Abatable · Authentication Profile

Abatable Authentication

Authentication

Abatable secures its APIs with oauth2 and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, refreshToken, deviceCode, implicit, password, tokenExchange, and jwtBearer flow(s).

Carbon MarketsCarbon CreditsCarbon OffsetsEnvironmental AssetsVoluntary Carbon MarketCORSIAClimateSustainabilityNet ZeroProcurementMarket IntelligenceDue DiligenceESGMCP
Methods: oauth2, openIdConnect Schemes: 2 OAuth flows: authorizationCode, clientCredentials, refreshToken, deviceCode, implicit, password, tokenExchange, jwtBearer API key in:

Security Schemes

Auth0 OIDC (end-user application sign-in) openIdConnect
Cloudflare Access OAuth (MCP endpoint) oauth2
· flows: authorizationCode

Source

Authentication Profile

abatable-authentication.yml Raw ↑
generated: '2026-09-05'
method: probed
source: >-
  https://login.abatable.com/.well-known/openid-configuration and
  https://mcp.abatable.com/.well-known/oauth-protected-resource — fetched 2026-09-05.
  No OpenAPI exists in this repo, so nothing here is derived from a spec; every field below was
  read out of a discovery document the provider serves.
docs: null
docs_note: >-
  Abatable publishes no authentication documentation. There is no developer portal and no API
  reference; /developers on abatable.com is a marketing page for carbon PROJECT developers, not
  software developers. The auth model below is what the two live discovery surfaces disclose.
summary:
  types: [oauth2, openIdConnect]
  api_key_in: []
  oauth2_flows: [authorizationCode, clientCredentials, refreshToken, deviceCode, implicit, password, tokenExchange, jwtBearer]
  human_auth: OIDC via an Auth0 tenant on the custom domain login.abatable.com
  machine_auth: OAuth 2.0 via Cloudflare Access for the MCP endpoint
  two_independent_issuers: true
  note: >-
    The application and the MCP endpoint do NOT share an identity provider. app.abatable.com
    authenticates end users against Auth0 (issuer https://login.abatable.com/); mcp.abatable.com is
    gated by Cloudflare Access (issuer https://abatable.cloudflareaccess.com). An agent holding an
    application session token cannot call the MCP server with it.
schemes:
- name: Auth0 OIDC (end-user application sign-in)
  type: openIdConnect
  openIdConnectUrl: https://login.abatable.com/.well-known/openid-configuration
  issuer: https://login.abatable.com/
  authorization_endpoint: https://login.abatable.com/authorize
  token_endpoint: https://login.abatable.com/oauth/token
  userinfo_endpoint: https://login.abatable.com/userinfo
  jwks_uri: https://login.abatable.com/.well-known/jwks.json
  device_authorization_endpoint: https://login.abatable.com/oauth/device/code
  revocation_endpoint: https://login.abatable.com/oauth/revoke
  registration_endpoint: https://login.abatable.com/oidc/register
  code_challenge_methods_supported: [S256, plain]
  token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt, none]
  id_token_signing_alg_values_supported: [HS256, RS256, PS256]
  dpop_signing_alg_values_supported: [ES256]
  observed_client_id_in_login_redirect: 4tYWXA9Pn1WFdKGAtSoKT9fsVwyupxMn
  observed_redirect_uri: https://app.abatable.com/api/auth/callback
  observed_connection: Username-Password-Authentication
  sources: [well-known/abatable-login-openid-configuration.json]
- name: Cloudflare Access OAuth (MCP endpoint)
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/authorization
    tokenUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/token
    refreshUrl: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/token
    scopes: {}
  issuer: https://abatable.cloudflareaccess.com
  registration_endpoint: https://abatable.cloudflareaccess.com/cdn-cgi/access/oauth/registration
  dynamic_client_registration: true
  code_challenge_methods_supported: [S256]
  protected_resource: https://mcp.abatable.com
  challenge_observed: 'HTTP 401 WWW-Authenticate: Bearer realm="OAuth", error="invalid_token", resource_metadata=...'
  rfc9728: true
  alternative_client: >-
    The Cloudflare Access protected-resource document also advertises `cloudflared access curl`
    as an interactive authentication method for CLI callers.
  sources:
  - well-known/abatable-mcp-oauth-authorization-server.json
  - well-known/abatable-mcp-oauth-protected-resource.json
api_keys:
  supported: unknown
  note: No API key programme is documented or discoverable on any public Abatable surface.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/abatable-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.