The nullable keyword is not supported by API Gateway
Decide explicitly how the API should handle null and omitted values.
Match the finding
These titles and messages come from this local checker. They are not AWS service error quotes.
Schema nullable is unsupportedAPI Gateway REST does not support the schema keyword nullable. It is preserved because removing it may change the contract.
Cause and scope
In OpenAPI 3.0, nullable: true permits null alongside a type declared on the same Schema Object, subject to the other constraints. API Gateway REST does not support nullable, so import can lose this part of the contract.
What to do
Keep the field until you have decided where nullability is enforced. If null is part of the contract, retain that behavior in application or other appropriate validation and verify the imported API accepts the intended requests.
- At the reported schema, identify its type and whether the containing object requires this property.
- Write tests for a normal value, an explicit null, and an omitted property, using the actual remaining schema constraints.
- Choose and test the validation layer that preserves the intended behavior. If the contract changes, update clients and documentation before removing the keyword.
Schema fragment: optional and nullable are separate choices
components:
schemas:
Pet:
type: object
required: [id]
properties:
id:
type: string
nickname:
type: string
nullable: trueFor this fragment, nickname may be a string, null, or absent because it is not required. id must be present and a string. Keep tests for all three nickname cases; deleting nullable would remove the declared null case.
Avoid a misleading fix
Do not silently delete nullable, replace it with type: [string, null], or treat an omitted property as equivalent to a property whose value is null. Changing the accepted payloads needs a deliberate contract change.
Check your complete file locally
Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.
Related findings
Sources and scope
Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.