AirMDR · Authentication Profile

Airmdr Authentication

Authentication

AirMDR secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.

SecurityManaged Detection and ResponseSecurity OperationsAlert TriageIncident ResponseAI AgentsSOC AutomationThreat DetectionMCPA2A
Methods: apiKey Schemes: 2 OAuth flows: API key in: cookie

Security Schemes

SessionCookie apiKey
· in: cookie (Session)
WebhookURLSecret url-path-secret
· in: path ({webhook_id}/{secret})

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/airmdr-case-manager-openapi.yml, openapi/airmdr-user-management-service-openapi.yml
docs: https://docs.airmdr.com/api-reference/apitoken
summary:
  types:
  - apiKey
  api_key_in:
  - cookie
  oauth2: false
  oidc: false
schemes:
- name: SessionCookie
  type: apiKey
  in: cookie
  parameter: Session
  usage: 'curl --location https://app.airmdr.com/airmdrapi/organization --header ''Cookie: Session="<API Token Here>"'''
  token_lifecycle:
    issued_by: Admin dashboard → API Tokens → Create API Token (Admin or Super Admin role required); also createAPITokenForUserAPI (POST /users/tokens) and createAPITokenForSlackWorkflowAPI
    shown_once: true
    listing: listTokensForUserAPI (GET /users/tokens)
    revocation: delete the token in the dashboard or deleteTokenAPI (DELETE /users/tokens/{token_id})
    expiry: tokens can expire; docs advise handling 401 Unauthorized by checking for token expiration and prefer "scoped and expiring tokens" (no scope vocabulary is published)
  sources:
  - openapi/airmdr-case-manager-openapi.yml
  - openapi/airmdr-user-management-service-openapi.yml
- name: WebhookURLSecret
  type: url-path-secret
  in: path
  parameter: '{webhook_id}/{secret}'
  operation: createAlertFromWebhookAPI (POST /webhooks/{webhook_id}/{secret}/alerts)
  usage: authenticated purely by webhook_id + secret embedded in the URL path; 404 on unknown id or invalid secret
  sources:
  - openapi/airmdr-case-manager-openapi.yml
  note: not a securityScheme in the spec; documented in the operation description and the M28.1 release notes
context_headers:
  required: [User-ID, Organization-ID]
  optional: [X-Request-ID, Execution-ID, Organization-Hosturl]
  note: the docs say these are "automatically preloaded" into request examples when a token is generated
console_sso:
  providers: [Azure AD, Google, Okta]
  docs: https://docs.airmdr.com/essentials/SSO-Overview
  note: console user sign-in only; not an API authentication surface

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/airmdr-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.