You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenAPI 3.0中正确配置Accept、Authorization及Content-Type?

解决Swagger中Authorization请求头不生效的问题

问题根源

你当前的配置同时存在两处Authorization相关定义:一处在parameters里手动声明请求头,另一处通过security引用安全方案。Swagger会忽略parameters中的Authorization头,且重复定义会导致配置冲突,所以请求中看不到该头。

正确配置方式

需要彻底移除parameters里的Authorization头定义,仅保留security和securitySchemes的配置,同时确保OpenAPI规范结构完整(必须包含openapi版本声明)。示例如下:

openapi: 3.0.3
paths:
  /path/user:
    get:
      security:
        - my_auth: []
      responses:
        '200':
          description: 成功响应
components:
  securitySchemes:
    my_auth:
      type: http
      scheme: bearer
      bearerFormat: JWT

关键说明

  • 移除冗余定义:删掉parameters数组中所有关于Authorization的配置,避免和security配置冲突。
  • 规范结构:根节点必须包含openapi版本(如3.0.3),这是OpenAPI 3.x规范的强制要求。
  • 测试验证:在Swagger Editor中,点击右上角的"Authorize"按钮,输入你的JWT令牌,之后发送/path/user的GET请求时,请求头会自动带上Authorization: Bearer <你的令牌>。

内容的提问来源于stack exchange,提问作者node_saini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 21:54:19