API reference workflow

Read OpenAPI locally without hiding unresolved references

An operation list helps a handoff, but an empty field can mean missing source data or an unresolved reference. Keep those states distinct.

Content updated: · Maintainer and corrections

Start with the declared version and scope

This explorer accepts JSON declaring OpenAPI 3.0.x or 3.1.x, with info.title, info.version and paths. Swagger 2.0 and OpenAPI 3.2 require different handling and are rejected. Parsing a supported document is not complete specification validation.

Paste up to 1 MiB and at most 1,000 operations. The directory shows 50 entries per page; search matches method, path, summary, operationId and tags. Export retains all operations even when the directory is filtered.

Follow inheritance deliberately

Path-level parameters apply to operations. An operation parameter with the same name and in value replaces that path parameter. Servers use operation, then path, then document scope; an absent or empty server list uses the specification default /. Operation security replaces root security, including an explicit empty array that removes inherited requirements.

Inspect effective parameters, responses, requestBody, servers and security together. Displayed security requirements describe the document; the tool does not authenticate, authorize, contact a server or verify whether the API enforces them.

Treat unresolved refs as unfinished evidence

Local #/ JSON Pointers resolve through own properties with URI-fragment percent decoding followed by ~0 and ~1 decoding, a depth limit of 40 and a shared work budget of 100,000 visited values. External references, anchors, missing targets, cycles and limits stay visibly unresolved. No reference is fetched over HTTP.

Reference siblings are not merged and produce a warning. This bounded policy avoids pretending that version-specific reference and JSON Schema rules were fully applied. Keep the original document and use a full version-aware validator when correctness depends on those semantics.

Review exports before sharing

Descriptions are React text, not rendered Markdown or HTML. JSON and Markdown exports include operation details and all warnings; the page previews only the first 50 warnings. Examples and server URLs can still contain secrets or private infrastructure names: local processing is not automatic redaction.

Inputs remain in page memory without upload, persistence, URL insertion or input analytics. Editing revokes the report. The static source snapshot for this guide is 2026-10-09; downloaded files and clipboard contents remain under your device's control.

Path parameter: {"name":"id","in":"path"}
Operation with the same pair overrides it.
Operation security: [] removes root security requirements.

Data provenance

Sources