A safe preview could not be produced

Keep the original and review why the complete repair was rejected.

Match the finding

These titles and messages come from this local checker. They are not AWS service error quotes.

Cause and scope

Preview generation checks output budgets, reparses the result, and verifies that only the intended security copies changed. If any postcondition fails, the original source is returned with no patches.

What to do

Review the remaining findings and local limits. If needed, make the operation security copies manually in a trusted editor, compare the complete result with the original, and validate it independently.

  1. Keep an unchanged copy of the original and inspect all blocking findings.
  2. Reduce complexity only when it preserves the complete contract, or use another local workflow.
  3. After any manual security copies, check the full diff and test authorization after import.

Diagnostic result fragment: a rejected preview has no patches

patches: []
analysis:
  canRepair: false
  issues:
    - ruleId: repair.postcondition
      title: Safe preview could not be produced

These are selected fields from a rejected local preview; its output remains the unchanged original. For example, serialization can exceed the output budget after input checks pass. Keep the original and review another complete workflow; an empty patch list is not a successful repair.

Avoid a misleading fix

Do not treat a failed preview as repaired output or bypass its checks. Do not overwrite operation overrides or remove the root security definition.

Check your complete file locally

Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.

Open the free OpenAPI checker →

Related findings

Sources and scope

Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.