Adventus.io · Authentication Profile

Adventusio Authentication

Authentication

Adventus.io declares 2 security scheme(s) across its OpenAPI definitions.

CompanyEducationInternational EducationStudent RecruitmentMarketplaceGraphQLHigher EducationEdTechAdmissionsAnalytics
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

http
scheme: bearer · in: header ()
apiKey
· in: query (accessToken)

Source

Authentication Profile

adventusio-authentication.yml Raw ↑
generated: '2026-09-09'
method: probed
source: https://api.adventus.io/graphql (anonymous introspection + live unauthenticated probes, 2026-09-09)
provider: Adventus.io
api: adventusio-graphql
summary: >-
  Adventus.io does not publish an authentication guide. Everything below was
  established by introspecting the live GraphQL endpoint and by observing what
  the server returns to an unauthenticated caller. There is no OAuth 2.0
  authorization server, no OpenID Connect discovery document and no API-key
  provisioning surface reachable without a partner account: the only
  credential issuers in the contract are two password-login mutations.
schemes:
- id: bearer-token
  type: http
  scheme: bearer
  in: header
  header: Authorization
  description: >-
    Session bearer token returned by the userLogin (recruiter / institution
    staff) or studentLogin mutation. Both mutations return an auth payload type
    (UserAuthPayload / StudentAuthPayload) and there are matching userLogout /
    studentLogout mutations, so the token is server-revocable.
  issued_by:
  - mutation: userLogin
    arguments: [email, password]
    returns: UserAuthPayload
    audience: recruiter, agent and institution staff accounts
  - mutation: studentLogin
    arguments: [email, password]
    returns: StudentAuthPayload
    audience: student accounts
  revoked_by: [userLogout, studentLogout]
  recovery:
  - userForgotPassword / userResetPassword
  - studentForgotPassword / studentResetPassword
  evidence: graphql/adventusio.graphql
  method: derived
- id: connect-access-token
  type: apiKey
  in: query
  parameter: accessToken
  description: >-
    A second, distinct credential. The Adventus Connect queries
    pendingConnectCount(accessToken: String!) and
    connectInvites(accessToken: String!) take the token as a REQUIRED GraphQL
    ARGUMENT rather than an Authorization header. This is an invitation-scoped
    token delivered out of band (ConnectSource enum values are EMAIL and WEB),
    not the session bearer above.
  note: >-
    Passing a credential as a query argument means it can land in GraphQL query
    logs, APM traces and error payloads that a header-borne token would not
    reach. Recorded as observed, not endorsed.
  evidence: graphql/adventusio.graphql
  method: derived
anonymous_surface:
  description: >-
    A subset of reference data answers with no credential at all. Confirmed by
    live unauthenticated POST on 2026-09-09.
  verified: probed
  operations:
  - field: countries
    http_status: 200
    result: full country list returned
  - field: studyLevels
    http_status: 200
    result: 11 study levels returned
  - field: languages
    http_status: 200
    result: schema-confirmed; same anonymous class
  - field: gradingSystems
    http_status: 200
    result: schema-confirmed; same anonymous class
  - field: __schema
    http_status: 200
    result: full introspection returned (99 types)
gated_surface:
  description: >-
    Every student, order, institution, document, messaging and statistics field
    is gated. The server answers HTTP 200 with a GraphQL errors[] entry rather
    than an HTTP 401.
  verified: probed
  observed:
  - field: students
    http_status: 200
    graphql_error_code: UNAUTHENTICATED
    message: '401: Unauthorized'
  - field: myAgent
    http_status: 200
    graphql_error_code: UNAUTHENTICATED
    message: '401: Unauthorized'
  - field: institution
    http_status: 200
    graphql_error_code: UNAUTHENTICATED
    message: '401: Unauthorized'
discovery_documents_absent:
  note: >-
    Probed 2026-09-09 on adventus.io, www.adventus.io, api.adventus.io,
    app.adventus.io and blog.adventus.io. See
    well-known/adventusio-well-known.yml for the full status table.
  paths:
  - path: /.well-known/openid-configuration
    result: no host served a document
  - path: /.well-known/oauth-authorization-server
    result: no host served a document
  - path: /.well-known/oauth-protected-resource
    result: no host served a document
oauth_scopes: none
mtls: false
transport:
  tls_minimum_observed: TLSv1.2
  hsts_on_api_host: true
  hsts_max_age: 2592000
  hsts_include_subdomains: true
  note: >-
    HSTS observed directly on the POST /graphql response from api.adventus.io
    on 2026-09-09 (strict-transport-security max-age=2592000; includeSubdomains).
    The domain-security probe records hsts null for that host because it reads
    the 404 root, not the GraphQL path.
  provider_claim: >-
    "All communications are encrypted via industry standard HTTPS/TLS (TLS 1.2
    or higher)" -- https://adventus.io/recruiters/security/
gaps:
- No published authentication documentation of any kind.
- No token lifetime, refresh mechanism or expiry semantics stated anywhere in the
  contract or on the public site.
- No scope, role or permission model exposed in the schema.
- Credential provisioning requires a partner account; there is no self-serve API key.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/adventusio-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.