Security

84 distinct extensions were invented to do this job. Each one is a provider deciding OpenAPI would not carry something and building their own way through. Where a job has many names and few uses each, nobody won — the problem was solved privately, over and over.

84 extensions
16078 occurrences
26 vendor-named

The extensions

ExtensionWhat it appears to doUsesProviders
x-fapi-interaction-id `x-fapi-interaction-id` appears on header objects. Its value is a structured object. Used by 45 providers across 52 OpenAPI documents. Consistent with security — this is inferred from where the key ap 6036 45
x-atlassian-oauth2-scopes
vendor
`x-atlassian-oauth2-scopes` appears on operations. Its value is a list. Used by a single provider across 97 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by atl 1929 1
x-atlassian-connect-scope
vendor
`x-atlassian-connect-scope` appears on operations. Its value is a string. Used by a single provider across 95 OpenAPI documents. It sits in the `x-atlassian-` namespace, so its meaning is defined by a 1468 1
x-scopes `x-scopes` appears on operations. Its value is a list. Used by 46 providers across 48 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, not 821 46
x-permission `x-permission` appears on operations. Its value is a structured object. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what 628 4
x-permissions `x-permissions` appears on operations. Its value is a list. Used by 5 providers across 5 OpenAPI documents. Observed values include `null`. Consistent with security — this is inferred from where the k 560 5
x-api-token-group `x-api-token-group` appears on operations. Its value is a list. Used by 4 providers across 4 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carri 544 4
x-cfPermissionsRequired `x-cfPermissionsRequired` appears on operations. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appear 530 2
x-encrypted `x-encrypted` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the ke 521 1
x-rolesRequirements `x-rolesRequirements` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what i 452 1
x-app-permission `x-app-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ReadAccounts`, `EditAccounts`, `TeamMessaging`, `EditExte 446 1
x-required-permissions `x-required-permissions` appears on operations. Its value is a structured object. Used by a single provider across 17 OpenAPI documents. Consistent with security — this is inferred from where the key 268 1
x-ms-secret
vendor
`x-ms-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 62 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined 259 1
x-user-permission `x-user-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `ConfigureEmergencyMaps`, `ReadExtensions`, `Meetings`, ` 236 1
x-appdirect-required-scopes `x-appdirect-required-scopes` appears on operations. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the k 165 1
x-jws-signature `x-jws-signature` appears on header objects. Its value is a structured object. Used by 4 providers across 11 OpenAPI documents. Consistent with security — this is inferred from where the key appears a 157 4
x-role-requirements `x-role-requirements` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `Viewer or higher`, `Data Manager or higher`, `Admin`, 146 1
x-dct-toolkit-credential-field `x-dct-toolkit-credential-field` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferre 128 1
x-yba-api-authz
vendor
`x-yba-api-authz` appears on operations. Its value is a list. Used by a single provider across 2 OpenAPI documents. It sits in the `x-yba-` namespace, so its meaning is defined by yba tooling rather t 110 1
x-scope `x-scope` appears on operations. Its value is a string. Used by 2 providers across 2 OpenAPI documents. Observed values include `read`, `write`, `read:users`, `read:api_keys`. Consistent with security 98 2
x-restricted `x-restricted` appears on operations. Its value is a boolean flag. Used by 3 providers across 9 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it ca 63 3
x-obmcs-authz-declarations
vendor
`x-obmcs-authz-declarations` appears on operations. Its value is a structured object. Used by a single provider across 14 OpenAPI documents. It sits in the `x-obmcs-` namespace, so its meaning is defi 53 1
x-mastercard-api-encrypted
vendor
`x-mastercard-api-encrypted` appears on operations. Its value is a boolean flag. Used by a single provider across 11 OpenAPI documents. It sits in the `x-mastercard-` namespace, so its meaning is defi 41 1
x-required-roles `x-required-roles` appears on operations. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what it c 35 1
x-ibm-permissions
vendor
