128 Technology · Authentication Profile
128 Technology Authentication
Authentication
128 Technology secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
CompanyNetworkingSD-WANRoutingNetwork ManagementSession Smart NetworkingNETCONFYANGTelecommunicationsInfrastructure
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
bearerAuth http
scheme: bearer
· in: header (Authorization)
Source
Authentication Profile
generated: '2026-09-05'
method: searched
source: https://docs.128technology.com/docs/intro_rest_graphql_apis
docs: https://docs.128technology.com/docs/intro_rest_graphql_apis
note: >-
Derived from the provider's own published API documentation, not from an OpenAPI document.
128 Technology publishes no OpenAPI: the SSR serves an interactive Swagger reference from the
deployed instance itself (https://<SSR address>/documentation/swagger), reachable only from a
customer's own router or conductor, so no securityScheme block could be harvested.
summary:
types:
- http
api_key_in: []
oauth2_flows: []
model: bearer-jwt-from-password-login
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: JWT
in: header
parameter: Authorization
description: >-
Every REST and GraphQL call carries an Authorization header of the form
"Bearer <token>". The token is an RS256-signed JWT issued by the SSR itself and carries the
caller's name, roles, scopes and capabilities as claims.
sources:
- https://docs.128technology.com/docs/intro_rest_graphql_apis
token_issuance:
operation: POST /api/v1/login
content_type: application/json
request_fields:
- username
- password
response_field: token
token_type: JWT (RS256)
docs: https://docs.128technology.com/docs/intro_rest_graphql_apis
note: >-
Credentials are the SSR local user account. There is no OAuth authorization server, no
client_id/client_secret exchange, and no refresh-token flow documented.
authorization:
model: RBAC
docs: https://docs.128technology.com/docs/config_RBAC
description: >-
Access Management Roles carry capabilities and are bound to Resource Groups, which are in
turn assigned to Authority-level resources (routers, tenants, services, service-policies).
The RBAC privileges of the authenticated user determine which resources an API call can
reach; a role may additionally exclude named resources, which are then hidden from that
user's view entirely.
capabilities:
- name: config-read
description: Read the configuration tree.
- name: config-write
description: Modify and commit configuration.
- name: provisioning
description: >-
Software lifecycle management — download software, upgrade existing installations.
built_in_roles:
- name: admin
description: Default administrator role; has access to all configuration options and cannot be removed.
jwt_claims_observed:
- name
- roles
- scopes
- capabilities
- application
- userAgent
- iss
- iat
jwt_claim_note: >-
Claim names read from the example decoded token published in the REST/GraphQL API
documentation; scopes observed there were "configure" and "show-commands", capabilities
"config-read", "config-write" and "provisioning". No published scope reference page exists,
so scopes/ was not written.
other_interfaces:
- interface: NETCONF
auth: SSH transport (password or public-key), per RFC 6242
note: The SSR also exposes its YANG data model over NETCONF alongside REST and GraphQL.
- interface: SSH / PCLI
auth: Local username+password or public-key authentication using keys in the local filesystem
source: https://docs.128technology.com/docs/cc_fips_intro
transport_note: >-
The documented curl examples pass -k (skip TLS verification) because a factory SSR presents a
self-signed webserver certificate; the SSR supports replacing it with a CA-signed certificate
(see https://docs.128technology.com/docs/config_webserver_certs).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/128-technology-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.