Multiple security schemes in OpenAPI: AND vs OR, optional auth, and per-operation overrides
The security array means OR, any one listed scheme is enough; combining schemes inside one requirement object means AND, all are required. Get this backwards and an endpoint that needs both an API key and a bearer token accepts just one, or a public endpoint demands credentials.
Oct 8, 20266 min read

