Alloovium · Authentication Profile

Alloovium Authentication

Authentication

Alloovium secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyConstructionDocument IntelligenceComplianceArtificial IntelligenceConstruction TechnologyDocumentsMCP
Methods: apiKey, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header (Authorization)
OAuth2 oauth2
· flows: authorizationCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-17'
method: searched
source: https://www.alloovium.com/en/developers/authentication
docs: https://www.alloovium.com/en/developers/authentication
summary:
  types: [apiKey, oauth2]
  api_key_in: [header]
  oauth2_flows: [authorizationCode]
schemes:
- name: ApiKeyAuth
  type: apiKey
  in: header
  parameter: Authorization
  format: 'Authorization: Bearer <key>'
  key_prefixes: [ak_live_, ak_test_]
  key_length: 60
  notes: >-
    Keys are rejected in query strings, cookies, or JSON bodies — header only. Test and live keys are
    created in the Developer Console.
- name: OAuth2
  type: oauth2
  version: OAuth 2.1
  flows:
  - flow: authorizationCode
    pkce: required (S256)
    authorizationUrl: https://api.alloovium.com/api/v2/oauth/authorize
    tokenUrl: https://api.alloovium.com/api/v2/oauth/token
    registrationUrl: https://api.alloovium.com/api/v2/oauth/register
    revocationUrl: https://api.alloovium.com/api/v2/oauth/revoke
  dynamic_client_registration: true
  dcr_note: >-
    Clients self-register without pre-provisioning; dynamically registered clients are always issued
    read-only scopes.
  note: OAuth tokens are not accepted on the MCP transport (API key only there).