Prev Next

API / Swagger Interview questions

Explain how to enforce validation constraints in an OpenAPI schema?

OpenAPI schemas support a range of validation keywords, inherited from JSON Schema, that go beyond simply declaring a field's type — letting a spec express constraints like string length, numeric ranges, and allowed value sets that a validating tool can check requests and responses against.

Product:
  type: object
  required: [name, price]
  properties:
    name:
      type: string
      minLength: 1
      maxLength: 100
    price:
      type: number
      minimum: 0
      exclusiveMinimum: true
    category:
      type: string
      enum: [electronics, clothing, food]
    sku:
      type: string
      pattern: '^[A-Z]{3}-\\d{4}$'

Common constraint keywords include minLength/maxLength for strings, minimum/maximum (with optional exclusiveMinimum/exclusiveMaximum) for numbers, enum for a fixed set of allowed values, and pattern for regex-validated string formats like the SKU example above; array types additionally support minItems, maxItems, and uniqueItems.

These constraints matter beyond documentation value: request validation middleware (in an API gateway, or in framework-integrated validation like Spring's Bean Validation working alongside springdoc-openapi) can enforce them automatically against real incoming requests, rejecting invalid data before it ever reaches business logic, and mock servers can use the same constraints to generate more realistic sample data than an unconstrained schema would allow.

What keyword restricts a string field to a fixed set of allowed values?
What can enforce these constraints against real incoming requests, not just documentation?

More Related questions...

What is Swagger? What is the purpose of Swagger? What is the OpenAPI Specification? What is the difference between Swagger and OpenAPI? What are the key components of Swagger? What is Swagger UI? What is Swagger Editor? What is Swagger Codegen? Define paths in an OpenAPI document? What are operations in OpenAPI? What is a schema in OpenAPI? What are the supported formats for writing an OpenAPI document? What is the purpose of the info object in OpenAPI? What are tags used for in Swagger? List the HTTP methods supported in OpenAPI operations? What is a parameter in OpenAPI, and what are its types? What is a response object in OpenAPI? Describe the components section in OpenAPI 3.0? What is $ref used for in OpenAPI documents? How do you use Swagger annotations in a Java Spring Boot application? What is the difference between OpenAPI 2.0 (Swagger) and OpenAPI 3.0? What is the difference between OpenAPI 3.0 and OpenAPI 3.1? Why is contract-first API design preferred over code-first in some teams? How does Swagger support security schemes like OAuth2 and API keys? What is the difference between springfox and springdoc-openapi? How do you document request and response examples in OpenAPI? Explain how Swagger Codegen generates client SDKs from an OpenAPI spec? What is the difference between path parameters and query parameters? How do you handle polymorphism and discriminators in OpenAPI schemas? Explain the lifecycle of validating an OpenAPI document with a linter like Spectral? When should you use the allOf, oneOf, and anyOf keywords in OpenAPI schemas? How do you version a REST API documented with Swagger? What happens when you click "Try it out" in Swagger UI? How do you split a large OpenAPI specification across multiple files? Explain the internal working of Swagger UI's rendering process? How do you mock an API server using an OpenAPI specification? What is the difference between Swagger and Postman? How do you deprecate an API operation in OpenAPI? Explain the execution flow of generating server stubs from an OpenAPI document? What is the difference between Swagger 2.0's definitions and OpenAPI 3.0's components/schemas? How does content negotiation work in OpenAPI, using the content field? Why doesn't OpenAPI natively describe webhooks before version 3.1? How do you handle authentication in Swagger UI for testing secured endpoints? What is the difference between OpenAPI Generator and the legacy Swagger Codegen? Explain how to enforce validation constraints in an OpenAPI schema? How do you convert a Swagger 2.0 document to OpenAPI 3.0? What is the role of the servers object in OpenAPI 3.0? Explain the internal working of $ref resolution across multiple OpenAPI files? How do you implement contract testing using an OpenAPI specification? Explain the execution flow of API documentation generation in a CI/CD pipeline using Swagger/OpenAPI tooling?
Show more question and Answers...

BigData

Comments & Discussions