x-amazon-apigateway-authtype

`x-amazon-apigateway-authtype` appears on security schemes. Its value is a string. Used by 104 providers across 114 OpenAPI documents. It sits in the `x-amazon-` namespace, so its meaning is defined by amazon tooling rather than by OpenAPI. Observed values include `awsSigv4`, `custom`, `cognito_user_pools`, `oauth2`. Consistent with runtime & gateway — this is inferred from where the key appears and what it carries, not from any published definition.

Runtime & gateway x-amazon- namespace derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
115 occurrences
114 documents
104 providers
vendor-named

Where it appears

Location in the documentOccurrences
securityScheme 113
other 2

What its value looks like

Value shapeOccurrences
string115

Observed values

Sampled from the specifications, most frequent first.

awsSigv4customcognito_user_poolsoauth2awsSigv2awsS3

Providers publishing it

Showing 50 of 104.

alayacareamazon-app-meshamazon-app-runneramazon-codeartifactamazon-codebuildamazon-codedeployamazon-codeguru-profileramazon-codeguru-revieweramazon-codeguru-securityamazon-codepipelineamazon-codestaramazon-cognitoamazon-comprehendamazon-compute-optimizeramazon-configamazon-device-farmamazon-devops-guruamazon-direct-connectamazon-directory-serviceamazon-dmsamazon-ec2-auto-scalingamazon-ec2-image-builderamazon-elastic-transcoderamazon-entity-resolutionamazon-eventbridge-pipesamazon-eventbridge-scheduleramazon-gameliftamazon-global-acceleratoramazon-glueamazon-glue-databrewamazon-ground-stationamazon-guarddutyamazon-health-dashboardamazon-healthimagingamazon-healthlakeamazon-healthomicsamazon-iam-access-analyzeramazon-iam-identity-centeramazon-incident-manageramazon-inspectoramazon-interactive-video-serviceamazon-iot-coreamazon-iot-device-defenderamazon-iot-device-managementamazon-iot-eventsamazon-iot-fleetwiseamazon-iot-greengrassamazon-iot-sitewiseamazon-iot-twinmakeramazon-lookout-for-metrics

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the runtime & gateway job.