{"id":37158701,"url":"https://github.com/rtfpessoa/kin-openapi","last_synced_at":"2026-01-14T18:57:15.867Z","repository":{"id":57621384,"uuid":"392608009","full_name":"rtfpessoa/kin-openapi","owner":"rtfpessoa","description":"OpenAPI 3.0 implementation for Go (parsing, converting, validation, and more)","archived":false,"fork":true,"pushed_at":"2021-08-10T14:38:51.000Z","size":831,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-09-28T10:33:21.934Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"getkin/kin-openapi","license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rtfpessoa.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-08-04T08:21:57.000Z","updated_at":"2023-03-09T04:30:44.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/rtfpessoa/kin-openapi","commit_stats":null,"previous_names":[],"tags_count":73,"template":false,"template_full_name":null,"purl":"pkg:github/rtfpessoa/kin-openapi","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rtfpessoa%2Fkin-openapi","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rtfpessoa%2Fkin-openapi/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rtfpessoa%2Fkin-openapi/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rtfpessoa%2Fkin-openapi/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rtfpessoa","download_url":"https://codeload.github.com/rtfpessoa/kin-openapi/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rtfpessoa%2Fkin-openapi/sbom","scorecard":{"id":788064,"data":{"date":"2025-08-11","repo":{"name":"github.com/rtfpessoa/kin-openapi","commit":"7fd2ca16cdda3afc5f9a8b2dab3456a8fa2f662e"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.3,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/go.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/rtfpessoa/kin-openapi/go.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/rtfpessoa/kin-openapi/go.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/rtfpessoa/kin-openapi/go.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/rtfpessoa/kin-openapi/go.yml/master?enable=pin","Warn: goCommand not pinned by hash: .github/workflows/go.yml:73","Info:   0 out of   4 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":9,"reason":"1 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: CVE-2025-30153 / GO-2025-3533 / GHSA-wq9g-9vfc-cfq9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T06:38:59.426Z","repository_id":57621384,"created_at":"2025-08-23T06:38:59.426Z","updated_at":"2025-08-23T06:38:59.426Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28431035,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T16:38:47.836Z","status":"ssl_error","status_checked_at":"2026-01-14T16:34:59.695Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-14T18:57:15.086Z","updated_at":"2026-01-14T18:57:15.859Z","avatar_url":"https://github.com/rtfpessoa.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"[![CI](https://github.com/getkin/kin-openapi/workflows/go/badge.svg)](https://github.com/getkin/kin-openapi/actions)\n[![Go Report Card](https://goreportcard.com/badge/github.com/getkin/kin-openapi)](https://goreportcard.com/report/github.com/getkin/kin-openapi)\n[![GoDoc](https://godoc.org/github.com/getkin/kin-openapi?status.svg)](https://godoc.org/github.com/getkin/kin-openapi)\n[![Join Gitter Chat Channel -](https://badges.gitter.im/getkin/kin.svg)](https://gitter.im/getkin/kin?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge)\n\n# Introduction\nA [Go](https://golang.org) project for handling [OpenAPI](https://www.openapis.org/) files. We target the latest OpenAPI version (currently 3), but the project contains support for older OpenAPI versions too.\n\nLicensed under the [MIT License](LICENSE).\n\n## Contributors and users\nThe project has received pull requests from many people. Thanks to everyone!\n\nHere's some projects that depend on _kin-openapi_:\n  * [https://github.com/Tufin/oasdiff](https://github.com/Tufin/oasdiff) - \"A diff tool for OpenAPI Specification 3\"\n  * [github.com/getkin/kin](https://github.com/getkin/kin) - \"A configurable backend\"\n  * [github.com/danielgtaylor/apisprout](https://github.com/danielgtaylor/apisprout) - \"Lightweight, blazing fast, cross-platform OpenAPI 3 mock server with validation\"\n  * [github.com/deepmap/oapi-codegen](https://github.com/deepmap/oapi-codegen) - Generate Go server boilerplate from an OpenAPIv3 spec document\n  * [github.com/dunglas/vulcain](https://github.com/dunglas/vulcain) - \"Use HTTP/2 Server Push to create fast and idiomatic client-driven REST APIs\"\n  * [github.com/danielgtaylor/restish](https://github.com/danielgtaylor/restish) - \"...a CLI for interacting with REST-ish HTTP APIs with some nice features built-in\"\n  * [github.com/goadesign/goa](https://github.com/goadesign/goa) - \"Goa is a framework for building micro-services and APIs in Go using a unique design-first approach.