Resolve security schemes and review AWS authorizers
A security requirement must name a valid scheme, and import needs the intended authorizer.
Match the finding
These titles and messages come from this local checker. They are not AWS service error quotes.
Security scheme cannot be resolvedSecurity scheme needs AWS-specific review
Cause and scope
Unresolved or cyclic security scheme definitions prevent safe copies. Separately, HTTP, OAuth2, and OpenID Connect schemes require AWS-specific review; this checker does not configure authorizers.
What to do
Match every security requirement name to a valid securitySchemes component. Preserve its authentication type and scopes, then check the intended AWS authorizer configuration and test authorization.
- Check scheme names, required fields, references, and scopes at the reported location.
- Use an empty scope array for non-OAuth/non-OpenID schemes; retain real OAuth/OpenID scopes where applicable.
- Review the appropriate AWS authorizer setup and test both allowed and rejected requests in a non-production environment.
Security fragment: match the requirement to its intended bearer scheme
security:
- BearerAuth: []
components:
securitySchemes:
BearerAuth:
type: http
scheme: bearerIf the requirement used a different, missing name, correct it to the intended existing scheme. This fragment resolves the name while retaining bearer authentication. It still needs AWS-specific authorizer review; it is not a complete deployment configuration.
Avoid a misleading fix
Do not turn OAuth or bearer authentication into an API key to silence a warning. Do not clear required scopes, add anonymous access, or remove security requirements as a fix.
Check your complete file locally
Choose one OpenAPI 3.0 JSON or YAML file, diagnose the findings, and review any eligible security-copy preview before downloading. No file upload or account is needed.
Related findings
Sources and scope
Scope: this local checker, API Gateway REST APIs, and OpenAPI 3.0. Guidance reviewed 4 October 2026. A passing check does not guarantee import or runtime behavior.