Data & schema semantics · Identity & relationships

x-api-key

`x-api-key` appears on parameter objects and on security schemes. Its value is a structured object. Used by 12 providers across 63 OpenAPI documents. Consistent with identity & relationships — this is inferred from where the key appears and what it carries, not from any published definition.

Data & schema semantics derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
67 occurrences
63 documents
12 providers
purpose-named

Where it appears

Location in the documentOccurrences
parameter 27
securityScheme 24
other 3
header 11
operation 1
info 1

What its value looks like

Value shapeOccurrences
object51
empty3
string13

Observed values

Sampled from the specifications, most frequent first.

my-api-key$EXA_API_KEY\" \\\n -H \"Exa-Beta: agent-2026-05-07\" \\\n -d '{\n \"query\your-api-key-here

Providers publishing it

All 12.

adobe-suitecachetdaytona-ioemburseexa-aifaciliomv-sistemasphotoroomportcastspektrsupagluetrustradius

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the data & schema semantics job.