ADRO · Authentication Profile
Adro1B33 Authentication
Authentication
ADRO declares 0 security scheme(s) across its OpenAPI definitions.
AerodynamicsComputational Fluid DynamicsSimulationAutomotiveEngineeringOptimizationManufacturingArtificial IntelligenceHigh Performance ComputingEcommerceMCPSouth Korea
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-09-07'
method: derived
source: >-
openapi/adro1b33-aox-openapi.yaml (no components.securitySchemes are declared, so the model below is
derived from the account operations and their request/response schemas) plus live anonymous probes of
api.aoxlabs.com recorded under evidence[], and well-known/adro1b33-openid-configuration.json for the
separate storefront identity surface.
apis:
- api: AOX Platform API
host: https://api.aoxlabs.com
declared_security_schemes: []
gap: >-
THE SPEC DECLARES NO securitySchemes AND NO GLOBAL security BLOCK. drf-spectacular emitted the
document without an authentication configuration, so a consumer reading the contract alone cannot
tell how to authenticate. 212 of 231 operations carry no security field at all and 19 carry
`security: [{}]`, which marks them explicitly public. The real behaviour has to be probed.
observed_model:
style: session
mechanism: >-
Credential exchange at POST /accounts/login/ (email + password) and POST /accounts/social-login/,
with POST /accounts/token/refresh/ for renewal and POST /accounts/logout/ to end the session. The
LoginResponse schema carries no token field (only detail, teamId, teamName, userType,
mustChangePassword), which is consistent with a browser-oriented httpOnly cookie session rather
than a bearer token handed to the client.
bearer_token_documented: false
api_key_documented: false
confidence: medium
note: >-
No published developer documentation describes machine-to-machine authentication for this API.
This is the honest limit of what can be established anonymously; the exact credential material
cannot be confirmed without an account.
multi_tenancy:
model: team
mechanism: >-
Every substantive resource is scoped to a team. POST /accounts/team-switch/ changes the active
team for the session, GET /accounts/teams/ lists memberships, and Project, Job, CreditWallet,
Subscription and Payment all carry teamId. POST /tenants/exists/ is a public tenant-existence
check.
public_operations:
count: 19
operations:
- accounts_login_create
- accounts_logout_create
- accounts_signup_create
- accounts_social_login_create
- accounts_social_register_create
- accounts_token_refresh_create
- accounts_password_reset_create
- accounts_password_reset_confirm_create
- board_retrieve
- board_retrieve_2
- book_demo_create
- credits_bundles_list
- credits_bundles_retrieve
- health_retrieve
- plans_list
- plans_retrieve
- tenants_exists_create
- verifier_email_verifier_create
- verifier_email_verifier_confirm_create
password_policy_surface:
- PUT /accounts/me/password-change/
- POST /accounts/me/password-verify/
- POST /accounts/me/force-password-change/
- POST /accounts/password-reset/
- POST /accounts/password-reset-confirm/
evidence:
- url: https://api.aoxlabs.com/
status: 401
body: '{"detail":"자격 인증 데이터가 제공되지 않았습니다."}'
note: Django REST Framework "Authentication credentials were not provided" (Korean locale).
- url: https://api.aoxlabs.com/announcements/
status: 401
- url: https://api.aoxlabs.com/board/
status: 200
note: >-
Confirms the spec's `security: [{}]` marking — this operation really is anonymous.
- url: https://api.aoxlabs.com/health/
status: 200
body: '{"status":"ok"}'
- url: https://api.aoxlabs.com/schema/
status: 200
note: The OpenAPI document itself is served anonymously.
- api: ADRO US Store Agent Commerce (UCP / MCP)
host: https://adro.com
observed_model:
style: oidc
mechanism: >-
Shopify Customer Accounts. adro.com serves OpenID Connect and OAuth 2.0 authorization-server
metadata on its own domain, issued for ADRO's shop (issuer
https://shopify.com/authentication/67310649500). Authorization code with PKCE (S256), refresh
tokens and the JWT bearer grant; RS256 id tokens; bearer methods: header.
confidence: high
anonymous_surface: >-
The UCP MCP endpoint at POST /api/ucp/mcp answers tools/list with no credential at all. Catalog
browsing, cart and checkout creation are anonymous; only payment completion requires buyer consent.
scopes: scopes/adro1b33-scopes.yml
evidence:
- url: https://adro.com/.well-known/openid-configuration
status: 200
- url: https://adro.com/.well-known/oauth-protected-resource
status: 200
- url: https://shopify.com/authentication/67310649500/.well-known/jwks.json
status: 200
- url: https://adro.com/api/ucp/mcp
status: 200
note: POST tools/list, no Authorization header sent.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/adro1b33-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.