AAA AI · Authentication Profile

Aaaai Me Authentication

Authentication

AAA AI secures its APIs with apiKey and cookie across 4 declared security schemes, as derived from its OpenAPI definitions.

Artificial IntelligenceAgentsMulti-AgentLLM OrchestrationMeetingsVoiceVideoWorkflowsMCPAgentic CommerceOpenAI-CompatibleSelf-HostedAgent-NativeMontenegro
Methods: apiKey, cookie Schemes: 4 OAuth flows: API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (X-User-Login)
session cookie cookie
· in: cookie (session)
X-Agent-Token apiKey
· in: header (X-Agent-Token)
OAuth 2.0 / OpenID Connect (advertised) oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/aaaai-me-openapi.json
docs: https://aaaai.me/auth.md
summary:
  types:
  - apiKey
  - cookie
  api_key_in:
  - header
  oauth2_flows: []
  note: >-
    The contract declares ONE scheme, ApiKeyAuth (apiKey, header X-User-Login), and applies it to no
    operation, so the derived profile is thin; the rest is from https://aaaai.me/auth.md, the live 401
    text, response headers observed 2026-09-19 and the OAuth/OIDC discovery documents on aaaai.me.
    OAuth is advertised in metadata only (scopes/aaaai-me-scopes.yml): the issuer host web.aaaai.me
    serves no discovery document and no JWKS, so oauth2 is not listed as a working type here.
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: X-User-Login
  sources:
  - openapi/aaaai-me-openapi.json
  evidence: >-
    GET https://web.aaaai.me/api/status without credentials -> 401 {"message":"Authentication required.
    Please login or provide X-User-Login header.","status":"error"}; no WWW-Authenticate header.
  how_to_obtain: 'auth.md: "Programmatic clients should use API keys configured in the product (Settings -> API keys)". Key format is not published.'
- name: session cookie
  type: cookie
  in: cookie
  parameter: session
  sources:
  - https://aaaai.me/auth.md
  evidence: >-
    GET https://web.aaaai.me/ sets "session=...; Expires=+30 days; HttpOnly; Path=/; SameSite=Lax".
    auth.md: "After authentication, the platform issues a session cookie for browser clients."
  obtained_via:
  - 'POST /api/auth/login {login, password} (bare POST -> 400 "Login and password required")'
  - 'POST /api/auth/apple {identity_token, authorization_code, email} (Sign in with Apple)'
  - 'Google sign-in on https://web.aaaai.me/ (auth.md; no API route in the contract)'
  revoked_via: POST /api/auth/logout (also named revocation_endpoint in the OAuth metadata)
- name: X-Agent-Token
  type: apiKey
  in: header
  parameter: X-Agent-Token
  sources:
  - 'openapi/aaaai-me-openapi.json#POST /api/approvals (summary: "Create approval (agent when destructive + no TTY). Header: X-Agent-Token.")'
  evidence: Named only in that operation's summary; not declared as a parameter or securityDefinition. Identifies a paired device agent (see GET /api/nodes). Format and issuance not published.
- name: OAuth 2.0 / OpenID Connect (advertised)
  type: oauth2
  status: advertised-not-verified
  sources:
  - well-known/aaaai-me-oauth-authorization-server.json
  - well-known/aaaai-me-openid-configuration.json
  - well-known/aaaai-me-oauth-protected-resource.json
  issuer: https://web.aaaai.me
  authorizationUrl: https://web.aaaai.me/
  tokenUrl: https://web.aaaai.me/api/auth/login
  scopes: [openid, profile, email, api, offline_access]
  evidence: >-
    Metadata is served from aaaai.me (200) but the issuer host returns 404 for
    /.well-known/oauth-authorization-server, /.well-known/openid-configuration and the declared
    jwks_uri; the token endpoint is the password-login route. Recorded for completeness; see
    scopes/ and conformance/ for the RFC 8414 / OIDC Discovery / RFC 9728 verdicts.
account_security:
  two_factor: 'docs.html s9 Security: "Enable two-factor authentication (2FA) ... Scan a QR code with your authenticator app and save backup codes. View connected devices and active sessions."'
anonymous_routes_observed:
- GET /api/health
- GET /api/billing/crypto/config
- GET /api/billing/yookassa/config
- GET /api/mcp/marketplace
subscription_gate:
  status: 403
  field: subscribe_url
  source: https://aaaai.me/.well-known/agent-payments.json#access_gate

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aaaai-me-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.