AdvicePay · Authentication Profile
Advicepay Authentication
Authentication
AdvicePay secures its APIs with oauth2, apiKey, and saml2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).
Financial ServicesPaymentsBillingInvoicingFinancial PlanningWealth ManagementSubscriptionE-SignatureComplianceFintech
Methods: oauth2, apiKey, saml2
Schemes: 3
OAuth flows: authorizationCode, clientCredentials
API key in: cookie
Security Schemes
OAuth2 oauth2
· flows: authorizationCode, clientCredentials
SessionCookie apiKey
· in: cookie ()
SAML2 SSO saml2
Source
Authentication Profile
generated: '2026-09-09'
method: searched
source: https://docs.advicepay.com/#authentication
docs: https://docs.advicepay.com/#authentication
note: >-
Derived by reading the published AdvicePay API documentation, not from a machine-readable
OpenAPI document — AdvicePay publishes no OpenAPI/Swagger file (see x-contract-discovery in
apis.yml). Every scheme, endpoint, lifetime and claim below is stated verbatim in the docs.
summary:
types:
- oauth2
- apiKey
- saml2
api_key_in:
- cookie
oauth2_flows:
- authorizationCode
- clientCredentials
client_authentication_methods:
- client_secret_post
- client_secret_jwt
- private_key_jwt
schemes:
- name: OAuth2
type: oauth2
description: >-
OAuth 2.0 is the mechanism for all public API access. Access tokens are presented in the
Authorization header as "Bearer <token>".
bearer_header: 'Authorization: Bearer <access_token>'
flows:
- flow: authorizationCode
description: >-
For user-level integrations where AdvicePay users sit in different accounts. OAuth clients
for firms with developer access are created in the developer console; partner clients are
provisioned on request (company name, website URL, logo and redirect URI required).
authorizationUrl: https://app.advicepay.com/oauth2/authorize
tokenUrl: https://app.advicepay.com/oauth2/access_token
refreshUrl: https://app.advicepay.com/oauth2/access_token
authorization_code_ttl_seconds: 600
state_parameter: supported (optional, CSRF protection)
- flow: clientCredentials
description: >-
For enterprise account-owner accounts acting on behalf of an integrating system. Enabled
per OAuth client with the "Enable OAuth 2.0 Client Credentials Flow" toggle.
tokenUrl: https://app.advicepay.com/oauth2/access_token
- name: SessionCookie
type: apiKey
in: cookie
parameter_name: session
description: Session-based authentication using a secure HTTP-only cookie (browser sessions).
- name: SAML2 SSO
type: saml2
description: >-
SAML 2.0 single sign-on. POST /auth/sso consumes a SAMLResponse plus RelayState and creates a
session, keyed by a `source` company slug that selects the certificate to validate against.
The integrator's public certificate must be installed on an AdvicePay server first
(enterprise@advicepay.com). GET /auth/sso supports deep linking into the application.
endpoints:
- POST /auth/sso
- GET /auth/sso
token_lifetimes:
access_token_seconds: 300
access_token_note: Access tokens expire after 5 minutes (both flows).
refresh_token_days: 30
refresh_token_rotation: >-
Refresh tokens are single-use. A new refresh token is issued every time one is consumed and
the previous one is invalidated, so the integrator must persist the new token after every
refresh call.
authorization_code_seconds: 600
client_authentication_methods:
- id: client_secret_post
description: >-
Client secret sent in the request body as `client_secret`. The docs describe this as the
least secure of the three methods.
security_posture: lowest
- id: client_secret_jwt
description: >-
A JWT signed with the client secret using HS256, sent as `client_assertion` with
client_assertion_type urn:ietf:params:oauth:client-assertion-type:jwt-bearer. The secret
never leaves the integrator's server.
algorithm: HS256
security_posture: better
- id: private_key_jwt
description: >-
A JWT signed with the integrator's private key using RS256; the public key is uploaded in the
developer dashboard and AdvicePay verifies each request against it. The docs describe this as
the most secure method.
algorithm: RS256
security_posture: highest
jwt_client_assertion:
client_assertion_type: urn:ietf:params:oauth:client-assertion-type:jwt-bearer
standard: RFC 7523 (JWT profile for OAuth 2.0 client authentication)
claims:
- claim: aud
required: true
description: The URL of the resource being authenticated to, generally https://app.advicepay.com/oauth2/access_token
- claim: exp
required: true
description: Expiration time; requests received after exp are rejected. Short lifetimes recommended.
- claim: iat
required: true
description: Issued-at time; requests received before iat are rejected.
- claim: iss
required: true
description: Issuer — always the client ID.
- claim: sub
required: true
description: Subject — always the client ID.
- claim: jti
required: false
description: >-
Token identifier. When present AdvicePay prevents the same jti being replayed, mitigating
replay attacks. The docs highly recommend it.
scopes:
supported:
- all
note: The docs state that only the scope value "all" is currently supported.
developer_console: >-
OAuth clients, the client-credentials toggle, the client authentication method and the
private-key JWT public key are all managed in the AdvicePay developer console, available to
firms with developer access (an Enterprise-plan capability). Partner/integration clients are
provisioned on request via enterprise@advicepay.com.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/advicepay-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.