1up · Authentication Profile

1Up Authentication

Authentication

1up secures its APIs with oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyArtificial IntelligenceSales EnablementKnowledge ManagementRFP AutomationSecurity QuestionnairesMCPAgentsSoftware-as-a-ServiceRevenue Operations
Methods: oauth2 Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

1up MCP OAuth 2.1 oauth2
· flows: authorizationCode
1up platform API token http
scheme: bearer

Source

Authentication Profile

1up-authentication.yml Raw ↑
generated: '2026-09-05'
method: probed
source: >-
  https://mcp.1up.ai/.well-known/oauth-authorization-server ;
  https://mcp.1up.ai/.well-known/oauth-protected-resource ;
  https://help.1up.ai/en/articles/14304740-mcp
docs: https://help.1up.ai/en/articles/14304740-mcp
note: >-
  Derived from probed RFC 8414 / RFC 9728 discovery documents and observed 401 responses,
  not from an OpenAPI — 1up publishes no OpenAPI. Two distinct auth surfaces exist and they
  are not the same thing: the public MCP server (OAuth 2.1) and the platform REST host
  api.1upapi.com (undocumented, token-authenticated, Django REST Framework).
summary:
  types: [oauth2]
  api_key_in: []
  oauth2_flows: [authorizationCode]
  bearer_methods: [header]
  pkce: [S256]
  dynamic_client_registration: true
  identity_provider: Auth0 (1up-app.us.auth0.com)
  human_sso: >-
    Single Sign-On is a paid platform feature from the Starter tier upward
    (https://help.1up.ai/en/articles/13401537-enabling-single-sign-on-sso).
schemes:
- name: 1up MCP OAuth 2.1
  type: oauth2
  applies_to: https://mcp.1up.ai/mcp
  sources: [well-known/1up-oauth-authorization-server.json, well-known/1up-oauth-protected-resource.json]
  issuer: https://mcp.1up.ai
  flows:
  - flow: authorizationCode
    authorizationUrl: https://mcp.1up.ai/authorize
    tokenUrl: https://mcp.1up.ai/token
    registrationUrl: https://mcp.1up.ai/register
    code_challenge_methods_supported: [S256]
    grant_types_supported: [authorization_code, refresh_token]
    response_types_supported: [code]
    token_endpoint_auth_methods_supported: [none]
    scopes: [openid, profile, email, offline_access]
  public_client_id: TAWQL8mbs0eHLzaBaxV3Va5vH6qal4Wq
  public_client_id_note: >-
    Published by the provider in both the discovery document and the copy-paste Claude Code
    config in their own docs. It is a public OAuth client identifier, not a secret.
  protected_resource:
    resource: https://mcp.1up.ai/mcp
    authorization_servers: [https://mcp.1up.ai]
    bearer_methods_supported: [header]
    resource_name: 1up MCP Server
  challenge_observed:
    url: https://mcp.1up.ai/mcp
    http_status: 401
    www_authenticate: Bearer
    body: '{"error":"unauthorized","error_description":"Missing Authorization header"}'
- name: 1up platform API token
  type: http
  scheme: bearer
  applies_to: https://api.1upapi.com/api/v1/
  documented: false
  sources: [pypi:1up-mcp==0.1.0 (oneup_mcp/api_client.py, oneup_mcp/config.py)]
  note: >-
    Not part of a public developer program. The base URL and Authorization-header behaviour
    are recorded here only because 1up's own published PyPI package names them; there is no
    public reference, no published spec and no self-service key issuance. The host answers
    an anonymous GET /api/v1/ with HTTP 401 and the Django REST Framework body
    {"detail":"Authentication credentials were not provided."}. Tokens are Auth0-issued
    (audience https://1up-app.us.auth0.com/api/v2/) and obtained via `1up-mcp auth login`.
  challenge_observed:
    url: https://api.1upapi.com/api/v1/
    http_status: 401
    body: '{"detail":"Authentication credentials were not provided."}'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/1up-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.