Root-level security is not applied by API Gateway

Make inherited security explicit without changing operation overrides.

Match the finding

These titles and messages come from this local checker. They are not AWS service error quotes.

Cause and scope

OpenAPI operations can inherit root security. API Gateway REST import does not apply that root-level definition. This checker offers one guarded repair: exact copies into directly declared operations that omit security.

What to do

Review the proposed copies and retain the root definition. Explicit operation security is preserved, including an empty array and anonymous alternatives. Import into a non-production environment and test authorization.

  1. Resolve every blocking finding first.
  2. Select the security-copy repair, review every affected operation, then download the reviewed output.
  3. Test authenticated and unauthenticated requests against the imported API.

Operation fragment: copy inherited requirements, preserve public overrides

security:
  - ApiKey: []
paths:
  /pets:
    get:
      security:
        - ApiKey: []
      responses:
        '200':
          description: OK
    post:
      security: []
      responses:
        '201':
          description: Created

Assume ApiKey is an existing, valid security scheme. GET receives the unchanged root array; POST already declares public access and must stay unchanged. If the root array contains {}, preserve that anonymous alternative too.

Avoid a misleading fix

Do not overwrite existing security, remove anonymous alternatives, or convert authentication types. Copying requirements does not provision an AWS authorizer.

Check your complete file locally

Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.

Open the free OpenAPI checker →

Related findings

Sources and scope

Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.