x-Auth-Token

`x-Auth-Token` appears in the info block. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `{{ACCESS_TOKEN}}`. Consistent with security — this is inferred from where the key appears and what it carries, not from any published definition.

Security derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
Also published under another name. This key exists in the wild spelled more than one way — differing only by case or a hyphen, which means no tool can treat them as the same thing: x-auth-token. Each is catalogued separately here because that is how they exist.
1 occurrences
1 documents
1 providers
purpose-named

Where it appears

Location in the documentOccurrences
info 1

What its value looks like

Value shapeOccurrences
string1

Observed values

Sampled from the specifications, most frequent first.

{{ACCESS_TOKEN}}

Providers publishing it

All 1.

bigcommerce

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the security job.