x-fapi-interaction-id
`x-fapi-interaction-id` appears on header objects. Its value is a structured object. Used by 45 providers across 52 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, not from any published definition.
Security
derived description
HTTP header, not an extension
How this description was produced. It is assembled from what was
measured in the corpus — where this key appears in a document, what shape its value
takes, the values observed, and how many providers use it. It is not taken
from a published definition, because for most extensions none exists. Read it as
evidence, not as a specification. If you own this extension and want it described
properly, tell us.
This is an HTTP header name, not a vendor extension. It appears
under a
headers: map, which is the same syntactic position an extension
key occupies — but OpenAPI models headers natively and this is not extending
anything. It is listed here because it turns up when you inventory the
x- namespace, and leaving it out would hide why the namespace looks
bigger than it is.
6036 occurrences
52 documents
45 providers
purpose-named
Where it appears
| Location in the document | Occurrences | |
|---|---|---|
| header | 6026 | |
| parameter | 10 |
What its value looks like
| Value shape | Occurrences |
|---|---|
| object | 6036 |
Providers publishing it
All 45.
alex-bankamp-bankanzaustralian-military-bankauswide-bankbank-firstbank-of-queenslandbank-of-sydneybank-of-usbanksabankwestbcu-bankbendigo-and-adelaide-bankbeyond-bankdefence-bankgateway-bankgc-mutual-bankgreat-southern-bankgreater-bankhsbc-australiahume-bankimb-banking-australiajudo-banklean-technologiesmacquarie-bankmystate-banknational-australia-banknatwestnewcastle-permanentopen-banking-ukpeople-first-bankpn-bankpolice-bankqudos-bankrabobank-australiaracq-bankregional-australia-bankrevolutsuncorp-bankteachers-mutual-bankubankunity-bankwestpaczopa
Why this is not in OpenAPI
Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the security job.