NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2525 most downloaded on PyPI
client-side and server-side support for the OpenAPI Specification v3
Last release 6 months ago
02 Apr 2026
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 47 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
77 releases · first in 2017
Add Starlette 1.x support #1151
Fix deprecation warnings for omitted params and headers #1125
One column per quarter.
Upgrade jsonschema-path 0.4.0b8 and openapi-spec-validator 0.8.0b3 #1002
Typed style deserializers (casting is part of style deserializing) #1075
style_deserializers_factory and media_tyles_deserialization_factory defaults to None in configuration and protocolsCastError inherits from DeserializeErrorStyleDeserializersFactory requires schema_caster_factorystyle_deserialization_factory and media_tyles_deserialization_factory objectsCache compiled path parsers #1063
Accomodate type changes in werkzeug 3.1.4, resolve CVE-2025-66221 #1041
Allow Starlette 0.41.x and FastAPI 0.115.x; bump to 0.41.2 and 0.115.4, respectively #933
Fix resolvers not updating properly when referencing other files. #894
spec_base_uri configuration is deprecated. Use base_uri parameter in OpenAPI.from_dict and OpenAPI.from_file if you want to define it. #859
base_uri from schema path for spec validation #859spec_base_uri configuration is deprecated. Use base_uri parameter in OpenAPI.from_dict and OpenAPI.from_file if you want to define it. #859Fix a DeprecationWarning from aiohttp in TestPetPhotoView #836
Path finder cls configuration #797
Spec class is deprecated. Use SchemaPath from jsonschema-path package.
This version focuses on OpenAPI app and support for binary requests and responses.
SchemaPath from jsonschema-path package #690mimetype with content_type to include content parameters #699Spec class is deprecated. Use SchemaPath from jsonschema-path package.request_class/response_class renamed to request_cls/response_cls in unmarshalling processors (Django, Falcon and Flask integrations) #667ParameterDeserializersFactory renamed to StyleDeserializersFactory #676Spec object creation and moved to be part of OpenAPI object creation. #686 #716Request and Response protocols' mimetype attribute replaced with content_type #699Request protocol's body attribute returns bytes instead of str #710Response protocol's data attribute returns bytes instead of str #710FormatUnmarshalErrorThis version focuses on OpenAPI app and support for binary requests and responses.
This version focuses on OpenAPI app and support for binary requests and responses.
FormatUnmarshalErrorSpec class is deprecated. Use SchemaPath from jsonschema-path package.
This version focuses on OpenAPI app and support for binary requests and responses.
SchemaPath from jsonschema-path package #690mimetype with content_type to include content parameters #699Spec class is deprecated. Use SchemaPath from jsonschema-path package.request_class/response_class renamed to request_cls/response_cls in unmarshalling processors (Django, Falcon and Flask integrations) #667ParameterDeserializersFactory renamed to StyleDeserializersFactory #676Spec object creation and moved to be part of OpenAPI object creation. #686 #716Request and Response protocols' mimetype attribute replaced with content_type #699Request protocol's body attribute returns bytes instead of str #710Response protocol's data attribute returns bytes instead of str #710Deprecated spec validator fix + warnings resolved #717
Ignore formats for other types in unmarshalling process #599
FalconOpenAPIMiddleware, FlaskOpenAPIView, FlaskOpenAPIViewDecorator) #623spec_url parameter of Spec.from_dict is deprecated. Use base_uri instead. #597
This version drops support for Python 3.7
spec_url parameter of Spec.from_dict is deprecated. Use base_uri instead. #597ref_resolver_handlers parameter of Spec.from_dict is deprecated. Use handlers instead. #597Spec.create methodspec as a first parameter for validate_request and validate_response shortcutsvalidator parameter for validate_request and validate_response shortcutsvalidate_request and validate_response shortcutsRequestValidator, ResponseValidator and openapi_ objectscustom_deserializersparametercustom_formattersparameterspec_url parameter of Spec.from_dict is deprecated. Use base_uri instead.
