Amplify · Authentication Profile
Amplify Authentication
Authentication
Amplify secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
CompanyInsuranceInsurtechLife InsuranceFinancial-ServicesFintechEmbedded FinanceAnnuities
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
BearerIdToken http
scheme: bearer
· in: header (Authorization)
Source
Authentication Profile
generated: '2026-07-20'
method: probed
source: live HTTP probes of https://api.getamplifylife.com/ (2026-07-20)
docs: null
summary:
types:
- http
api_key_in: []
oauth2_flows: []
note: >-
Amplify publishes no authentication documentation. The profile below is derived
entirely from observed responses of the live, gated production API host. It is
an observation of behaviour, not a provider claim.
schemes:
- name: BearerIdToken
type: http
scheme: bearer
bearerFormat: JWT
in: header
parameter: Authorization
sources:
- probe:https://api.getamplifylife.com/
description: >-
Sending "Authorization: Bearer <token>" changes the failure mode from the
generic gate to token validation, and the returned stack trace shows the token
being handed to google-auth-library's OAuth2Client.verifyIdTokenAsync /
verifySignedJwtWithCertsAsync inside a User.Auth handler. The API therefore
authenticates callers with Google-issued OpenID Connect ID tokens (Google
Sign-In), verified server-side against Google's public certificates.
evidence:
- request: 'GET / with header "Authorization: Bearer test"'
status: 401
body_error: 'Wrong number of segments in token: test'
stack_frames:
- _OAuth2Client.verifySignedJwtWithCertsAsync
- _OAuth2Client.verifyIdTokenAsync
- User.Auth
gate:
description: >-
Requests carrying no Authorization header are rejected by an application-level
gate before any token validation runs. The gate is not satisfied by any of the
common API-key header names probed (x-api-key, apikey, authorizationkey,
authorization-key), which all produced the same unauthenticated response.
status: 401
body: '{"error":"authorization key is not provided"}'
headers_probed_without_effect:
- x-api-key
- apikey
- authorizationkey
- authorization-key
infrastructure:
edge: Amazon CloudFront
gateway: AWS API Gateway (HTTP API, $default stage, /{proxy+} catch-all route)
region: us-west-1
runtime: Node.js Lambda built with SST (apps/legacy/src/sst.mjs)
evidence:
- apigw-requestid + x-amzn-trace-id response headers
- via/x-amz-cf-id CloudFront response headers
- echoed requestContext.domainName aruc25yw2d.execute-api.us-west-1.amazonaws.com
access: private
onboarding: >-
No public sign-up, key issuance or documentation surface was found. Access appears
to be granted only under a carrier or partner agreement; the Carrier Solutions page
describes the motion as "Embed your products inside trusted partner ecosystems via
API".
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/amplify-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.