the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 1 | 1 |
| x-allowedTenantIdForRestriction | `x-allowedTenantIdForRestriction` appears in the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where | 1 | 1 |
|
x-amz-server-side-encryption-aws-kms-key-id
vendor |
`x-amz-server-side-encryption-aws-kms-key-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-amz-` namespace, so it | 1 | 1 |
| x-auth-responses | `x-auth-responses` appears at the root of the document. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `&AUTHRESPONSES`. Consistent with security — | 1 | 1 |
| x-client-secret | `x-client-secret` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `3586fea59c3ef4d3a829b398a865fb95`. Consistent with s | 1 | 1 |
| x-fapi-customer-ip-address-Param | `x-fapi-customer-ip-address-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from | 1 | 1 |
| x-fapi-customer-last-logged-time-Param | `x-fapi-customer-last-logged-time-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferre | 1 | 1 |
|
x-ms-acl
vendor |
`x-ms-acl` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms tooling r | 1 | 1 |
|
x-ms-default-encryption-scope
vendor |
`x-ms-default-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is de | 1 | 1 |
|
x-ms-deny-encryption-scope-override
vendor |
`x-ms-deny-encryption-scope-override` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning | 1 | 1 |
|
x-ms-permissions
vendor |
`x-ms-permissions` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms t | 1 | 1 |
| x-oauth-error-codes | `x-oauth-error-codes` appears at the root of the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where | 1 | 1 |
|
x-obmcs-splat-search-metadata-scope
vendor |
`x-obmcs-splat-search-metadata-scope` appears in the document. Its value is a string. Used by a single provider across 1 OpenAPI document. It sits in the `x-obmcs-` namespace, so its meaning is define | 1 | 1 |
| x-out-of-scope-note | `x-out-of-scope-note` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key a | 1 | 1 |
| x-permission-checks | `x-permission-checks` appears in the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what | 1 | 1 |
| x-qfex-hmac-signature | `x-qfex-hmac-signature` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the | 1 | 1 |
| x-role-system | `x-role-system` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 1 | 1 |
| x-sca-id | `x-sca-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and | 1 | 1 |
| x-sca-required | `x-sca-required` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 1 | 1 |
| x-sca-type | `x-sca-type` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears an | 1 | 1 |
| x-scopeValidateFunc | `x-scopeValidateFunc` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `api.middleware.auth.validate_scopes`. Consistent | 1 | 1 |
| x-signature-sha256 | `x-signature-sha256` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key | 1 | 1 |
| x-zapier-auth-scheme-exempt | `x-zapier-auth-scheme-exempt` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the | 1 | 1 |