This version drops support for Python 3.7
spec_url parameter of Spec.from_dict is deprecated. Use base_uri instead.ref_resolver_handlers parameter of Spec.from_dict is deprecated. Use handlers instead.Spec.create methodspec as a first parameter for validate_request and validate_response shortcutsvalidator parameter for validate_request and validate_response shortcutsvalidate_request and validate_response shortcutsRequestValidator, ResponseValidator and openapi_ objectscustom_deserializersparametercustom_formattersparameterShortcuts: validate_request and validate_response show deprecation warning on return value use only #589
validate_request and validate_response show deprecation warning on return value use only #589Include tests in sdist archives #537
ParametersError context property deprecated #462
ParametersError context property deprecated #462Spec.create deprecated #463UnmarshalContext to ValidationContext #472PATH_PARAMETER_PATTERN for DRF default value pattern. #468RequestValidator and ResponseValidator backward compatibility #487Request Response factories check types fix #490Invalid* exception (InvalidData, InvalidParameter, InvalidRequestBody, InvalidHeader). Use __cause__ property to get root cause exception.InvalidSecurity exception renamed to SecurityNotFoundFix Requests request dont allow fragments #491
Shortcuts backward compatible #482
RequestValidator and ResponseValidator backward compatibility #487Request Response factories check types fix #490ParametersError context property deprecated #462
UnmarshalContext to ValidationContext #472request parameter for validate_request shortcut function moved to first positionrequest and response parameters for validate_response shortcut function moved to first and second positionInvalid* exception (InvalidData, InvalidParameter, InvalidRequestBody, InvalidHeader). Use __cause__ property to get root cause exception.InvalidSecurity exception renamed to SecurityNotFoundopenapi-schema-validator 0.5.2 tests compatibility fix #527
validators public api expose #455
better unmarshaller finders with refactor #447
werkzeug flask root path fix #449
Unmarshaller format refactor #434
lists as additional properties fix #429
Use auto-detect validator proxy #418
Parameter deserialize complex scenario support
NoValue type removed (#340)attrs remove and use dataclasses backport for python 3.6 (#345)pathable #389create_spec shortcut #393Request and Response protocols #407headers attribute added to OpenAPIResponse datatypeRequestParameters' header attribute as Headers typeRequestParameters' cookie attribute as ImmutableMultiDict typeRequestValidationResult' parameters attribute as Parameters typeserver, operation and path attributes removed from RequestValidationResultEmptyParameterValue exception renamed to EmptyQueryParameterValueFalconOpenAPIRequestFactory requires to be instantiatedcreate_spec shortcut replaced with Spec.createOpenAPIRequest and OpenAPIResponse removed. All backward compabilities fromcontrib removed.spec_validate_* shortcuts removed. Use validate_request and validate_response with validator parameter instead.validate_{parameters,body,security} shortcuts removed. Use predefined openapi_request_parameters_validator, openapi_request_body_validator and openapi_request_security_validator from openapi_core.validation.request instead.validate_{data,headers} shortcuts removed. Use predefined openapi_response_data_validator and openapi_response_headers_validator from openapi_core.validation.response instead.custom_media_type_deserializers parameter for RequestValidator and ResponseValidator removed. Use MediaTypeDeserializersFactory with custom_deserializers parameter and pass it to validator with media_type_deserializers_factory parameter.custom_formatters parameter for RequestValidator and ResponseValidator removed. Use SchemaUnmarshallersFactory with custom_formatters parameter and pass it to validator.Request and Response protocols #407
