APIM sets OpenApi spec api required parameters to template parameters

Casper Hansen 25 Reputation points
2025-09-18T10:46:23.2933333+00:00

Hello! It seems that when importing an open api spec into api management (we do this through iac) the api sets any required parameters to template parameters and not query parameters which means it automatically responds with a 404 when a call has missing parameters. This is not the behavior we want as missing parameters is a "bad request" and should return a 400 to match out consumers' expectations. How do you all handle this? The api spec is also autogenerated from out application meaning that parameters have to be marked as "requred" in the backend to ensure correct functionality there.

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

Answer accepted by question author
Alex Burlachenko 25,290 Reputation points MVP Volunteer Moderator
2025-09-18T10:57:52.9766667+00:00

hi Casper,

you are absolutely right. a missing required parameter should be a 400 bad request, not a 404 not found. the 404 makes it look like the api endpoint itself doesn't exist, which is just wrong and confuses everyone.

the root cause is how apim handles the openapi import. it sees a required parameter and, for its own internal routing, makes it a template parameter. this happens deep in the import process.

here is how u can fix it. u need to override the operation policy for that specific api. u can use a policy to validate the query parameters manually and return the correct 400 error.

go to your apim instance in the azure portal, select your api, and then choose the operation that has the required query parameters. in the 'inbound processing' section, u can add an xml policy.

add a policy snippet like this to check for the existence of the parameter.

<choose> <when condition="@(context.Request.Url.Query.GetValueOrDefault("yourRequiredParam", "") == "")"> <return-response> <set-status code="400" reason="Bad Request" /> <set-body>{"error": "Missing required query parameter: 'yourRequiredParam'"}</set-body> </return-response> </when> </choose>

u will have to do this for each required parameter. it is a bit of manual work, but it gives u complete control over the error response.

if u have many apis, u can also look into using a base policy or writing a script to automate adding these policy checks during your iac deployment.

hope this gets your error responses back on track. that 404 behavior is truly misleading for api consumers.

Best regards,

Alex

and "yes" if you would follow me at Q&A - personaly thx.
P.S. If my answer help to you, please Accept my answer

https://ctrlaltdel.blog/

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.