You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Swagger 2.0安全方案已定义但未使用问题:端点认证保护配置方法问询

Fixing "Security scheme was defined but never used" in Swagger 2.0

Hey there, let's get that warning sorted out and make sure your API endpoints are properly locked down—no need to stress about competitors sneaking in once we fix this!

Why you're seeing the warning

You've correctly set up your api_key security scheme in securityDefinitions, but Swagger has no clue which endpoints should use it until you explicitly link the scheme to your paths or operations. That's exactly why you're getting the "never used" error message.

Two ways to apply the security scheme

You’ve got two solid options to associate your api_key with your endpoints—pick the one that fits your API’s needs:

1. Apply to ALL endpoints (global security)

Add a top-level security section to your Swagger file. This will enforce the API key requirement for every path in your document automatically:

swagger: "2.0"
info:
  version: 1.0.0
  title: Das ERP
host: virtserver.swaggerhub.com
basePath: /rossja/whatchamacallit/1.0.0
schemes:
  - https
securityDefinitions:
  api_key:
    type: apiKey
    name: api_key
    in: header
    description: API Key
# Add this global security block to enforce auth everywhere
security:
  - api_key: []  # References your defined api_key scheme
paths:
  /dt/invoicestatuses:
    get:
      tags:
        - invoice
      summary: Returns a list of invoice statuses
      produces:
        - application/json
      operationId: listInvoiceStatuses
      responses:
        200:
          description: OK
          schema:
            type: object
            properties:
              code:
                type: integer
              value:
                type: string

2. Apply to specific endpoints

If only certain paths need the API key check, add the security section directly inside the individual operation (like the get method for /dt/invoicestatuses):

paths:
  /dt/invoicestatuses:
    get:
      tags:
        - invoice
      summary: Returns a list of invoice statuses
      produces:
        - application/json
      operationId: listInvoiceStatuses
      # Add this to lock down just this endpoint
      security:
        - api_key: []
      responses:
        200:
          description: OK
          schema:
            type: object
            properties:
              code:
                type: integer
              value:
                type: string

Verifying your setup

Since you mentioned the authentication already works in production, your api_key configuration (name, location in the header) is spot-on. Adding the security reference will just update your Swagger documentation to reflect this requirement, and the warning will vanish immediately.

Now your Swagger docs will clearly show which endpoints require the api_key header, and you can rest easy knowing your data is properly protected as you intended.

内容的提问来源于stack exchange,提问作者jimjoseph_lebonboncroissant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 18:22:39