x-rolesRequirements

`x-rolesRequirements` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what it carries, not from any published definition.

Security derived description
How this description was produced. It is assembled from what was measured in the corpus — where this key appears in a document, what shape its value takes, the values observed, and how many providers use it. It is not taken from a published definition, because for most extensions none exists. Read it as evidence, not as a specification. If you own this extension and want it described properly, tell us.
452 occurrences
1 documents
1 providers
purpose-named

Where it appears

Location in the documentOccurrences
operation 452

What its value looks like

Value shapeOccurrences
array452

Providers publishing it

All 1.

mongodb

Why this is not in OpenAPI

Extensions exist because a provider needed something the specification would not carry. Most of what they hold is not the API contract at all — it is operational metadata about the contract: documentation, lifecycle, policy, provenance, and now agents. That metadata is usually better placed alongside the contract, in an Overlay or an APIs.json index, than crammed inside it. See everything else doing the security job.