AdvicePay · Authentication Profile

Advicepay Authentication

Authentication

AdvicePay secures its APIs with oauth2, apiKey, and saml2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).

Financial ServicesPaymentsBillingInvoicingFinancial PlanningWealth ManagementSubscriptionE-SignatureComplianceFintech
Methods: oauth2, apiKey, saml2 Schemes: 3 OAuth flows: authorizationCode, clientCredentials API key in: cookie

Security Schemes

OAuth2 oauth2
· flows: authorizationCode, clientCredentials
SessionCookie apiKey
· in: cookie ()
SAML2 SSO saml2

Source

Authentication Profile

advicepay-authentication.yml Raw ↑
generated: '2026-09-09'
method: searched
source: https://docs.advicepay.com/#authentication
docs: https://docs.advicepay.com/#authentication
note: >-
  Derived by reading the published AdvicePay API documentation, not from a machine-readable
  OpenAPI document — AdvicePay publishes no OpenAPI/Swagger file (see x-contract-discovery in
  apis.yml). Every scheme, endpoint, lifetime and claim below is stated verbatim in the docs.
summary:
  types:
  - oauth2
  - apiKey
  - saml2
  api_key_in:
  - cookie
  oauth2_flows:
  - authorizationCode
  - clientCredentials
  client_authentication_methods:
  - client_secret_post
  - client_secret_jwt
  - private_key_jwt
schemes:
- name: OAuth2
  type: oauth2
  description: >-
    OAuth 2.0 is the mechanism for all public API access. Access tokens are presented in the
    Authorization header as "Bearer <token>".
  bearer_header: 'Authorization: Bearer <access_token>'
  flows:
  - flow: authorizationCode
    description: >-
      For user-level integrations where AdvicePay users sit in different accounts. OAuth clients
      for firms with developer access are created in the developer console; partner clients are
      provisioned on request (company name, website URL, logo and redirect URI required).
    authorizationUrl: https://app.advicepay.com/oauth2/authorize
    tokenUrl: https://app.advicepay.com/oauth2/access_token
    refreshUrl: https://app.advicepay.com/oauth2/access_token
    authorization_code_ttl_seconds: 600
    state_parameter: supported (optional, CSRF protection)
  - flow: clientCredentials
    description: >-
      For enterprise account-owner accounts acting on behalf of an integrating system. Enabled
      per OAuth client with the "Enable OAuth 2.0 Client Credentials Flow" toggle.
    tokenUrl: https://app.advicepay.com/oauth2/access_token
- name: SessionCookie
  type: apiKey
  in: cookie
  parameter_name: session
  description: Session-based authentication using a secure HTTP-only cookie (browser sessions).
- name: SAML2 SSO
  type: saml2
  description: >-
    SAML 2.0 single sign-on. POST /auth/sso consumes a SAMLResponse plus RelayState and creates a
    session, keyed by a `source` company slug that selects the certificate to validate against.
    The integrator's public certificate must be installed on an AdvicePay server first
    (enterprise@advicepay.com). GET /auth/sso supports deep linking into the application.
  endpoints:
  - POST /auth/sso
  - GET /auth/sso
token_lifetimes:
  access_token_seconds: 300
  access_token_note: Access tokens expire after 5 minutes (both flows).
  refresh_token_days: 30
  refresh_token_rotation: >-
    Refresh tokens are single-use. A new refresh token is issued every time one is consumed and
    the previous one is invalidated, so the integrator must persist the new token after every
    refresh call.
  authorization_code_seconds: 600
client_authentication_methods:
- id: client_secret_post
  description: >-
    Client secret sent in the request body as `client_secret`. The docs describe this as the
    least secure of the three methods.
  security_posture: lowest
- id: client_secret_jwt
  description: >-
    A JWT signed with the client secret using HS256, sent as `client_assertion` with
    client_assertion_type urn:ietf:params:oauth:client-assertion-type:jwt-bearer. The secret
    never leaves the integrator's server.
  algorithm: HS256
  security_posture: better
- id: private_key_jwt
  description: >-
    A JWT signed with the integrator's private key using RS256; the public key is uploaded in the
    developer dashboard and AdvicePay verifies each request against it. The docs describe this as
    the most secure method.
  algorithm: RS256
  security_posture: highest
jwt_client_assertion:
  client_assertion_type: urn:ietf:params:oauth:client-assertion-type:jwt-bearer
  standard: RFC 7523 (JWT profile for OAuth 2.0 client authentication)
  claims:
  - claim: aud
    required: true
    description: The URL of the resource being authenticated to, generally https://app.advicepay.com/oauth2/access_token
  - claim: exp
    required: true
    description: Expiration time; requests received after exp are rejected. Short lifetimes recommended.
  - claim: iat
    required: true
    description: Issued-at time; requests received before iat are rejected.
  - claim: iss
    required: true
    description: Issuer — always the client ID.
  - claim: sub
    required: true
    description: Subject — always the client ID.
  - claim: jti
    required: false
    description: >-
      Token identifier. When present AdvicePay prevents the same jti being replayed, mitigating
      replay attacks. The docs highly recommend it.
scopes:
  supported:
  - all
  note: The docs state that only the scope value "all" is currently supported.
developer_console: >-
  OAuth clients, the client-credentials toggle, the client authentication method and the
  private-key JWT public key are all managed in the AdvicePay developer console, available to
  firms with developer access (an Enterprise-plan capability). Partner/integration clients are
  provisioned on request via enterprise@advicepay.com.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/advicepay-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.