`x-ibm-permissions` appears on operations. Its value is a structured object. Used by a single provider across 5 OpenAPI documents. It sits in the `x-ibm-` namespace, so its meaning is defined by ibm t 29 1
x-auth-type `x-auth-type` appears on operations. Its value is a string. Used by 2 providers across 6 OpenAPI documents. Observed values include `Application & Application User`, `Application`, `None`, `OAuth 1.0a 27 2
x-korbit-permission `x-korbit-permission` appears on operations. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `readOrders`, `readDeposits`, `readWithdrawals`, `write 24 1
x-vault-sudo
vendor
`x-vault-sudo` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vault tooling 24 1
x-ms-request-server-encrypted
vendor
`x-ms-request-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is d 23 1
x-ms-encryption-scope
vendor
`x-ms-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by 18 1
x-scope3-semantic-validation `x-scope3-semantic-validation` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is infer 18 1
x-vault-unauthenticated
vendor
`x-vault-unauthenticated` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau 18 1
x-ms-encryption-key-sha256
vendor
`x-ms-encryption-key-sha256` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defin 17 1
x-vault-createSupported
vendor
`x-vault-createSupported` appears on path items. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its meaning is defined by vau 14 1
x-roles `x-roles` appears on operations. Its value is a list. Used by a single provider across 3 OpenAPI documents. Consistent with security — this is inferred from where the key appears and what it carries, 13 1
x-ms-file-permission-key
vendor
`x-ms-file-permission-key` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined 11 1
x-amz-signature
vendor
`x-amz-signature` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 6 providers across 6 OpenAPI documents. It sits in the `x-amz-` namespace, 10 6
x-fapi-auth-date `x-fapi-auth-date` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the key appea 10 3
x-fapi-customer-ip-address `x-fapi-customer-ip-address` appears on parameter objects. Its value is a structured object. Used by 3 providers across 10 OpenAPI documents. Consistent with security — this is inferred from where the 10 3
x-amz-credential
vendor
`x-amz-credential` appears on schema objects and properties and on response objects. Its value is a structured object. Used by 5 providers across 5 OpenAPI documents. It sits in the `x-amz-` namespace 9 5
x-ms-server-encrypted
vendor
`x-ms-server-encrypted` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. It sits in the `x-ms-` namespace, so its meaning is defined b 9 1
x-guarded-string `x-guarded-string` appears on schema objects and properties. Its value is a string. Used by a single provider across 2 OpenAPI documents. Observed values include `true`. Consistent with security — thi 8 1
x-scopes-required-access-tier `x-scopes-required-access-tier` appears on security schemes. Its value is a structured object. Used by a single provider across 8 OpenAPI documents. Consistent with security — this is inferred from wh 8 1
x-secret `x-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key ap 6 1
x-vault-displayAttrs
vendor
`x-vault-displayAttrs` appears on schema objects and properties. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-vault-` namespace, so its mean 6 1
x-amz-server-side-encryption
vendor
`x-amz-server-side-encryption` appears on header objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. It sits in the `x-amz-` namespace, so its meaning is defined 5 2
x-forbid-unknown-cookie `x-forbid-unknown-cookie` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear 5 1
x-forbid-unknown-header `x-forbid-unknown-header` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear 5 1
x-forbid-unknown-path `x-forbid-unknown-path` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears 5 1
x-forbid-unknown-query `x-forbid-unknown-query` appears on operations. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears 5 1
x-app-secret `x-app-secret` appears on operations and on security schemes. It is used as a marker with no value. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred fro 4 1
x-auth `x-auth` appears on response objects. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `authvalue`, `keith`. Consistent with security — this is infer 4 1
x-cog-secret `x-cog-secret` appears on schema objects and properties. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke 3 1
x-auth-id-alias `x-auth-id-alias` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears 2 1
x-auth-token `x-auth-token` appears on header objects. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key appears 2 1
x-fapi-financial-id-Param `x-fapi-financial-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the k 2 2
