---
title: "Step 6: The security object (OpenAPI tutorial)"
date: 2026-09-27
description: "Download PDF Swagger UI provides a “Try it out” feature that lets users submit actual requests. To submit requests that are authorized by your API server,..."
canonical_url: https://idratherbewriting.com/learnapidoc/pubapis_openapi_step6_security_object
---
# Step 6: The security object (OpenAPI tutorial)
[STEP 1:openapi object](/learnapidoc/pubapis_openapi_step1_openapi_object.html)
→

[STEP 2:info object](/learnapidoc/pubapis_openapi_step2_info_object.html)
→

[STEP 3:servers object](/learnapidoc/pubapis_openapi_step3_servers_object.html)
→

[STEP 4: paths object](/learnapidoc/pubapis_openapi_step4_paths_object.html)
→

[STEP 5:components object](/learnapidoc/pubapis_openapi_step5_components_object.html)
→

[STEP 6:security object](/learnapidoc/pubapis_openapi_step6_security_object.html)
→

[STEP 7:tags object](/learnapidoc/pubapis_openapi_step7_tags_object.html)
→

[STEP 8:externalDocs object](/learnapidoc/pubapis_openapi_step8_externaldocs_object.html)
→

[STEP 9:Other elements](/learnapidoc/pubapis_openapi_step9_other_elements.html)

[Download PDF](https://www.buymeacoffee.com/learnapidoc/e/146076)

Swagger UI provides a “Try it out” feature that lets users submit actual requests. To submit requests that are authorized by your API server, the spec must contain security information that will authorize the request. The [security object](https://github.com/OAI/OpenAPI-Specification/blob/main/versions/3.1.1.md#securityRequirementObject) specifies the security or authorization protocol used when submitting requests.

## Which security scheme?

REST APIs can use different security approaches to authorize requests. I explored the most common authorization methods in [Authentication and authorization requirements](docapis_more_about_authorization.html). OpenAPI 3.1 supports several authorization schemes:

 - API key (`apiKey`)

 - HTTP (`http`) - for Basic, Bearer, and other HTTP authentication schemes.

 - OAuth 2.0 (`oauth2`)

 - OpenID Connect (`openIdConnect`)

 - Mutual TLS (`mutualTLS`)

In this step of the OpenAPI tutorial, we’ll use the API key approach, since this is what the OpenWeatherMap API uses. If your API uses [OAuth 2.0](docapis_more_about_authorization.html#oauth) or another method, you’ll need to read the [Security Scheme Object documentation](https://github.com/OAI/OpenAPI-Specification/blob/main/versions/3.1.1.md#security-scheme-object) for details on how to configure it. However, all the security methods mostly follow the same pattern.