ARGUS · Authentication Profile

Argus Authentication

Authentication

Authentication profile for the ARGUS platform (Altus Group). No public ARGUS API reference or OpenAPI is published, so nothing here is derived from a contract — every entry below was read off a live, anonymous discovery document or the platform's own front-end configuration. Two distinct identity surfaces exist, and they are not the same system.

ARGUS declares 2 security scheme(s) across its OpenAPI definitions.

Altus GroupAsset ManagementCommercial Real EstateFund ManagementPortfolio ManagementReal Estate SoftwareValuation
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

ARGUS Intelligence Platform — Microsoft Entra ID (OIDC) openIdConnect
ARGUS Support Community — Salesforce Experience Cloud (OIDC) openIdConnect

Source

Authentication Profile

argus-authentication.yml Raw ↑
specification: API Commons Authentication
specificationVersion: '0.1'
generated: '2026-09-14'
method: probed
source: >-
  https://service.altusgroup.com/.well-known/openid-configuration (HTTP 200),
  https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/v2.0/.well-known/openid-configuration
  (HTTP 200), and https://platform.altusintelligence.com/config.js (HTTP 200), which names
  the Entra tenant, client id and scope the ARGUS Intelligence Platform front-end requests.
provider: ARGUS
providerId: argus
description: >-
  Authentication profile for the ARGUS platform (Altus Group). No public ARGUS API
  reference or OpenAPI is published, so nothing here is derived from a contract — every
  entry below was read off a live, anonymous discovery document or the platform's own
  front-end configuration. Two distinct identity surfaces exist, and they are not the same
  system.
schemes:
  - id: argus-intelligence-entra-oidc
    name: ARGUS Intelligence Platform — Microsoft Entra ID (OIDC)
    type: openIdConnect
    flow: authorization_code
    pkce: S256
    openIdConnectUrl: >-
      https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/v2.0/.well-known/openid-configuration
    issuer: https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/v2.0
    authorization_endpoint: >-
      https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/oauth2/v2.0/authorize
    token_endpoint: >-
      https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/oauth2/v2.0/token
    jwks_uri: >-
      https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/discovery/v2.0/keys
    tenant_region_scope: EU
    token_format: JWT
    id_token_signing_alg: RS256
    subject_type: pairwise
    scopes_supported:
      - openid
      - profile
      - email
      - offline_access
    resource_scope: api://4e11f0c5-761c-4021-a96f-82e2df6c73a9/.default
    applies_to:
      - ARGUS Intelligence Platform
      - ARGUS ValueInsight
    note: >-
      Single-tenant Entra ID application. The platform front-end acquires a token for the
      resource scope above and presents it to the service prefixes listed under
      gated_surfaces. Anonymous callers receive HTTP 403 "Missing Authentication Token"
      from the fronting AWS API Gateway.
  - id: argus-support-community-oidc
    name: ARGUS Support Community — Salesforce Experience Cloud (OIDC)
    type: openIdConnect
    flow: authorization_code
    pkce: S256
    openIdConnectUrl: https://service.altusgroup.com/.well-known/openid-configuration
    issuer: https://service.altusgroup.com
    authorization_endpoint: https://service.altusgroup.com/services/oauth2/authorize
    token_endpoint: https://service.altusgroup.com/services/oauth2/token
    introspection_endpoint: https://service.altusgroup.com/services/oauth2/introspect
    revocation_endpoint: https://service.altusgroup.com/services/oauth2/revoke
    userinfo_endpoint: https://service.altusgroup.com/services/oauth2/userinfo
    jwks_uri: https://service.altusgroup.com/id/keys
    registration_endpoint: https://service.altusgroup.com/services/oauth2/register
    id_token_signing_alg: RS256
    dpop_supported: true
    token_endpoint_auth_methods:
      - client_secret_post
      - client_secret_basic
      - private_key_jwt
    grant_types:
      - authorization_code
      - refresh_token
    applies_to:
      - ARGUS support community and knowledge base
    note: >-
      This is the stock Salesforce Experience Cloud identity provider running under an
      Altus Group host. Its advertised scopes are the Salesforce platform set (api, web,
      chatter_api, pardot_api, cdp_*, einstein_gpt_api, mcp_api and so on), not ARGUS
      product scopes — it authenticates support-community users, not ARGUS API consumers.
      Recorded because it is the only OIDC discovery document the ARGUS estate serves from
      its own domain; see scopes/ for why no ARGUS scope catalog is published.
gated_surfaces:
  - name: ARGUS Intelligence Platform core service
    base: https://platform.altusintelligence.com/core-service-v1
    anonymous_status: 403
    anonymous_body: '{"message":"Missing Authentication Token"}'
  - name: ARGUS Intelligence Platform backend
    base: https://platform.altusintelligence.com/backend-v1
    anonymous_status: 403
  - name: ARGUS Intelligence Platform stewardship / file upload
    base: https://platform.altusintelligence.com/stewardship-v1
    anonymous_status: 403
  - name: ARGUS Intelligence Platform master data service
    base: https://platform.altusintelligence.com/mdmapisvc-v1
    anonymous_status: 403
  - name: ARGUS Intelligence Platform derived domains
    base: https://platform.altusintelligence.com/derived_domains-v1
    anonymous_status: 403
  - name: ARGUS Intelligence Platform stress testing
    base: https://platform.altusintelligence.com/stress-testing-v1
    anonymous_status: 403
    note: >-
      These are the versioned service prefixes the ARGUS Intelligence Platform front-end
      calls, read from the provider's own config.js. They back the application UI; Altus
      Group does not publish a reference or a spec for them. Every /swagger/v1/swagger.json
      and /openapi.json probe under them returned 403.
argus_api:
  name: ARGUS API
  documented_auth: not published
  note: >-
    Altus Group markets an "ARGUS API" integration gateway for cloud-enabled ARGUS
    solutions, but publishes no public authentication reference, no base URL, and no spec.
    The product page that described it (/argus/products/integration-solutions and
    /solutions/argus-integrations/) now 301s to https://www.altusgroup.com/argus/, and the
    integration-solutions download page 301s to the general downloads index. Access is
    obtained through a customer account and the support community. Nothing is asserted here
    about its scheme because nothing is published.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/argus-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.