Aeris · Authentication Profile

Aeris Authentication

Authentication

Aeris secures its APIs with apiKey, http, and oauth2 across 5 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials and password flow(s).

IoTCellular ConnectivityM2MeSIMSIM ManagementTelecommunicationsDevice ManagementIoT SecurityConnectivity Management PlatformSMS MessagingeUICCFleet TelematicsMachine-to-Machine
Methods: apiKey, http, oauth2 Schemes: 5 OAuth flows: clientCredentials, password API key in: header

Security Schemes

Oauth2_auth oauth2
· flows: password
BearerAuth http
scheme: bearer
OAuth2 oauth2
· flows: clientCredentials
token apiKey
· in: header (X-Access-Token)
BasicAuth http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-09-10'
method: searched
source: openapi/aeris-business-analytics-report-api-openapi.yaml, openapi/aeris-business-automation-api-openapi.yaml,
  openapi/aeris-consumer-connectivity-openapi.yaml, openapi/aeris-eco-operations-api-openapi.yaml, openapi/aeris-eim-info-api-openapi.yaml,
  openapi/aeris-enterprise-management-api-openapi.yaml, openapi/aeris-euicc-setup-api-openapi.yaml, openapi/aeris-incidents-external-api-openapi.yaml,
  openapi/aeris-mds-esb-device-localization-openapi.yaml, openapi/aeris-mds-esb-subscription-management-openapi.yaml,
  openapi/aeris-operator-order-management-api-openapi.yaml, openapi/aeris-organization-signaling-aggregations-api-openapi.yaml
  ... — upgraded from the Aeris IoT Developer Portal API Quick start guide, which publishes the authentication mechanism
  used by each API group.
summary:
  types:
  - apiKey
  - http
  - oauth2
  api_key_in:
  - header
  oauth2_flows:
  - clientCredentials
  - password
schemes:
- name: Oauth2_auth
  type: oauth2
  flows:
  - flow: password
    tokenUrl: /iot/api/auth/token
    scopes: 17
  sources:
  - openapi/aeris-business-analytics-report-api-openapi.yaml
  - openapi/aeris-business-automation-api-openapi.yaml
  - openapi/aeris-consumer-connectivity-openapi.yaml
  - openapi/aeris-enterprise-management-api-openapi.yaml
  - openapi/aeris-incidents-external-api-openapi.yaml
  - openapi/aeris-operator-order-management-api-openapi.yaml
  - openapi/aeris-organization-signaling-aggregations-api-openapi.yaml
  - openapi/aeris-resource-inventory-api-openapi.yaml
  - openapi/aeris-shared-bundle-api-openapi.yaml
  - openapi/aeris-sim-specification-management-api-openapi.yaml
  - openapi/aeris-subscription-change-history-openapi.yaml
  - openapi/aeris-subscription-custom-fields-api-openapi.yaml
  - openapi/aeris-subscription-device-api-openapi.yaml
  - openapi/aeris-subscription-device-reconnect-api-openapi.yaml
  - openapi/aeris-subscription-inventory-common-api-openapi.yaml
  - openapi/aeris-subscription-location-api-openapi.yaml
  - openapi/aeris-subscription-number-management-api-openapi.yaml
  - openapi/aeris-subscription-search-api-openapi.yaml
  - openapi/aeris-subscription-signalling-events-api-openapi.yaml
  - openapi/aeris-subscription-signalling-usages-api-openapi.yaml
- name: BearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  sources:
  - openapi/aeris-business-automation-api-openapi.yaml
- name: OAuth2
  type: oauth2
  flows:
  - flow: clientCredentials
    tokenUrl: https://iot-api.aeris.com/iot/api/auth/token
    scopes: 4
  description: The resources in the API are protected using the OAuth 2.0 protocol
  sources:
  - openapi/aeris-eco-operations-api-openapi.yaml
  - openapi/aeris-eim-info-api-openapi.yaml
  - openapi/aeris-euicc-setup-api-openapi.yaml
  - openapi/aeris-watchtower-api-openapi-openapi.yaml
- name: token
  type: apiKey
  in: header
  parameter: X-Access-Token
  description: Input token directly or use login endpoints
  sources:
  - openapi/aeris-mds-esb-device-localization-openapi.yaml
  - openapi/aeris-mds-esb-subscription-management-openapi.yaml
- name: BasicAuth
  type: http
  scheme: basic
  sources:
  - openapi/aeris-sms-messaging-api-openapi.yaml
docs:
- https://iotdeveloper.aeris.net/hc/en-us/articles/25348523998748-API-Quick-start-guide
- https://iotdeveloper.aeris.net/hc/en-us/articles/25348574275868-JWT-Authentication-Best-Practices
- https://iotdeveloper.aeris.net/hc/en-us/articles/25348572926236-Auth-API-1-0-1
docs_findings:
  token_endpoints:
    bearer: POST /iot/api/auth and POST /iot/api/auth/token
    x_access_token: POST /login (per API group)
    marketplace_hub: POST /auth/login
  by_api_group:
    Service Portal (SOAP): wss-security UsernameToken
    User Administration: X-access-token via POST /login
    Consumer Connectivity: X-access-token via POST /login
    Subscription Management: X-access-token via POST /login
    Device Localization: X-access-token via POST /login
    Shared bundle: Bearer via POST /token
    Enterprise Management (CSP only): Bearer via POST /token
    eUICC Setup (CSP and Advanced Resellers only): Bearer via POST /token
    Device Reconnect: Bearer via POST /token
    Subscription Change History: Bearer via POST /token
    Subscription management - additional functions: Bearer via POST /token
    Search Subscription Details: Bearer via POST /token
    Ticketing service for incident management: Bearer via POST /token
    SMS messaging: HTTP Basic Auth
    Enterprise Provisioning for Marketplace HUB (CSP only): Bearer via POST /auth/login
    Custom fields: Bearer via POST /token
    Subscription location: Bearer via POST /token
    Subscription signaling usages: Bearer via POST /token
    Subscription signaling events: Bearer via POST /token
    'Devices: eUICC inventory view': Bearer via POST /token
    AerAdmin / AerFrame / AerTraffic (Aeris-native): apiKey query parameter
  jwt_claims:
  - sub
  - iss
  - aud
  - azp
  - upn
  - email
  - first_name
  - last_name
  - groups
  - organization_ids
  - enterprise_group_ids
  - billing_organization_id
  - exp
  - iat
  - jti
  token_reuse_guidance: Aeris documents reading the exp claim and reusing the token rather than re-authenticating
    per request; /iot/api/auth is rate limited to 5 req/s and 60 req/min.
  onboarding: Credentials are issued by the Connectivity Service Provider on subscription; there is no self-serve
    API key.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aeris-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.