\"\n  * (Feel free to add your project by [creating an issue](https://github.com/getkin/kin-openapi/issues/new) or a pull request)\n\n## Alternatives\n* [go-swagger](https://github.com/go-swagger/go-swagger) stated [*OpenAPIv3 won't be supported*](https://github.com/go-swagger/go-swagger/issues/1122#issuecomment-575968499)\n* [swaggo](https://github.com/swaggo/swag) has an [open issue on OpenAPIv3](https://github.com/swaggo/swag/issues/386)\n* [go-openapi](https://github.com/go-openapi)'s [spec3](https://github.com/go-openapi/spec3)\n\t* an iteration on [spec](https://github.com/go-openapi/spec) (for OpenAPIv2)\n\t* see [README](https://github.com/go-openapi/spec3/tree/3fab9faa9094e06ebd19ded7ea96d156c2283dca#oai-object-model---) for the missing parts\n* See [https://github.com/OAI](https://github.com/OAI)'s [great tooling list](https://github.com/OAI/OpenAPI-Specification/blob/master/IMPLEMENTATIONS.md)\n\n# Structure\n  * _openapi2_ ([godoc](https://godoc.org/github.com/getkin/kin-openapi/openapi2))\n    * Support for OpenAPI 2 files, including serialization, deserialization, and validation.\n  * _openapi2conv_ ([godoc](https://godoc.org/github.com/getkin/kin-openapi/openapi2conv))\n    * Converts OpenAPI 2 files into OpenAPI 3 files.\n  * _openapi3_ ([godoc](https://godoc.org/github.com/getkin/kin-openapi/openapi3))\n    * Support for OpenAPI 3 files, including serialization, deserialization, and validation.\n  * _openapi3filter_ ([godoc](https://godoc.org/github.com/getkin/kin-openapi/openapi3filter))\n    * Validates HTTP requests and responses\n    * Provides a [gorilla/mux](https://github.com/gorilla/mux) router for OpenAPI operations\n  * _openapi3gen_ ([godoc](https://godoc.org/github.com/getkin/kin-openapi/openapi3gen))\n    * Generates `*openapi3.Schema` values for Go types.\n\n# Some recipes\n## Loading OpenAPI document\nUse `openapi3.Loader`, which resolves all references:\n```go\ndoc, err := openapi3.NewLoader().LoadFromFile(\"swagger.json\")\n```\n\n## Getting OpenAPI operation that matches request\n```go\nloader := openapi3.NewLoader()\ndoc, _ := loader.LoadFromData([]byte(`...`))\n_ := doc.Validate(loader.Context)\nrouter, _ := gorillamux.NewRouter(doc)\nroute, pathParams, _ := router.FindRoute(httpRequest)\n// Do something with route.Operation\n```\n\n## Validating HTTP requests/responses\n```go\npackage main\n\nimport (\n\t\"bytes\"\n\t\"context\"\n\t\"encoding/json\"\n\t\"log\"\n\t\"net/http\"\n\n\t\"github.com/getkin/kin-openapi/openapi3filter\"\n\tlegacyrouter \"github.com/getkin/kin-openapi/routers/legacy\"\n)\n\nfunc main() {\n\tctx := context.Background()\n\tloader := \u0026openapi3.Loader{Context: ctx}\n\tdoc, _ := loader.LoadFromFile(\"openapi3_spec.json\")\n\t_ := doc.Validate(ctx)\n\trouter, _ := legacyrouter.NewRouter(doc)\n\thttpReq, _ := http.NewRequest(http.MethodGet, \"/items\", nil)\n\n\t// Find route\n\troute, pathParams, _ := router.FindRoute(httpReq)\n\n\t// Validate request\n\trequestValidationInput := \u0026openapi3filter.RequestValidationInput{\n\t\tRequest:    httpReq,\n\t\tPathParams: pathParams,\n\t\tRoute:      route,\n\t}\n\tif err := openapi3filter.ValidateRequest(ctx, requestValidationInput); err != nil {\n\t\tpanic(err)\n\t}\n\n\tvar (\n\t\trespStatus      = 200\n\t\trespContentType = \"application/json\"\n\t\trespBody        = bytes.NewBufferString(`{}`)\n\t)\n\n\tlog.Println(\"Response:\", respStatus)\n\tresponseValidationInput := \u0026openapi3filter.ResponseValidationInput{\n\t\tRequestValidationInput: requestValidationInput,\n\t\tStatus:                 respStatus,\n\t\tHeader:                 http.Header{\"Content-Type\": []string{respContentType}},\n\t}\n\tif respBody != nil {\n\t\tdata, _ := json.Marshal(respBody)\n\t\tresponseValidationInput.SetBodyBytes(data)\n\t}\n\n\t// Validate response.