Alcohol and Tobacco Tax and Trade Bureau · Authentication Profile

Alcohol And Tobacco Tax And Trade Bureau Authentication

Authentication

Alcohol and Tobacco Tax and Trade Bureau secures its APIs with none and session-login across 2 declared security schemes, as derived from its OpenAPI definitions.

AlcoholTobaccoFederal-GovernmentExcise TaxRegulationsTreasury
Methods: none, session-login Schemes: 2 OAuth flows: API key in:

Security Schemes

anonymous-public-data none
ttb-online-session-login session
scheme: form-login

Source

Authentication Profile

alcohol-and-tobacco-tax-and-trade-bureau-authentication.yml Raw ↑
generated: '2026-09-01'
method: searched
source: https://www.ttb.gov/data
docs: https://www.ttb.gov/regulated-commodities/labeling/cola-public-registry
note: >-
  Derived by search, not from a spec — TTB publishes no OpenAPI, so there are no
  securitySchemes to aggregate. The auth model is nonetheless well-defined and worth recording:
  TTB's machine-readable open data is entirely anonymous and issues no credentials of any kind,
  while its two transactional web applications are session-login only with no programmatic
  access path.
summary:
  types: [none, session-login]
  api_key_in: []
  oauth2_flows: []
  api_keys_issued: false
  registration_required_for_data: false
schemes:
  - name: anonymous-public-data
    type: none
    applies_to:
      - TTB Open Data files (XML / CSV / JSON)
      - TTB Public COLA Registry read access
    evidence: >-
      https://www.ttb.gov/images/foia/cola_stats.xml and
      https://www.ttb.gov/images/foia/form_stats.csv both return HTTP 200 with no
      Authorization header, no cookie and no API key (probed 2026-09-01). The COLA Public
      Registry page states no registration or password is required to use it.
    sources: [https://www.ttb.gov/regulated-commodities/labeling/cola-public-registry]
  - name: ttb-online-session-login
    type: session
    scheme: form-login
    applies_to:
      - Permits Online (PONL)
      - COLAs Online (filing)
      - Formulas Online (FONL)
    login_url: https://www.ttbonline.gov/permitsonline/
    evidence: >-
      TTB Online applications require a registered TTB.gov user account and are entered through
      a form login at https://www.ttbonline.gov/permitsonline/. No token, key or OAuth endpoint
      is documented; /.well-known/oauth-authorization-server and
      /.well-known/openid-configuration are not served on www.ttb.gov (404 each).
    programmatic_access: false
    sources: [https://www.ttb.gov/online-services/ponl/permits-online-help]
absent:
  - api_key
  - bearer_token
  - oauth2
  - openid_connect
  - mutual_tls
  - hmac_signing

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/alcohol-and-tobacco-tax-and-trade-bureau-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.