Useful checks, explicit limits
This first version supports one UTF-8 JSON or YAML OpenAPI 3.0 file, up to 1 MiB. It targets AWS API Gateway REST APIs. HTTP APIs, WebSocket APIs, Swagger 2.0, and OpenAPI 3.1/3.2 are outside this checker’s scope.
What is checked
- Document structure against a pinned OpenAPI 3.0 schema
- Selected API Gateway restrictions, including root security, model names, path forms, security scheme types, and selected schema keywords
- References in supported OpenAPI locations, with external fetching disabled
- Input resource limits, duplicate keys, unsupported YAML constructs, and invalid scalar values
One guarded repair
With your selection and review, root security can be copied to directly declared operations that have no security field. Existing operation overrides, including public operations, stay unchanged. The root security definition is retained. This does not provision an AWS authorizer, change IAM, or deploy your API.
What is not promised
Passing these checks does not guarantee AWS import, deployment, authorization, or runtime behavior. Integration configuration, service quotas, IAM permissions, AWS account settings, and all possible specification constraints are not fully validated.
The checker does not compile or execute your schemas. It does not evaluate arbitrary patterns or fetch remote references. Some valid complex inputs are deliberately rejected by resource or safety limits.
Verify before production
Review the full output and unresolved findings, then test the import and authorization behavior in your own non-production AWS environment.
Rule references checked on 3 October 2026. AWS REST API important notes · Pinned OAS schema