7SIGNAL · Authentication Profile

7Signalsolutions Authentication

Authentication

7SIGNAL secures its APIs with oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials and authorization_code flow(s).

Wireless Network MonitoringWi-Fi Experience MonitoringDigital Experience MonitoringNetwork Performance MonitoringNetwork ObservabilityAIOpsIT OperationsEndpoint MonitoringTime SeriesMCPAgent-NativeCompany
Methods: oauth2 Schemes: 2 OAuth flows: clientCredentials, authorization_code API key in:

Security Schemes

oauth2 oauth2
· flows: clientCredentials
mcp_oauth oauth2
· flows: authorization_code

Source

Authentication Profile

Raw ↑
generated: '2026-09-05'
method: searched
source: https://github.com/7Signal/API-Examples/blob/develop/docs/01-authentication.md
docs: https://github.com/7Signal/API-Examples/blob/develop/docs/01-authentication.md
summary:
  types:
  - oauth2
  oauth2_flows:
  - clientCredentials
  - authorization_code
  surfaces: 2
  note: >-
    Two distinct OAuth 2.0 surfaces. The REST gateway (api-v2.7signal.com) uses the client-credentials
    grant with a 7SIGNAL "API Key" and "API Secret" as client_id / client_secret. The remote MCP server
    (mcp-v2.7signal.com) uses an authorization-code + PKCE flow with dynamic client registration,
    advertised via RFC 8414 / RFC 9728 discovery documents.
schemes:
- name: oauth2
  type: oauth2
  surface: 7SIGNAL Platform API (Gateway v2)
  flows:
  - flow: clientCredentials
    tokenUrl: https://api-v2.7signal.com/oauth2/token
    scopes: 1
    scope_names:
    - read
  credential_terms:
    client_id: API Key
    client_secret: API Secret
    note: >-
      7SIGNAL's docs state plainly: "our API Key and Secret are just Client ID and Secret. We are using
      the same concept with simpler naming terms." Keys are created in the platform dashboard at
      https://start.7signal.com under Users -> API Keys, scoped to an Organization, Role and Sapphire Group.
  token:
    format: JWT bearer
    lifetime_seconds: 86400
    lifetime_human: 24 hours
    fixed: true
    refreshable: false
    response_fields:
    - access_token
    - scope
    - expires_in
    - token_type
    reuse_guidance: >-
      "Tokens are only valid for 24 hours. This amount of time is fixed and cannot be changed. Once you
      acquire a token, reuse it for the duration of its validity." Do not request a new token per call.
  request_header: 'Authorization: Bearer <access_token>'
  failure_modes:
  - status: 401
    meaning: token missing, expired or invalid
  - status: 403
    meaning: token valid but lacks the required permission
  - error: invalid_grant
    meaning: grant_type missing or not client_credentials
  sources:
  - https://github.com/7Signal/API-Examples/blob/develop/docs/01-authentication.md
  - https://github.com/7Signal/API-Examples/blob/develop/docs/04-api-keys.md
  - openapi/7signalsolutions-openapi.json
- name: mcp_oauth
  type: oauth2
  surface: 7SIGNAL MCP Server
  flows:
  - flow: authorization_code
    authorizationUrl: https://mcp-v2.7signal.com/authorize
    tokenUrl: https://mcp-v2.7signal.com/token
    registrationUrl: https://mcp-v2.7signal.com/register
    pkce: S256
    scopes: 9
  grant_types_supported:
  - authorization_code
  - refresh_token
  token_endpoint_auth_methods_supported:
  - client_secret_post
  bearer_methods_supported:
  - header
  discovery:
  - path: /.well-known/oauth-authorization-server
    rfc: RFC 8414
    status: 200
    file: well-known/7signalsolutions-mcp-oauth-authorization-server.json
  - path: /.well-known/oauth-protected-resource
    rfc: RFC 9728
    status: 200
    file: well-known/7signalsolutions-mcp-oauth-protected-resource.json
  sources:
  - https://mcp-v2.7signal.com/.well-known/oauth-authorization-server
  - https://mcp-v2.7signal.com/.well-known/oauth-protected-resource
api_key_management:
  create_path: https://start.7signal.com -> Users -> API Keys -> Add
  scoped_by:
  - Organization
  - Role
  - Sapphire Group
  api_operations:
  - apikeys-get-e5f6
  - apikeys-post-g7h8
  - apikeys-with-id-get-i9j0
  - apikeys-with-id-delete-k1l2
  source: https://github.com/7Signal/API-Examples/blob/develop/README.md

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/7signalsolutions-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.