Attendease · Authentication Profile
Attendease Authentication
Authentication
Attendease declares 4 security scheme(s) across its OpenAPI definitions.
CompanyEventEvent ManagementEvent MarketingConferencesWebinarsAttendeesRegistrationSoftware-as-a-Service
Methods:
Schemes: 4
OAuth flows:
API key in:
Security Schemes
http
scheme: hmac-sha1
X-Attendee-Token apiKey
· in: header ()
X-Event-Token apiKey
· in: header ()
http
scheme: basic
Source
Authentication Profile
generated: '2026-08-13'
method: searched
source: https://developer.attendease.com/, https://eventupplanner.zendesk.com/hc/en-us/articles/27101295757207-Event-and-Organization-API-Keys, https://eventupplanner.zendesk.com/hc/en-us/articles/27101962543383-How-do-I-add-or-remove-access-tokens
docs: https://developer.attendease.com/
summary: >-
Attendease exposes two authentication models. The Organization API (/api/v2/)
uses HMAC-SHA1 request signing with an Access Key ID and Secret Access Token.
The Event API uses per-event attendee/event tokens (query params or headers)
and also accepts HTTP Basic auth. All requests must use HTTPS.
schemes:
- id: org_api_hmac
api: Attendease Organization API
type: http
scheme: hmac-sha1
header: Authorization
format: 'APIAuth <access_key>:<signature>'
signing:
algorithm: HMAC-SHA1
encoding: base64
canonical_string: content-type,content-MD5,request-URI,timestamp
timestamp_header: Date
timestamp_format: RFC 1123
timestamp_skew_minutes: 15
content_md5: base64 MD5 of request body (PUT/POST only; empty for GET)
notes: >-
Query strings are part of the request URI but are not factored into the
Content-MD5. Signature = Base64.strict_encode64(HMAC-SHA1(secret_key,
canonical_string)).
- id: event_attendee_token
api: Attendease Event API
type: apiKey
in: header
name: X-Attendee-Token
alt_in: query
alt_name: attendee_token
description: Per-attendee access token scoped to a single event.
- id: event_token
api: Attendease Event API
type: apiKey
in: header
name: X-Event-Token
description: Event-level access token scoped to a single event subdomain.
- id: event_basic
api: Attendease Event API
type: http
scheme: basic
description: HTTP Basic auth with email/password (also accepted as query params).
credentials:
org_api: >-
Access Key ID + Secret Access Token issued at the organization level.
event_api: >-
Attendee tokens managed per event at
https://attendease.com/events/<event-subdomain>/access_tokens
credential_management:
event_api:
self_serve: true
console_path: Event -> Integrate -> Access Tokens
default_token: >-
A token named "default" is created automatically for every event. It is a
randomly generated UUID (128-bit value).
multiple_tokens: true
naming: Each token carries its own name for reference.
rotation: Self-serve — add a new token, remove the old one.
revocation: Deleting a token immediately prevents authenticating with it.
private_events: >-
If an event is marked "private", ALL API calls require an access token.
Marking an event private requires contacting support.
source: https://eventupplanner.zendesk.com/hc/en-us/articles/27101962543383-How-do-I-add-or-remove-access-tokens
org_api:
self_serve: false
rotation: >-
Organization API credentials cannot be created, deleted or regenerated from
the dashboard. Every change requires contacting support.
entitlement: >-
The Organization API is offered to ENTERPRISE customers only ("For
Enterprise customers, we also offer an Organization API to access all events
and attendees at the organization level"). See
plans/attendease-plans-pricing.yml.
source: https://eventupplanner.zendesk.com/hc/en-us/articles/27101295757207-Event-and-Organization-API-Keys
guidance_published:
never_share_keys: true
delete_unused_keys: true
periodic_rotation: true
note: >-
The help center publishes explicit API-key hygiene guidance: keys act as
passwords, delete them when no longer needed, and regenerate them
periodically when access must be maintained over long periods.
sso:
available: true
scope: Attendee and dashboard SSO
plans:
- Enterprise
protocol_published: false
note: >-
SSO is listed as an Enterprise entitlement on the plans page but no protocol
(SAML/OIDC) or metadata endpoint is documented publicly. The GitHub org
carries a fork of saml_idp, which suggests SAML, but that is not a provider
statement and is not recorded as fact.
source: https://eventupplanner.com/plans-and-pricing/
mfa:
available: true
scope: dashboard users (not API)
source: https://eventupplanner.zendesk.com/hc/en-us/articles/27102025968919-How-do-I-set-up-two-factor-authentication
transport: HTTPS required for all requests. Calls made over plain HTTP will fail.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/attendease-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.