Security
84 distinct extensions were invented to do this job. Each one is a provider deciding OpenAPI would not carry something and building their own way through. Where a job has many names and few uses each, nobody won — the problem was solved privately, over and over.
84 extensions
16078 occurrences
26 vendor-named
The extensions
| Extension | What it appears to do | Uses | Providers |
|---|---|---|---|
| x-fapi-interaction-id | `x-fapi-interaction-id` appears on header objects. Its value is a structured object. Used by 45 providers across 52 OpenAPI documents. Consistent with security — this is inferred from where the key ap | 6036 | 45 |
|
x-atlassian-oauth2-scopes
vendor |
`x-atlassian-oauth2-scopes` appears on operations. Its value is a list. Used by a single provider across 97 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by atl | 1929 | 1 |
|
x-atlassian-connect-scope
vendor |
`x-atlassian-connect-scope` appears on operations. Its value is a string. Used by a single provider across 95 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by a | 1468 | 1 |
| x-scopes | `x-scopes` appears on operations. Its value is a list. Used by 46 providers across 48 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, not | 821 | 46 |
| x-permission | `x-permission` appears on operations. Its value is a structured object. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what | 628 | 4 |
| x-permissions | `x-permissions` appears on operations. Its value is a list. Used by 5 providers across 5 OpenAPI documents. Observed values include `null`. Consistent with security — this is inferred from where the k | 560 | 5 |
| x-api-token-group | `x-api-token-group` appears on operations. Its value is a list. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carri | 544 | 4 |
| x-cfPermissionsRequired | `x-cfPermissionsRequired` appears on operations. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appear | 530 | 2 |
| x-encrypted | `x-encrypted` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the ke | 521 | 1 |
| x-rolesRequirements | `x-rolesRequirements` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what i | 452 | 1 |
| x-app-permission | `x-app-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ReadAccounts`, `EditAccounts`, `TeamMessaging`, `EditExte | 446 | 1 |
| x-required-permissions | `x-required-permissions` appears on operations. Its value is a structured object. Used by a single provider across 17 OpenAPI documents. Consistent with security — this is inferred from where the key | 268 | 1 |
|
x-ms-secret
vendor |
`x-ms-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 62 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined | 259 | 1 |
| x-user-permission | `x-user-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ConfigureEmergencyMaps`, `ReadExtensions`, `Meetings`, ` | 236 | 1 |
| x-appdirect-required-scopes | `x-appdirect-required-scopes` appears on operations. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the k | 165 | 1 |
| x-jws-signature | `x-jws-signature` appears on header objects. Its value is a structured object. Used by 4 providers across 11 OpenAPI documents. Consistent with security — this is inferred from where the key appears a | 157 | 4 |
| x-role-requirements | `x-role-requirements` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `Viewer or higher`, `Data Manager or higher`, `Admin`, | 146 | 1 |
| x-dct-toolkit-credential-field | `x-dct-toolkit-credential-field` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferre | 128 | 1 |
|
x-yba-api-authz
vendor |
`x-yba-api-authz` appears on operations. Its value is a list. Used by a single provider across 2 OpenAPI documents. It sits in the `x-yba-` namespace, so its meaning is defined by yba tooling rather t | 110 | 1 |
| x-scope | `x-scope` appears on operations. Its value is a string. Used by 2 providers across 2 OpenAPI documents. Observed values include `read`, `write`, `read:users`, `read:api_keys`. Consistent with security | 98 | 2 |
| x-restricted | `x-restricted` appears on operations. Its value is a boolean flag. Used by 3 providers across 9 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it ca | 63 | 3 |
|
x-obmcs-authz-declarations
vendor |
`x-obmcs-authz-declarations` appears on operations. Its value is a structured object. Used by a single provider across 14 OpenAPI documents. It sits in the `x-obmcs-` namespace, so its meaning is defi | 53 | 1 |
|
x-mastercard-api-encrypted
vendor |
