Skip to content

Security

@security on a namespace declares schemes in components.securitySchemes; @operationSecurity attaches requirements to one operation as $ref pointers.

The emitter matches AsyncAPI 3.1 exactly: apiKey, asymmetricEncryption, gssapi, http, httpApiKey, oauth2, openIdConnect, plain, scramSha256, scramSha512, symmetricEncryption, userPassword, X509.

Not valid (rejected with diagnostics): sasl (use the specific mechanism), mutualTLS, external, oauthBearer.

@security(#{
name: "oauth2"
scheme: #{
type: "oauth2"
flows: #{
clientCredentials: #{
tokenUrl: "https://auth.example.com/oauth/token"
availableScopes: #{ read: "Read access", write: "Write access" }
}
}
}
})
namespace SecureAPI;

Two distinct schemes, straight from the AsyncAPI 3.1 schema:

  • apiKey — { type, in } with in limited to "user" or "password" (SASL-style, no name)
  • httpApiKey — { type, name, in }, all required, in limited to "header", "query", or "cookie"

plain, scramSha256, scramSha512, and gssapi accept { type, description? } only.

@operationSecurity(#{ name: "oauth2" })
@channel("orders")
@publish
op placeOrder(): Order;

This attaches { $ref: "#/components/securitySchemes/oauth2" } to the operation. The referenced scheme must also be declared with @security, or the ref dangles.