\n\tif err := openapi3filter.ValidateResponse(ctx, responseValidationInput); err != nil {\n\t\tpanic(err)\n\t}\n}\n```\n\n## Custom content type for body of HTTP request/response\n\nBy default, the library parses a body of HTTP request and response\nif it has one of the next content types: `\"text/plain\"` or `\"application/json\"`.\nTo support other content types you must register decoders for them:\n\n```go\nfunc main() {\n\t// ...\n\n\t// Register a body's decoder for content type \"application/xml\".\n\topenapi3filter.RegisterBodyDecoder(\"application/xml\", xmlBodyDecoder)\n\n\t// Now you can validate HTTP request that contains a body with content type \"application/xml\".\n\trequestValidationInput := \u0026openapi3filter.RequestValidationInput{\n\t\tRequest:    httpReq,\n\t\tPathParams: pathParams,\n\t\tRoute:      route,\n\t}\n\tif err := openapi3filter.ValidateRequest(ctx, requestValidationInput); err != nil {\n\t\tpanic(err)\n\t}\n\n\t// ...\n\n\t// And you can validate HTTP response that contains a body with content type \"application/xml\".\n\tif err := openapi3filter.ValidateResponse(ctx, responseValidationInput); err != nil {\n\t\tpanic(err)\n\t}\n}\n\nfunc xmlBodyDecoder(body []byte) (interface{}, error) {\n\t// Decode body to a primitive, []inteface{}, or map[string]interface{}.\n}\n```\n\n## Custom function to check uniqueness of array items\n\nBy defaut, the library check unique items by below predefined function\n\n```go\nfunc isSliceOfUniqueItems(xs []interface{}) bool {\n\ts := len(xs)\n\tm := make(map[string]struct{}, s)\n\tfor _, x := range xs {\n\t\tkey, _ := json.Marshal(\u0026x)\n\t\tm[string(key)] = struct{}{}\n\t}\n\treturn s == len(m)\n}\n```\n\nIn the predefined function using `json.Marshal` to generate a string can\nbe used as a map key which is to support check the uniqueness of an array\nwhen the array items are objects or arrays. You can register\nyou own function according to your input data to get better performance:\n\n```go\nfunc main() {\n\t// ...\n\n\t// Register a customized function used to check uniqueness of array.\n\topenapi3.RegisterArrayUniqueItemsChecker(arrayUniqueItemsChecker)\n\n\t// ... other validate codes\n}\n\nfunc arrayUniqueItemsChecker(items []interface{}) bool {\n\t// Check the uniqueness of the input slice\n}\n```\n\n## Sub-v0 breaking API changes\n\n### v0.61.0\n* Renamed `openapi2.Swagger` to `openapi2.T`.\n* Renamed `openapi2conv.FromV3Swagger` to `openapi2conv.FromV3`.\n* Renamed `openapi2conv.ToV3Swagger` to `openapi2conv.ToV3`.\n* Renamed `openapi3.LoadSwaggerFromData` to `openapi3.LoadFromData`.\n* Renamed `openapi3.LoadSwaggerFromDataWithPath` to `openapi3.LoadFromDataWithPath`.\n* Renamed `openapi3.LoadSwaggerFromFile` to `openapi3.LoadFromFile`.\n* Renamed `openapi3.LoadSwaggerFromURI` to `openapi3.LoadFromURI`.\n* Renamed `openapi3.NewSwaggerLoader` to `openapi3.NewLoader`.\n* Renamed `openapi3.Swagger` to `openapi3.T`.\n* Renamed `openapi3.SwaggerLoader` to `openapi3.Loader`.\n* Renamed `openapi3filter.ValidationHandler.SwaggerFile` to `openapi3filter.ValidationHandler.File`.\n* Renamed `routers.Route.Swagger` to `routers.Route.Spec`.\n\n### v0.51.0\n* Type `openapi3filter.Route` moved to `routers` (and `Route.Handler` was dropped. See https://github.com/getkin/kin-openapi/issues/329)\n* Type `openapi3filter.RouteError` moved to `routers` (so did `ErrPathNotFound` and `ErrMethodNotAllowed` which are now `RouteError`s)\n* Routers' `FindRoute(...)` method now takes only one argument: `*http.Request`\n* `getkin/kin-openapi/openapi3filter.Router` moved to `getkin/kin-openapi/routers/legacy`\n* `openapi3filter.NewRouter()` and its related `WithSwaggerFromFile(string)`, `WithSwagger(*openapi3.Swagger)`, `AddSwaggerFromFile(string)` and `AddSwagger(*openapi3.Swagger)` are all replaced with a single `\u003crouter package\u003e.NewRouter(*openapi3.Swagger)`\n\t* NOTE: the `NewRouter(doc)` call now requires that the user ensures `doc` is valid (`doc.Validate() != nil`). This used to be asserted.\n\n### v0.47.0\nField `(*openapi3.SwaggerLoader).LoadSwaggerFromURIFunc` of type `func(*openapi3.SwaggerLoader, *url.URL) (*openapi3.Swagger, error)` was removed after the addition of the field `(*openapi3.SwaggerLoader).ReadFromURIFunc` of type `func(*openapi3.SwaggerLoader, *url.URL) ([]byte, error)`.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frtfpessoa%2Fkin-openapi","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frtfpessoa%2Fkin-openapi","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frtfpessoa%2Fkin-openapi/lists"}