`x-mastercard-api-encrypted` appears on operations. Its value is a boolean flag. Used by a single provider across 11 OpenAPI documents. It sits in the `x-mastercard-` namespace, so its meaning is defi | 41 | 1 |
| x-required-roles | `x-required-roles` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what it c | 35 | 1 |
|
x-ibm-permissions
vendor |
`x-ibm-permissions` appears on operations. Its value is a structured object. Used by a single provider across 5 OpenAPI documents. It sits in the `x-ibm-` namespace, so its meaning is defined by ibm t | 29 | 1 |
| x-auth-type | `x-auth-type` appears on operations. Its value is a string. Used by 2 providers across 6 OpenAPI documents. Observed values include `Application & Application User`, `Application`, `None`, `OAuth 1.0a | 27 | 2 |
| x-korbit-permission | `x-korbit-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `readOrders`, `readDeposits`, `readWithdrawals`, `write | 24 | 1 |
|
x-vault-sudo
vendor |
`x-vault-sudo` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vault tooling | 24 | 1 |
|
x-ms-request-server-encrypted
vendor |
`x-ms-request-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is d | 23 | 1 |
|
x-ms-encryption-scope
vendor |
`x-ms-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by | 18 | 1 |
| x-scope3-semantic-validation | `x-scope3-semantic-validation` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is infer | 18 | 1 |
|
x-vault-unauthenticated
vendor |
`x-vault-unauthenticated` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau | 18 | 1 |
|
x-ms-encryption-key-sha256
vendor |
`x-ms-encryption-key-sha256` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defin | 17 | 1 |
|
x-vault-createSupported
vendor |
`x-vault-createSupported` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau | 14 | 1 |
| x-roles | `x-roles` appears on operations. Its value is a list. Used by a single provider across 3 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, | 13 | 1 |
|
x-ms-file-permission-key
vendor |
`x-ms-file-permission-key` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined | 11 | 1 |
|
x-amz-signature
vendor |
`x-amz-signature` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 6 providers across 6 OpenAPI documents. It sits in the `x-amz-` namespace, | 10 | 6 |
| x-fapi-auth-date | `x-fapi-auth-date` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the key appea | 10 | 3 |
| x-fapi-customer-ip-address | `x-fapi-customer-ip-address` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the | 10 | 3 |
|
x-amz-credential
vendor |
`x-amz-credential` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 5 providers across 5 OpenAPI documents. It sits in the `x-amz-` namespace | 9 | 5 |
|
x-ms-server-encrypted
vendor |
`x-ms-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined b | 9 | 1 |
| x-guarded-string | `x-guarded-string` appears on schema objects and properties. Its value is a string. Used by a single provider across 2 OpenAPI documents. Observed values include `true`. Consistent with security — thi | 8 | 1 |
| x-scopes-required-access-tier | `x-scopes-required-access-tier` appears on security schemes. Its value is a structured object. Used by a single provider across 8 OpenAPI documents. Consistent with security — this is inferred from wh | 8 | 1 |
| x-secret | `x-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key ap | 6 | 1 |
|
x-vault-displayAttrs
vendor |
`x-vault-displayAttrs` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its mean | 6 | 1 |
|
x-amz-server-side-encryption
vendor |
`x-amz-server-side-encryption` appears on header objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. It sits in the `x-amz-` namespace, so its meaning is defined | 5 | 2 |
| x-forbid-unknown-cookie | `x-forbid-unknown-cookie` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 5 | 1 |
| x-forbid-unknown-header | `x-forbid-unknown-header` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 5 | 1 |
| x-forbid-unknown-path | `x-forbid-unknown-path` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 5 | 1 |
| x-forbid-unknown-query | `x-forbid-unknown-query` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 5 | 1 |
| x-app-secret | `x-app-secret` appears on operations and on security schemes. It is used as a marker with no value. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred fro | 4 | 1 |
| x-auth | `x-auth` appears on response objects. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `authvalue`, `keith`. Consistent with security — this is infer | 4 | 1 |
| x-cog-secret | `x-cog-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke | 3 | 1 |
