📄

OpenAPI Validator

Check OpenAPI 3.0/3.1 YAML/JSON syntax and selected local structure

API Document Validation
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
OpenAPI YAML / JSON

Local checks cover 3.0/3.1, info, paths/webhooks and direct operation responses. Schemas, parameter matching, security, callbacks and reference targets are not validated. Limits: 2 MiB, 100 levels, 100,000 nodes; up to 100 issues shown.

Validation result

Syntax and structure issues appear here.

About this tool

OpenAPI Validator performs a limited local review of OpenAPI 3.0.x and 3.1.x YAML or JSON. It checks syntax, string mapping keys, version and info types, path-item and operation object shapes, and directly declared response codes and descriptions. The version matters: 3.0 requires paths and operation responses; 3.1 can instead contain components or webhooks and does not require a responses field on every operation. YAML syntax diagnostics show source line and column; structural findings use escaped JSON Pointer paths. It does not validate Schema Objects, parameter matching, security schemes, callbacks, vendor rules or any local/remote reference target. Passing these checks is not full OpenAPI conformance. Inputs stay in the page without saved drafts or endpoint requests. Limits are 2 MiB, 100 nesting levels, 100,000 visited nodes, bounded YAML alias expansion and at most 100 displayed findings.

Scenario Recipes

01

Check a components-only OpenAPI 3.1 document

Goal: Catch version-specific false errors before reviewing the complete contract

  1. Paste {"openapi":"3.1.0","info":{"title":"Shared models","version":"1.0"},"components":{}} and run the local checks.
  2. The listed checks pass because 3.1 allows components without paths. Change the version to 3.0.3 and run again to see the missing paths finding.
  3. Restore the intended version, then use your CI validator to check schema definitions and reference targets.

Result: A version-aware local report with the unvalidated contract portions stated explicitly.

Frequently Asked Questions

Which OpenAPI versions are supported?

Selected structure checks accept 3.0.x and 3.1.x version strings. OpenAPI 2.0 and 3.2 are outside this checker’s scope.

Why can a 3.1 document omit paths or operation responses?

OpenAPI 3.1 requires at least one of paths, components or webhooks. Its operation responses field is optional; in 3.0, paths and operation responses are required. A responses object, when present, must contain at least one response.

Does passing mean my whole API contract is valid?

No. Checks stop at the listed surface structure. Schemas, parameter/path matching, security, callbacks, semantic relationships and local or external reference targets are not validated. Use a full version-aware validator in CI.

Why must YAML response codes be quoted?

OpenAPI maps use string keys. Write "200": rather than a numeric YAML key. YAML duplicate keys, unsupported tags, recursive aliases and excessive alias expansion are rejected rather than silently normalized.

What do source locations and paths represent?

Parser findings include source line and column when available. Structural findings use JSON Pointer escaping: a path key /orders is represented by ~1orders. At most 100 findings are displayed; a notice appears if more were found.

Are documents uploaded, fetched or saved?

No. Pasted text and selected files are checked locally and are not saved as drafts. No endpoint or reference URL is fetched. Editing, replacing a file or clearing the tool invalidates the previous report.

Keep browsing