Advisr · Authentication Profile

Advisr Authentication

Authentication

Authentication profile for the Advisr REST API, read from the public API reference. Advisr uses a single company-scoped API token supplied in a custom `token` request header. There is no OAuth 2.0, OpenID Connect, mTLS or HTTP Basic surface, and no self-service key issuance — tokens are provisioned by an Advisr support representative for the customer company.

Advisr declares 1 security scheme(s) across its OpenAPI definitions.

CompanyAdvertisingMediaSalesSales EnablementMedia PlanningProposalsAdvertising SalesCampaignsCRM
Methods: Schemes: 1 OAuth flows: API key in:

Security Schemes

token apiKey
· in: header ()

Source

Authentication Profile

advisr-authentication.yml Raw ↑
generated: '2026-09-09'
method: searched
source: https://apidocs.advisr.com/#authentication
description: >-
  Authentication profile for the Advisr REST API, read from the public API
  reference. Advisr uses a single company-scoped API token supplied in a custom
  `token` request header. There is no OAuth 2.0, OpenID Connect, mTLS or HTTP
  Basic surface, and no self-service key issuance — tokens are provisioned by an
  Advisr support representative for the customer company.
base_url: https://api.advisr.com/v1
schemes:
  - id: company_token
    type: apiKey
    in: header
    name: token
    description: >-
      Company access token. Sent verbatim as the `token` header on every
      request — there is no `Bearer` or other scheme prefix.
    example_shape: 'token: api-token'
    applies_to: All Advisr API endpoints.
    docs: https://apidocs.advisr.com/#authentication
scope_model:
  type: none
  detail: >-
    The token is scoped to a company; the API publishes no OAuth scopes,
    permissions matrix or per-endpoint grant list. A 403 AdvisrPermissionError
    is documented for a token that lacks the necessary permissions, so
    server-side permissioning exists but is not documented as an addressable
    scope surface.
issuance:
  self_service: false
  how: >-
    "In order to retrieve your Company's access token please contact your
    Support representative." Access to the API itself is also gated —
    "Please reach out to your account manager to inquire about access."
  docs: https://apidocs.advisr.com/#introduction
rotation:
  documented: false
  note: No key rotation, expiry or revocation procedure is published.
transport:
  tls_required: true
  note: All documented examples use https://api.advisr.com.
failure_modes:
  - status: 401
    type: AdvisrUnauthorizedError
    meaning: Invalid or no API key provided for this request.
  - status: 403
    type: AdvisrPermissionError
    meaning: The API key used for this request does not have the necessary permissions.
gaps:
  - No OAuth 2.0 / OpenID Connect surface, so no delegated or per-user authorization.
  - No documented token rotation, expiry, or revocation.
  - Token issuance is a human support request, not an API or console flow.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/advisr-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.