x-fapi-interaction-id-Param `x-fapi-interaction-id-Param` appears on parameter objects. Its value is a structured object. Used by 2 providers across 2 OpenAPI documents. Consistent with security — this is inferred from where the 2 2
x-redlock-auth `x-redlock-auth` appears on security schemes. Its value is a structured object. Used by a single provider across 2 OpenAPI documents. Consistent with security — this is inferred from where the key app 2 1
x-Auth-Token `x-Auth-Token` appears in the info block. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `{{ACCESS_TOKEN}}`. Consistent with security — this is inf 1 1
x-accelerate-signature `x-accelerate-signature` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the ke 1 1
x-ads-role
vendor
`x-ads-role` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ads-` namespace, so its meaning is defined by ads tooli 1 1
x-allowed-roles `x-allowed-roles` appears at the root of the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears 1 1
x-allowedTenantIdForRestriction `x-allowedTenantIdForRestriction` appears in the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where 1 1
x-amz-server-side-encryption-aws-kms-key-id
vendor
`x-amz-server-side-encryption-aws-kms-key-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-amz-` namespace, so it 1 1
x-auth-responses `x-auth-responses` appears at the root of the document. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `&AUTHRESPONSES`. Consistent with security — 1 1
x-client-secret `x-client-secret` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `3586fea59c3ef4d3a829b398a865fb95`. Consistent with s 1 1
x-fapi-customer-ip-address-Param `x-fapi-customer-ip-address-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from 1 1
x-fapi-customer-last-logged-time-Param `x-fapi-customer-last-logged-time-Param` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferre 1 1
x-ms-acl
vendor
`x-ms-acl` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms tooling r 1 1
x-ms-default-encryption-scope
vendor
`x-ms-default-encryption-scope` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is de 1 1
x-ms-deny-encryption-scope-override
vendor
`x-ms-deny-encryption-scope-override` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning 1 1
x-ms-permissions
vendor
`x-ms-permissions` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. It sits in the `x-ms-` namespace, so its meaning is defined by ms t 1 1
x-oauth-error-codes `x-oauth-error-codes` appears at the root of the document. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where 1 1
x-obmcs-splat-search-metadata-scope
vendor
`x-obmcs-splat-search-metadata-scope` appears in the document. Its value is a string. Used by a single provider across 1 OpenAPI document. It sits in the `x-obmcs-` namespace, so its meaning is define 1 1
x-out-of-scope-note `x-out-of-scope-note` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key a 1 1
x-permission-checks `x-permission-checks` appears in the document. Its value is a list. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and what 1 1
x-qfex-hmac-signature `x-qfex-hmac-signature` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the 1 1
x-role-system `x-role-system` appears in the info block. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears 1 1
x-sca-id `x-sca-id` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears and 1 1
x-sca-required `x-sca-required` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appear 1 1
x-sca-type `x-sca-type` appears on header objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key appears an 1 1
x-scopeValidateFunc `x-scopeValidateFunc` appears on security schemes. Its value is a string. Used by a single provider across 1 OpenAPI document. Observed values include `api.middleware.auth.validate_scopes`. Consistent 1 1
x-signature-sha256 `x-signature-sha256` appears on parameter objects. Its value is a structured object. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the key 1 1
x-zapier-auth-scheme-exempt `x-zapier-auth-scheme-exempt` appears on security schemes. Its value is a boolean flag. Used by a single provider across 1 OpenAPI document. Consistent with security — this is inferred from where the 1 1

Work with this as data

Every extension here is available over the APIs.io API and to AI agents over MCP. OpenAPI Extensions is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for openapi extensions

3 MCP tools reach this
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
Search the catalog
curl "https://apis.io/api/v1/search?q=security&limit=10"
Everything under a tag
curl "https://apis.io/api/v1/tags/security"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.