Aedifion · Authentication Profile

Aedifion Authentication

Authentication

Aedifion secures its APIs with http, oauth2, and openIdConnect across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit, authorizationCode, password, and clientCredentials flow(s).

Building AutomationSmart BuildingsEnergy ManagementIoTReal EstateHVACSustainabilityTime SeriesAnalyticsMQTTBuilding OperationsESGPropTechGermanyReal-Time
Methods: http, oauth2, openIdConnect Schemes: 4 OAuth flows: implicit, authorizationCode, password, clientCredentials API key in:

Security Schemes

basicAuth http
scheme: basic
openIDConnect oauth2
· flows: implicit, authorizationCode, password, clientCredentials
mqtt-credentials other
kafka-sasl other

Source

Authentication Profile

Raw ↑
generated: '2026-09-09'
method: searched
source: openapi/aedifion-openapi.yml
docs: https://docs.aedifion.io/en/developers/http-api/guides-and-tutorials/authentication/
discovery: well-known/aedifion-openid-configuration.json
summary:
  types: [http, oauth2, openIdConnect]
  http_schemes: [basic]
  oauth2_flows: [implicit, authorizationCode, password, clientCredentials]
  pkce: [S256, plain]
  mtls_client_auth: true
  preferred: openIDConnect
schemes:
- name: basicAuth
  type: http
  scheme: basic
  status: legacy
  header: 'Authorization: Basic base64(email:password)'
  rfc: RFC 7617
  note: >-
    The docs state "The aedifion HTTP API supports Basic Auth for legacy reasons until
    further notice. HTTP Basic Auth may be deprecated in future." Credentials are the user's
    platform email and password, sent on every request, so it must only be used over HTTPS.
  sources: [openapi/aedifion-openapi.yml]
- name: openIDConnect
  type: oauth2
  subtype: openIdConnect
  issuer: https://auth.aedifion.io/realms/aedifion
  provider: Keycloak
  header: 'Authorization: Bearer <access_token>'
  endpoints:
    authorization: https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/auth
    token: https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/token
    introspection: https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/token/introspect
    jwks_uri: https://auth.aedifion.io/realms/aedifion/protocol/openid-connect/certs
  flows:
  - flow: implicit
    declared_in: openapi
  - flow: authorizationCode
    declared_in: oidc-discovery
  - flow: password
    declared_in: docs
    note: Keycloak Direct Access Grant - grant_type=password with client_id, username, password.
  - flow: clientCredentials
    declared_in: oidc-discovery
  token_endpoint_auth_methods:
  - private_key_jwt
  - client_secret_basic
  - client_secret_post
  - tls_client_auth
  - client_secret_jwt
  sources: [openapi/aedifion-openapi.yml, well-known/aedifion-openid-configuration.json]
- name: mqtt-credentials
  type: other
  transport: mqtt
  note: >-
    The MQTT broker at mqtt.aedifion.io authenticates with username/password in the MQTT
    CONNECT packet over TLS. Limited-validity credentials are minted through the HTTP API's
    MQTT user-management endpoints; unlimited-validity credentials are issued only on
    request by aedifion staff. Authorization is per-topic read/write.
  docs: https://docs.aedifion.io/en/developers/http-api/guides-and-tutorials/mqtt-user-management/
- name: kafka-sasl
  type: other
  transport: kafka
  mechanism: SASL/SCRAM-SHA-512 over SSL
  note: Kafka consumers authenticate with SASL_SCRAM_SHA512 and security_protocol SSL.
  docs: https://docs.aedifion.io/en/developers/kafka/
sso:
  supported: true
  protocols: [OpenID Connect, OAuth 2.0, SAML, LDAP, Active Directory]
  docs: https://docs.aedifion.io/en/admins/sso/

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aedifion-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.