Review what an AWS REST import could miss.
Check a release set, trace root-security inheritance, and compare declared security before and after a change. Your JSON and YAML files stay in your browser.
Check a release set locally
Select up to 8 JSON/YAML files. Each is checked independently; references between files are not bundled.
1 MiB per file · 4 MiB total · sequential processing · no persistence after reload
Files stay in this tab. No AWS connection, external reference fetching, or automatic changes. Privacy details
Make a security copy you can explain
AWS API Gateway REST ignores root-level security. The workbench shows which directly declared operations inherit it and which have explicit overrides. The single-file checker can preview only the eligible copies, with your selection.
Try the guarded security-copy preview · Read the rule and AWS source
Repeat the same bounded checks in CI
The offline CLI uses the same parser, pinned schema and AWS rules. Export a summary JSON report or SARIF, select a warning policy, and compare security requirements without uploading a definition.
What this review proves
The comparison normalizes the order of security alternatives, scheme names and scopes. It distinguishes a declaration-only change from new anonymous access, changed requirements, or a changed security-scheme definition. The security review is limited to 200 operations and 1 MiB of expanded security detail. Referenced Path Items and callbacks make coverage partial. It does not decide whether a change is safe to deploy.
No AWS import, integration, authorizer, IAM or runtime check is performed. A quiet report does not guarantee import success or secure access. Replay the synthetic examples · Read all limits