API7 Docs
Traffic ManagementOAS Validator

OAS Validator Configuration

Parameters

See plugin common configurations for configuration options available to all plugins.

  • specstring · optional

    String containing the OpenAPI spec. Mutually exclusive with spec_url.

    The inline spec has a 2 MB size limit imposed by the control plane. If your OpenAPI specification exceeds this limit, use spec_url instead to load the spec from a remote URL.

  • spec_urlstring · optional

    URL to fetch the OpenAPI spec from (must start with http:// or https://). Mutually exclusive with spec. The fetched spec is cached with a configurable TTL (see plugin metadata spec_url_ttl), and stale entries continue serving requests while the spec refreshes in the background.

    Available in API7 Enterprise from version 3.9.12 and APISIX from version 3.17.0.

  • spec_url_request_headersobject · optional

    Custom HTTP headers to include when fetching spec_url (e.g. for authentication).

    Available in API7 Enterprise from version 3.9.12 and APISIX from version 3.17.0.

  • ssl_verifyboolean · optional · default: false

    Whether to verify the SSL certificate when fetching spec_url.

    Available in API7 Enterprise from version 3.9.12 and APISIX from version 3.17.0.

  • timeoutinteger · optional · default: 10000

    Valid values: 1000–60000

    HTTP request timeout in milliseconds when fetching spec_url.

    Available in API7 Enterprise from version 3.9.12 and APISIX from version 3.17.0.

  • verbose_errorsboolean · optional · default: false

    If true, respond with detailed error if the validation fails.

  • skip_request_body_validationboolean · optional · default: false

    If true, skip the validation of request body.

  • skip_request_header_validationboolean · optional · default: false

    If true, skip the validation of request header.

  • skip_query_param_validationboolean · optional · default: false

    If true, skip the validation of query parameters.

  • skip_path_params_validationboolean · optional · default: false

    If true, skip the validation of path parameters.

  • reject_if_not_matchboolean · optional · default: true

    If false, requests that fail OAS validation are logged as error but the request is still forwarded to the upstream service.

    Available in API7 Enterprise from 3.9.6 and APISIX from version 3.17.0.

  • rejection_status_codeinteger · optional · default: 400

    Valid values: 400–599

    HTTP status code to return when request validation fails. For example, set to 422 to distinguish semantic validation errors (Unprocessable Entity) from malformed request syntax (400 Bad Request). Only effective when reject_if_not_match is true.

    Available in API7 Enterprise from version 3.9.8 and APISIX from version 3.17.0.

  • max_req_body_sizeinteger · optional · default: 67108864

    Valid values: greater than or equal to 1

    Maximum request body size in bytes read for OpenAPI validation. A larger body returns 500 Internal Server Error. This field has no effect when skip_request_body_validation is true. Introduced in API7 Enterprise 3.9.17 and 3.10.4, and APISIX 3.18.0.

One of spec or spec_url must be configured. They are mutually exclusive.

Plugin Metadata

  • spec_url_ttlinteger · optional · default: 3600

    TTL in seconds for cached specs fetched from spec_url. After expiry, stale entries continue serving requests while the spec refreshes asynchronously in the background.

    Available in API7 Enterprise from version 3.9.12 and APISIX from version 3.17.0.