x-amazon-apigateway-authtype
`x-amazon-apigateway-authtype` appears on security schemes. Its value is a string. Used by 104 providers across 114 OpenAPI documents. It sits in the `x-amazon-` namespace, so its meaning is defined by amazon tooling rather than by OpenAPI. Observed values include `awsSigv4`, `custom`, `cognito_user_pools`, `oauth2`. Consistent with runtime & gateway — this is inferred from where the key appears and what it carries, not from any published definition.
Where it appears
| Location in the document | Occurrences | |
|---|---|---|
| securityScheme | 113 | |
| other | 2 |
What its value looks like
| Value shape | Occurrences |
|---|---|
| string | 115 |
Observed values
Sampled from the specifications, most frequent first.
Providers publishing it
Showing 50 of 104.
Why this is not in OpenAPI
Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the runtime & gateway job.