OpenAPI validator
Validate an OpenAPI 3.x / Swagger 2.0 document entirely in the browser: required openapi/info/paths fields, version format, paths starting with /, non-empty responses on every operation, complete parameters, and $ref targets that resolve inside the document — all reported with JSON Pointer paths.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Result
Paste an OpenAPI / Swagger document to validate
What this tool does
- Self-check an API document before submitting it: catch missing required fields, wrong version numbers, bad path keys and empty responses before review does.
- Find out why a code generator or gateway rejects the document — structural problems (missing fields, paths not starting with /, empty responses) are usually the cause.
- Confirm no $ref points at a schema that was deleted: every reference is resolved inside the document, and a dangling one is reported with its location.
- Get a quick overview of an inherited Swagger 2.0 document: how many paths, operations and schemas it actually contains.
Example
Input
openapi: 3.0.0
info:
title: Pet store
paths:
pets:
get:
summary: list petsOutput
/info/version [错误] info.version 缺失或为空 /paths/pets [错误] path 必须以 / 开头:pets /paths/pets/get/responses [错误] operation 缺少 responses
Every problem carries a JSON Pointer location (such as /paths/pets/get/responses) so you can jump straight to the offending line.
Frequently asked questions
Does it validate over the network?
No, it never makes a single request. Validation only looks at the document you paste: external references such as ./shared.yaml#/Pet are reported as "not resolved", while internal references (#/components/schemas/X) really are resolved as JSON Pointers and checked for existence.
Why are there warnings when errors is 0?
Warnings are things that do not invalidate the document but are probably not what you meant: an empty paths object, a suspicious status code such as 9999, a duplicate operationId, or an external $ref. They do not affect the valid flag, but they are worth fixing.
Which fields are actually required?
Per the specification: openapi (or swagger for 2.0), info, paths, plus title and version inside info. All of those are errors here. Everything else (servers, tags, security) is optional and is not checked.
Is OpenAPI 3.1 supported?
Yes. The version field accepts 3.x[.y] and suffixed forms such as 3.1.0-rc1. Since 3.1 allows paths to be empty, that case is only a warning rather than an error.
Is my document uploaded anywhere?
No. Parsing and validation run entirely in your browser with JavaScript, the page makes no network requests, and it keeps working with the network disconnected.
Keywords:openapi 验证swagger 验证openapi validatorswagger validatorapi 文档校验lint openapijson pointer接口文档检查paths$ref