Open Food Facts Authentication API

Endpoints for user authentication and session management.

Operations 3

POST /cgi/session.pl Login Session #
POST /auth Authentication #
POST /auth_by_cookie Authentication By Cookie #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/open-food-facts-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

open-food-facts-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Open Food Facts Authentication API
  version: '1.0'
  description: 'Operations tagged Authentication across 2 of this provider''s published API definitions: open-food-facts-api-v2-openapi.yml, open-food-facts-folksonomy-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- description: dev
  url: https://world.openfoodfacts.net
- description: prod
  url: https://world.openfoodfacts.org
- description: proxy (for doc purpose)
  url: http://localhost:8080
- url: https://api.folksonomy.openfoodfacts.org
  description: Production server
- url: http://localhost:8000
  description: Local development server
tags:
- name: Authentication
  description: Endpoints for user authentication and session management.
paths:
  /cgi/session.pl:
    post:
      summary: Login Session
      operationId: get-cgi-session.pl
      description: Retrieve session cookie for writing operations.
      tags:
      - Authentication
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                user_id:
                  type: string
                  description: 'Username for login


                    Note: you must always use the username (and not the email)

                    as it is far less brittle.

                    '
                password:
                  type: string
                  description: Password for login
                  format: password
              required:
              - user_id
              - password
      responses:
        '200':
          description: Successful login
          headers:
            Set-Cookie:
              schema:
                type: string
                description: Session cookie for subsequent authenticated requests
              examples:
                sessionCookie:
                  value: session=user123&testuser&user_session&abcdef1234567890; domain=.example.net; path=/; SameSite=Lax
        '401':
          description: Authentication failed
      security:
      - userAgentAuth: []
    servers:
    - description: dev
      url: https://world.openfoodfacts.net
    - description: prod
      url: https://world.openfoodfacts.org
    - description: proxy (for doc purpose)
      url: http://localhost:8080
  /auth:
    post:
      tags:
      - Authentication
      summary: Authentication
      description: 'Authentication: provide user/password and get a bearer token in return


        - **username**: Open Food Facts user_id (not email)

        - **password**: user password (clear text, but HTTPS encrypted)


        token is returned, to be used in later requests with usual "Authorization: bearer token" headers'
      operationId: authentication_auth_post
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Body_authentication_auth_post'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
    servers:
    - url: https://api.folksonomy.openfoodfacts.org
      description: Production server
    - url: http://localhost:8000
      description: Local development server
  /auth_by_cookie:
    post:
      tags:
      - Authentication
      summary: Authentication By Cookie
      description: 'Authentication: provide Open Food Facts session cookie and get a bearer token in return


        - **session cookie**: Open Food Facts session cookie


        token is returned, to be used in later requests with usual "Authorization: bearer token" headers'
      operationId: authentication_by_cookie_auth_by_cookie_post
      parameters:
      - name: session
        in: cookie
        required: false
        schema:
          anyOf:
          - type: string
          - type: 'null'
          title: Session
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
    servers:
    - url: https://api.folksonomy.openfoodfacts.org
      description: Production server
    - url: http://localhost:8000
      description: Local development server
components:
  schemas:
    TokenResponse:
      properties:
        access_token:
          type: string
          title: Access Token
        token_type:
          type: string
          title: Token Type
      type: object
      required:
      - access_token
      - token_type
      title: TokenResponse
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
            - type: string
            - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
      - loc
      - msg
      - type
      title: ValidationError
    Body_authentication_auth_post:
      properties:
        grant_type:
          anyOf:
          - type: string
            pattern: ^password$
          - type: 'null'
          title: Grant Type
        username:
          type: string
          title: Username
        password:
          type: string
          title: Password
        scope:
          type: string
          title: Scope
          default: ''
        client_id:
          anyOf:
          - type: string
          - type: 'null'
          title: Client Id
        client_secret:
          anyOf:
          - type: string
          - type: 'null'
          title: Client Secret
      type: object
      required:
      - username
      - password
      title: Body_authentication_auth_post
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
  securitySchemes:
    cookieAuth:
      type: apiKey
      in: cookie
      name: session
      description: 'Session cookie containing user ID, username, and session token.

        The value is structured as: user_id&username&user_session&session_token

        e.g. "user_id&exampleuser&user_session&abcdefghijklmnopqrstuvwxyz123456789ABCDEFGHIJKLM".

        The session token is obtained after successful login via the `/cgi/session.pl` endpoint.

        '
    userAgentAuth:
      description: Identification using the User-Agent header. This is recommended in all requests so that we can contact you if there are issues. If we cannot identify the source of problematic API queries, we may have to block them. User-Agent header in the format 'app_name/app_version (URL or contact info)'
      type: apiKey
      in: header
      name: User-Agent
    OAuth2PasswordBearer:
      type: oauth2
      flows:
        password:
          scopes: {}
          tokenUrl: auth
externalDocs:
  description: '**IMPORTANT**: Please read the API introduction before using this API.

    '
  url: https://openfoodfacts.github.io/openfoodfacts-server/api/
x-refined-from:
- open-food-facts-api-v2-openapi.yml
- open-food-facts-folksonomy-openapi.json