| x-auth-id-alias | `x-auth-id-alias` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 2 | 1 |
| x-auth-token | `x-auth-token` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appears | 2 | 1 |
| x-fapi-financial-id-Param | `x-fapi-financial-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the k | 2 | 2 |
| x-fapi-interaction-id-Param | `x-fapi-interaction-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the | 2 | 2 |
| x-redlock-auth | `x-redlock-auth` appears on security schemes. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key app | 2 | 1 |
| x-Auth-Token | `x-Auth-Token` appears in the info block. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `{{ACCESS_TOKEN}}`. Consistent with security — this is inf | 1 | 1 |
| x-accelerate-signature | `x-accelerate-signature` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke | 1 | 1 |
|
x-ads-role
vendor |
`x-ads-role` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ads-` namespace, so its meaning is defined by ads tooli | 1 | 1 |
| x-allowed-roles | `x-allowed-roles` appears at the root of the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 1 | 1 |
| x-allowedTenantIdForRestriction | `x-allowedTenantIdForRestriction` appears in the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where | 1 | 1 |
|
x-amz-server-side-encryption-aws-kms-key-id
vendor |
`x-amz-server-side-encryption-aws-kms-key-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-amz-` namespace, so it | 1 | 1 |
| x-auth-responses | `x-auth-responses` appears at the root of the document. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `&AUTHRESPONSES`. Consistent with security — | 1 | 1 |
| x-client-secret | `x-client-secret` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `3586fea59c3ef4d3a829b398a865fb95`. Consistent with s | 1 | 1 |
| x-fapi-customer-ip-address-Param | `x-fapi-customer-ip-address-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from | 1 | 1 |
| x-fapi-customer-last-logged-time-Param | `x-fapi-customer-last-logged-time-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferre | 1 | 1 |
|
x-ms-acl
vendor |
`x-ms-acl` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms tooling r | 1 | 1 |
|
x-ms-default-encryption-scope
vendor |
`x-ms-default-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is de | 1 | 1 |
|
x-ms-deny-encryption-scope-override
vendor |
`x-ms-deny-encryption-scope-override` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning | 1 | 1 |
|
x-ms-permissions
vendor |
`x-ms-permissions` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms t | 1 | 1 |
| x-oauth-error-codes | `x-oauth-error-codes` appears at the root of the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where | 1 | 1 |
|
x-obmcs-splat-search-metadata-scope
vendor |
`x-obmcs-splat-search-metadata-scope` appears in the document. Its value is a string. Used by a single provider across 1 OpenAPI document. It sits in the `x-obmcs-` namespace, so its meaning is define | 1 | 1 |
| x-out-of-scope-note | `x-out-of-scope-note` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key a | 1 | 1 |
| x-permission-checks | `x-permission-checks` appears in the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what | 1 | 1 |
| x-qfex-hmac-signature | `x-qfex-hmac-signature` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the | 1 | 1 |
| x-role-system | `x-role-system` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears | 1 | 1 |
| x-sca-id | `x-sca-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and | 1 | 1 |
| x-sca-required | `x-sca-required` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear | 1 | 1 |
| x-sca-type | `x-sca-type` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears an | 1 | 1 |
| x-scopeValidateFunc | `x-scopeValidateFunc` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `api.middleware.auth.validate_scopes`. Consistent | 1 | 1 |
| x-signature-sha256 | `x-signature-sha256` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key | 1 | 1 |
| x-zapier-auth-scheme-exempt | `x-zapier-auth-scheme-exempt` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the | 1 | 1 |
Work with this as data
Every extension here is available over the APIs.io API and to AI agents over MCP. OpenAPI Extensions is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for openapi extensions
3 MCP tools reach this
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
Search the catalog
curl "https://apis.io/api/v1/search?q=security&limit=10"
Everything under a tag
curl "https://apis.io/api/v1/tags/security"
Discovery needs no key. Ratings and market analysis are Pro.