x-amz-signature

`x-amz-signature` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 6 providers across 6 OpenAPI documents. It sits in the `x-amz-` namespace, so its meaning is defined by amz tooling rather than by OpenAPI. Consistent with security — this is inferred from where the key appears and what it carries, not from any published definition.

Security x-amz- namespace derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
10 occurrences
6 documents
6 providers
vendor-named

Where it appears

Location in the documentOccurrences
schema 7
response 3

What its value looks like

Value shapeOccurrences
object5
string5

Observed values

Sampled from the specifications, most frequent first.

6b715e441bd7ea5beec87f8415230a600be6dfd76b8f89103137618dca959faca249243213026c97ac80f9b2e4b2ef06c7c491022a8cf8e46f0ddf95a746e6f7fcd6309a6aaee213348666a72abed8b44552a43acb6b340e8e1b288d21a5fe92SIGNATURE_GOES_HERE...

Providers publishing it

All 6.

docspringnarmipinterestpunchhspektrvdocipher

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the security job.