Useful checks, explicit limits

This first version supports one UTF-8 JSON or YAML OpenAPI 3.0 file, up to 1 MiB. It targets AWS API Gateway REST APIs. HTTP APIs, WebSocket APIs, Swagger 2.0, and OpenAPI 3.1/3.2 are outside this checker’s scope.

What is checked

One guarded repair

With your selection and review, root security can be copied to directly declared operations that have no security field. Existing operation overrides, including public operations, stay unchanged. The root security definition is retained. This does not provision an AWS authorizer, change IAM, or deploy your API.

What is not promised

Passing these checks does not guarantee AWS import, deployment, authorization, or runtime behavior. Integration configuration, service quotas, IAM permissions, AWS account settings, and all possible specification constraints are not fully validated.

The checker does not compile or execute your schemas. It does not evaluate arbitrary patterns or fetch remote references. Some valid complex inputs are deliberately rejected by resource or safety limits.

Verify before production

Review the full output and unresolved findings, then test the import and authorization behavior in your own non-production AWS environment.

Rule references checked on 3 October 2026. AWS REST API important notes · Pinned OAS schema