x-apikeyInfoFunc

`x-apikeyInfoFunc` appears on security schemes. Its value is a string. Used by 3 providers across 4 OpenAPI documents. Observed values include `athenian.api.controllers.security_controller.info_from_apiKeyAuth`, `core.api_security.api_key`, `core.auth.alloy_user_key`, `core.auth.api_key`. Consistent with data & schema semantics — this is inferred from where the key appears and what it carries, not from any published definition.

Data & schema semantics derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
7 occurrences
4 documents
3 providers
purpose-named

Where it appears

Location in the documentOccurrences
securityScheme 7

What its value looks like

Value shapeOccurrences
string7

Observed values

Sampled from the specifications, most frequent first.

athenian.api.controllers.security_controller.info_from_apiKeyAuthcore.api_security.api_keycore.auth.alloy_user_keycore.auth.api_keycore.auth.internal_api_keycore.auth.jwt_authopenapi_server.controllers.security_controller_.info_from_CookieAuth

Providers publishing it

All 3.

athenianemotivesp-global

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the data & schema semantics job.