Atera · Authentication Profile

Atera Authentication

Authentication

Atera secures its APIs with apiKey across 1 declared security scheme, as derived from its OpenAPI definitions.

IT ManagementRMMPSAHelp DeskTicketingPatch ManagementRemote MonitoringEndpoint ManagementMSPNetwork DiscoveryAlertsDevicesBillingWebhookArtificial Intelligence
Methods: apiKey Schemes: 1 OAuth flows: API key in: header

Security Schemes

X-API-KEY apiKey
· in: header ()

Source

Authentication Profile

atera-authentication.yml Raw ↑
generated: '2026-08-06'
method: searched
source: https://support.atera.com/hc/en-us/articles/219083397-Using-the-Atera-API
docs: https://support.atera.com/hc/en-us/articles/219083397-Using-the-Atera-API
notes: >-
  Derived by reading Atera's own support documentation, not from an OpenAPI file.
  Atera states in its API FAQ that the API is driven by OpenAPI 3.0, but the
  interactive reference at https://app.atera.com/apidocs returns 401 with an empty
  body to any unauthenticated client, and no specification is published at a public
  URL, so no securitySchemes could be parsed.
summary:
  types: [apiKey]
  api_key_in: [header]
  oauth2_flows: []
  oauth2: false
  openid_connect: false
  mutual_tls: false
  transport: https-only
schemes:
- name: X-API-KEY
  type: apiKey
  in: header
  parameter_name: X-API-KEY
  description: >-
    Account-scoped API token supplied on every request. Created in the Atera console
    under Admin > Data management > API; the token value is shown once at creation and
    cannot be retrieved afterwards.
  sources:
  - https://support.atera.com/hc/en-us/articles/219083397-Using-the-Atera-API
  - https://support.atera.com/hc/en-us/articles/115015347567-Script-for-checking-USB-connection-to-devices
  evidence: >-
    Atera's own PowerShell sample sets $headers.Add("X-API-KEY", 'YOUR_API_KEY_HERE')
    and calls https://app.atera.com/api/v3/agents/machine/$ENV:COMPUTERNAME.
token_model:
  multiple_tokens: true
  named: true
  expiration: required
  max_lifetime: 1 year from creation
  ip_restriction:
    supported: true
    modes: [allow-all, specific-ips]
  permissions:
    modes: [full-access, custom-access]
    granularity: per data domain
    actions: [Read, Write, Delete]
    note: >-
      Custom access sets Read/Write/Delete independently for each of the twelve data
      domains. This is a token permission model, not OAuth scopes — there is no
      authorization server, no consent screen and no scope string, so no scopes/
      artifact is emitted.
  rotation: >-
    Tokens carry an operator-chosen expiration date (maximum one year), so rotation is
    enforced by expiry rather than by a documented rotation procedure.
  announced: >-
    Multiple tokens with expiration dates, IP restrictions and permission scopes shipped
    in 2026 (Release Notes: 2026), initially to new accounts only.
domains:
- Agents
- Alerts
- Billing
- Contacts
- Contracts
- Customers
- CustomValues
- Departments
- Devices
- KnowledgeBase
- Rates
- Tickets
access:
  included_in_subscription: true
  available_during_trial: false
  note: >-
    "The API module in Atera is included as part of your subscription at no additional
    cost. However, it's important to note that during the trial period, API access is
    not available." — Atera API FAQ.
gaps:
- No OAuth 2.0 or OpenID Connect authorization server is published.
- No /.well-known/openid-configuration or /.well-known/oauth-authorization-server on
  app.atera.com (probed 2026-08-06 — see well-known/atera-well-known.yml).
- The interactive API reference cannot be read without an authenticated tenant token,
  so the exact per-operation security requirements are not publicly verifiable.
x-evidence:
- {url: 'https://support.atera.com/hc/en-us/articles/219083397-Using-the-Atera-API', http_status: 200, fetched: '2026-08-06'}
- {url: 'https://support.atera.com/hc/en-us/articles/11071761826844-API-FAQ', http_status: 200, fetched: '2026-08-06'}
- {url: 'https://app.atera.com/api/v3/agents', http_status: 401, fetched: '2026-08-06', note: unauthenticated call returns 401 with empty body}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/atera-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.