$npx skillfedfor your agent

openapi-core

client-side and server-side support for the OpenAPI Specification v3

Worth itPyPI LibrariesReleased Apr 20264.3M downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — openapi_core-0.23.1-py3-none-any.whl
v0.23.1 · released 2026-04-02 · Python <4.0.0,>=3.10.0 · 8 runtime deps: isodate, jsonschema, jsonschema-path, more-itertools, openapi-schema-validator, openapi-spec-validator, typing-extensions, werkzeug

Yes. openapi-core is well-maintained, has no known vulnerabilities, and offers low install friction. It is the right choice if you need to validate or unmarshal OpenAPI v3.x data in a Python application, especially if you are already using one of its supported frameworks. The permissive BSD-3-Clause license poses no restrictions.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a request object that implements the OpenAPI Request protocol; for frameworks like Django, Flask, or Starlette, use the corresponding integration adapter.
  • Low install friction with a pure-Python wheel distribution.
  • Actively maintained with a recent release and no known vulnerabilities.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause is permissive; you may use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.

last release 2026-04-02 (134 days) · last repo commit 2026-08-09 · 368 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,272,937 downloads/mo, #2,344 on PyPI

Verify before relying

from openapi_core import OpenAPI

openapi = OpenAPI.from_file_path('openapi.json')
result = openapi.unmarshal_request(request)
path_params = result.parameters.path
query_params = result.parameters.query
body = result.body
  • Whether the package handles OpenAPI v2.0 (Swagger) specifications, or only v3.x versions as stated in the description.
  • Performance characteristics when validating large or deeply nested OpenAPI specifications.
  • Whether custom deserializers and unmarshallers are easy to implement for non-standard media types.
Same gist for agents: .md · .json

What it is and what it does

openapi-core is a Python library that validates and unmarshals HTTP request and response data against OpenAPI v3.0, v3.1, and v3.2 specifications. It extracts and type-converts parameters, headers, cookies, and request bodies according to the schema, raising an error if the data does not conform. The library works both client-side (validating responses from external APIs) and server-side (validating incoming requests), and includes built-in integrations with Requests, Werkzeug, Django, Flask, FastAPI, Starlette, Falcon, and AIOHTTP.

The package depends on jsonschema, openapi-schema-validator, and openapi-spec-validator to perform the actual validation logic. It is actively maintained, supports modern Python versions, and carries no known security vulnerabilities. Installation is straightforward via pip with low friction.

Use it for

  • Validate incoming API requests against an OpenAPI spec in a Flask or Django view to reject malformed data early.
  • Unmarshal and type-convert query parameters and path variables from a FastAPI or Starlette middleware layer.
  • Verify that responses from a third-party API conform to its published OpenAPI specification before processing.
  • Extract and validate security credentials (API keys, Bearer tokens, Basic auth) from requests according to the spec.
  • Build an API gateway or proxy that enforces OpenAPI compliance on both inbound and outbound traffic.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

openapi-core is well-maintained, has no known vulnerabilities, and offers low install friction. It is the right choice if you need to validate or unmarshal OpenAPI v3.x data in a Python application, especially if you are already using one of its supported frameworks. The permissive BSD-3-Clause license poses no restrictions.

Install

openapi-core on PyPI

Before you install

Low install friction with a pure-Python wheel distribution. Actively maintained with a recent release and no known vulnerabilities. Supports current Python versions (3.10–3.14).

Requires a request object that implements the OpenAPI Request protocol; for frameworks like Django, Flask, or Starlette, use the corresponding integration adapter.

License in practice

BSD-3-Clause is permissive; you may use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.

Quickstart

from openapi_core import OpenAPI

openapi = OpenAPI.from_file_path('openapi.json')
result = openapi.unmarshal_request(request)
path_params = result.parameters.path
query_params = result.parameters.query
body = result.body

Verify before relying

  • Whether the package handles OpenAPI v2.0 (Swagger) specifications, or only v3.x versions as stated in the description.
  • Performance characteristics when validating large or deeply nested OpenAPI specifications.
  • Whether custom deserializers and unmarshallers are easy to implement for non-standard media types.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release <4.0.0,>=3.10.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
isodatejsonschemajsonschema-pathmore-itertoolsopenapi-schema-validatoropenapi-spec-validatortyping-extensionswerkzeug
MaintenanceActively maintained 134 days since the last release
Last repo commit
First released
Downloads4,272,937 / month, #2,344 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: LibrariesTopic :: Software Development :: Libraries :: Python ModulesTyping :: Typed

Evidence: openapi_core-0.23.1-py3-none-any.whl

Tags

Capabilities
openapi validationopenapi request response validationopenapi unmarshallingopenapi schema validationapi specification validationopenapi framework integrationopenapi data unmarshalling
Topics
api-validationopenapischema-validation
PyPI keywords
openapiswaggerschema

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “openapi validation”

  • openapi-coreValidates and unmarshals OpenAPI v3.0, v3.1, and v3.2 request and…
  • voluptuous-openapiConverts Voluptuous validation schemas into OpenAPI 3.0 Schema…
  • bravado-corebravado-core validates, marshals, and transforms OpenAPI…

Give your agent the search over MCP, or paste the wish link into any chat.

More Libraries packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
python-dateutil Worth it
PyPI · Libraries · released Mar 2024

Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.

Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.

Apache-2.0pure Python
1.2Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo

See also openapi-schema-validator · openapi-spec-validator · aiopenapi3 · bravado-core · spectree · swagger-spec-validator · prance · openapi3 · apispec · coreapi