Skip to content
Owais Khan Software Reviews

Custom GPT Action Schema Validator

Paste the OpenAPI schema for a Custom GPT action and see every error the GPT builder will raise — and the ones it will not raise but that stop the action working — with an auto-fixed version to copy back.

Everything runs locally: your schema never leaves your browser.

Validate a GPT action schema

4 errors and 1 warning.

  • error paths./todos.get
    In path /todos, method get is missing operationId; skipping. Suggested: getTodos.
  • warning paths./todos.get.parameters.X-Workspace
    Header parameter "X-Workspace": custom headers are not supported in GPT actions. Move it to the query string or body, or configure it as API-key authentication.
  • error paths./todos/{id}.delete
    Path parameter {id} is not declared in parameters (in: path, required: true).
  • error paths./todos.get.responses.200.content.application/json.schema
    In context=(paths./todos.get.responses.200.content.application/json.schema), array schema missing items. Say what the array contains with items.
  • error paths./todos.post.requestBody.content.application/json.schema
    In context=(paths./todos.post.requestBody.content.application/json.schema), object schema missing properties. List the object's fields under properties.

Operations

MethodPathoperationIdAsks to confirm?
GET /todos — missing No (default)
POST /todos createTodo Yes (default)
DELETE /todos/{id} deleteTodo Yes (default)

Auto-fixed schema

  • Added operationId getTodos to GET /todos
  • Added items: {} to paths./todos.get.responses.200.content.application/json.schema — say what the array holds if you know it
  • Added empty properties to paths./todos.post.requestBody.content.application/json.schema — list its real fields if you know them

Only mechanical fixes are made. Anything listed above that the auto-fix cannot decide for you — the server URL, a header, a long description — still needs your edit.

Reading the example

The example looks like a normal OpenAPI file and would pass a generic validator, but the GPT builder would reject or cripple five parts of it. The GET has no operationId, so it is skipped. Its response is an array with no items, and the POST body is an object with no properties — both refused. /todos/{id} never declares id. And the X-Workspace header will never be sent, because GPT actions do not support custom headers. The auto-fix supplies getTodos, the empty items and properties; the path parameter and the header need decisions only you can make.

OpenAPI spec validator for ChatGPT actions

A general-purpose validator checks the OpenAPI specification. An OpenAPI spec validator for ChatGPT actions has to check what the GPT builder adds on top: an operationId everywhere, explicit object properties and array items, the 300 and 700 character limits, a single HTTPS host on port 443, one authentication type, and OAuth URLs on the API’s own domain. Each problem is reported with the builder’s own wording where it has one, so you can match it to the error you saw.

Fixing GPT action OpenAPI schema errors

Most GPT action OpenAPI schema error messages come from schemas generated by a framework or copied from API docs, which leave operationIds out and describe open objects loosely. Run the schema through here, copy the auto-fixed version back into the action editor, then fix the remaining items by hand. When you add an operation that changes data, decide whether ChatGPT should always ask first: set x-openai-isConsequential: true for payments and deletions, or false to allow “Always allow” on harmless writes.

Frequently asked questions

Why does ChatGPT say "Could not find a valid URL in servers" when importing my action?
The builder needs a servers entry with an absolute HTTPS URL — servers: [{ url: "https://api.example.com" }]. It fails when servers is missing, when the URL is relative ("/v1"), when it still contains a server variable such as {region}, or when it points to http://, a port other than 443, or localhost, none of which ChatGPT’s servers can reach. Put the literal public base URL of your API there.
What OpenAPI versions do Custom GPT actions support?
OpenAPI 3.0 and 3.1, in JSON or YAML; OpenAI’s own examples use 3.1.0. Swagger 2.0 files are not accepted and need converting to OpenAPI 3 first. Within 3.x, the builder is stricter than the specification in a few places: every operation needs an operationId, object schemas need properties and arrays need items.
Why is an operationId required for every path in a Custom GPT action schema?
ChatGPT turns each operation into a function it can call, and the operationId becomes that function’s name. An operation without one is dropped with the message "method get is missing operationId; skipping", so the GPT silently cannot use it. Use letters, digits, underscores and hyphens, keep it under 64 characters and make each one unique; the auto-fix above generates names such as getTodos from the method and path.
How do I fix "object schema missing properties"?
The builder rejects a schema that says type: object without listing properties — typical of generic "any object" responses and request bodies. List the fields the API actually returns or accepts under properties. The auto-fix adds an empty properties map as a starting point, but fill it in: the GPT only knows about fields you describe. The same applies to arrays, which need items.
What are the length limits in a GPT action schema?
OpenAI documents 300 characters for each operation’s description and summary, and 700 characters for each parameter’s description. Requests and responses must each be under 100,000 characters, and a call times out after 45 seconds. Custom request headers are not supported — send tenant IDs and similar values as query or body parameters, and put credentials in the action’s authentication settings.
Is my schema uploaded anywhere?
No. The validator runs entirely as a script inside this page, including the YAML parser; your schema never leaves your browser, and there is no upload, no API call and no analytics here. That is enforced rather than promised: this site’s test suite scans the shipped HTML for every browser API capable of sending data off the page and fails the build if it finds one.