Schema validation narrows what an API interprets
The smaller the set of inputs you accept, the smaller the set of behaviours anybody can provoke.
Unexpected fields, wrong types, extra nesting and oversized values all become rejections rather than code paths. It also prevents mass assignment by construction, because anything not in the schema never reaches the object.
