OpenAPI Lint

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Lint OpenAPI 3.x documents for missing security, responses, descriptions and versioning.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lints OpenAPI 3.x documents for missing security, responses, descriptions and versioning, and lists or fetches their operations.

What it does
Loads an OpenAPI 3.0 or 3.1 document from a local path or inline JSON/YAML and reports findings sorted by severity with rule id, JSON Pointer path and message. The lint_openapi tool covers version, servers, security schemes, missing responses, undescribed parameters, path parameters, operationIds, unversioned paths, empty request bodies, deprecated operations and undeclared tags. list_operations and get_operation enumerate operations with their effective security, parameters, media types and response codes, and explain_rule describes a rule and how to fix it.
When to use it
Useful when reviewing or maintaining an OpenAPI specification and you want an assistant to check completeness and security declarations, or to summarize the operations a document defines. It suits spec review and documentation work rather than testing a running API.
Requirements
Runs locally over stdio; no network access, accounts, API keys or environment variables are needed. Install via npx with the pinned package version, or run the container image with Docker. It reads one named local file, up to 5 MB.
Before you install
Findings describe the document, not the running API, so they are not a substitute for testing. Only local references are resolved and nothing is fetched. Pin the package version so an update cannot change what runs in your editor unnoticed.

Installation

In SourceWeft

  1. Open OpenAPI Lint in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

openapi-lint MCP server

Loads an OpenAPI 3.0 or 3.1 document (JSON or YAML, from a local path or inline) and lints it for security and completeness problems; lists and fetches operations with their effective security. Only local #/ references are resolved; nothing is fetched.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
lint_openapipath or document, ignore?Findings sorted by severity with rule id, JSON Pointer path and message: openapi version, http servers, missing, unused or undefined security schemes, operations without security (and explicitly public ones), operations without responses or success responses, undescribed responses and parameters, path parameters not declared or not required, missing or duplicate operationIds, unversioned paths, empty request bodies, deprecated operations, undeclared tags.
list_operationspath or document, tag?, method?, path_prefix?Every operation with operationId, summary, tags, deprecated flag, effective security (public for security: [], inherited-none when nothing applies), parameters, request media types and response codes.
get_operationpath or document, operation_id or method + operation_pathOne operation in full with path-level parameters merged and local references resolved.
explain_ruleruleSeverity, what the rule detects and how to fix it.

Install

Claude Code:

bash
claude mcp add openapi-lint -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "openapi-lint": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/openapi-lint/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: Reads the one file you name, up to 5 MB. YAML is parsed with an alias limit.
  • Telemetry: none.

Notes

  • Swagger 2.0 documents are reported by the openapi-version rule rather than linted.
  • Findings describe the document, not the running API.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-openapi-lintnpm test -w @basitalisandhu/mcp-openapi-lint

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/openapi-lint/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026