Request and Response protocols #407OpenAPIRequest and OpenAPIResponse removed. All backward compabilities fromcontrib removed.spec_validate_* shortcuts removed. Use validate_request and validate_response with validator parameter instead.validate_{parameters,body,security} shortcuts removed. Use predefined openapi_request_parameters_validator, openapi_request_body_validator and openapi_request_security_validator from openapi_core.validation.request instead.validate_{data,headers} shortcuts removed. Use predefined openapi_response_data_validator and openapi_response_headers_validator from openapi_core.validation.response instead.custom_media_type_deserializers parameter for RequestValidator and ResponseValidator removed. Use MediaTypeDeserializersFactory with custom_deserializers parameter and pass it to validator with media_type_deserializers_factory parameter.custom_formatters parameter for RequestValidator and ResponseValidator removed. Use SchemaUnmarshallersFactory with custom_formatters parameter and pass it to validator.Parameter deserialize complex scenario support
NoValue type removed (#340)attrs remove and use dataclasses backport for python 3.6 (#345)pathable #389create_spec shortcut #393headers attribute added to OpenAPIResponse datatypeRequestParameters' header attribute as Headers typeRequestParameters' cookie attribute as ImmutableMultiDict typeRequestValidationResult' parameters attribute as Parameters typeserver, operation and path attributes removed from RequestValidationResultEmptyParameterValue exception renamed to EmptyQueryParameterValueFalconOpenAPIRequestFactory requires to be instantiatedcreate_spec shortcut replaced with Spec.createopenapi-spec-validator strict requirement fix #406
pyyaml strict requirement fix #404
# Changelog * pin openapi dependencies #403
# Changelog * Non required request body fix
Parameter simple scenarion for any schema type fix
openapi-core 0.14 is scheduled to be the last major version in the 0.x series.
openapi-core 0.14 is scheduled to be the last major version in the 0.x series.
This release introduces SpecPath which reduces spec creation time and allows to get rid of big schema package
Changes:
Spec replaced with SpecPath (#318)Backward incompatibilities:
create_spec shortcut returns SpecPath instead of Specschema packageexceptions moved to top level exceptions modulereadOnly/writeOnly invalid properties raise error (before were ommitted)MediaTypeDeserializersFactory.create expects mimetype string instead of media_typeMediaTypeFinder.find returns media_type, mimetype tuple instead of just media_typeuse prepared request to format payload before converting
Format checker deepcopy to shallowcopy
Remove security on operation level fix
return None on nullable array type
Paths finder relative url and simple paths check fix
Path patterns finder (#202) - server and path with variables resolving
openapi-schema-validator library (#212)werkzeug missing dependency fix
# Changelog * Flask error handler status fix (#199) * Validators shortcuts fix
OpenAPI request/response factories introduction
RequestParameters. That means parameters in RequestValidationResult is no longer dict type but you can still access parameter types (path, query, heder, cookie) lika a dict.validate_body, validate_parameters and validate_data no longer accept wrapper_class, request_wrapper_class and response_wrapper_class keyword arguments. Use request_factory and response_factory instead.openapi_core.wrappers.flask module moved to openapi_core.contrib.flaskopenapi_core.wrappers.mock module moved to openapi_core.testing.mockstrict parameter removedFormatter class. Custom formatters should inherit from the class.InvalidMediaTypeValue and InvalidParameterValue exceptionsInvalidParameterValue exceptionInvalidMediaTypeValue exceptionOpenAPIRequest 's host_url and path_pattern attributes replaced with full_url_pattern attributeThis release contains new Open API schema validation based on jsonschema (OAS Validator).
This release contains new Open API schema validation based on jsonschema (OAS Validator).
# Changelog * Path item parameter override (#145) * Separate cast and unmarshal
openapi-core 0.11 is the last major version with schema validation based on internal validators (object validators). Next major versions is scheduled
openapi-core 0.11 is the last major version with schema validation based on internal validators (object validators). Next major versions is scheduled to be based on jsonschema validators (OAS Validator).
openapi-core 0.10 is the last major version with Python 3.4 support
openapi-core 0.10 is the last major version with Python 3.4 support
password string format (#132)Raw value type strict validation (#123
Dont use value for determining any type
# Changelog * Python 2.7 requirements fix
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →