Audatex · Authentication Profile

Audatex Authentication

Authentication

Audatex secures its APIs with apiKey and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit and password flow(s).

AutomotiveClaims ProcessingInsuranceRepair ManagementVehicle DataCollision RepairVehicle Inspection
Methods: apiKey, oauth2 Schemes: 3 OAuth flows: implicit, password API key in: header

Security Schemes

Bearer apiKey
· in: header (Authorization)
oauth2 oauth2
· flows: implicit
oauth2 oauth2
· flows: password

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: Derived from the five specs in openapi/ (openapi/audatex-api-gateway-openapi.yml, openapi/audatex-audaconnect-api-openapi.yml,
  openapi/audatex-audaconnect-bms-api-openapi.yml, openapi/audatex-dashboard-assignment-api-openapi.yml, openapi/audatex-gic-integration-api-openapi.yml,
  openapi/audatex-audaconnect-api-openapi.yml), then upgraded from the AudaConnect developers' guide https://audaconnect.ax-aee.co.uk/AudaAPI.BMSAPI/home/help
  and the OpenID Connect discovery document at https://dispatch-login-demo.audatex.com/.well-known/openid-configuration
  (2026-09-17).
summary:
  types:
  - apiKey
  - oauth2
  api_key_in:
  - header
  oauth2_flows:
  - implicit
  - password
  identity_servers:
  - name: AudaConnect OAuth 2.0 (Audatex UK)
    authorization_url: https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/OAuth20
    token_url: https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/OAuth20/token
    demo_authorization_url: https://audaconnect-demo.ax-aee.co.uk/AudaAPI.Portal/OAuth20
    serves:
    - Audatex AudaConnect API
    - Audatex AudaConnect BMS API
  - name: Solera / Audatex dispatch-login (North America, OpenID Connect)
    issuer: https://dispatch-login-demo.audatex.com
    token_url: https://dispatch-login-demo.audatex.com/connect/token
    authorization_url: https://dispatch-login-demo.audatex.com/connect/authorize
    discovery: well-known/audatex-openid-configuration.json
    serves:
    - Audatex GIC API
    - Solera Dashboard Assignment API
schemes:
- name: Bearer
  type: apiKey
  in: header
  parameter: Authorization
  description: "JWT Authorization header using the Bearer scheme. \r\n\r\n Enter 'Bearer' [space] and then your\
    \ token in the text input below.\r\n\r\nExample: \"Bearer 12345abcdef\""
  sources:
  - openapi/audatex-api-gateway-openapi.yml
- name: oauth2
  type: oauth2
  flows:
  - flow: implicit
    authorizationUrl: https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/Oauth20
    scopes: 18
  description: OAuth2 Implicit Grant
  sources:
  - openapi/audatex-audaconnect-api-openapi.yml
  - openapi/audatex-audaconnect-bms-api-openapi.yml
- name: oauth2
  type: oauth2
  flows:
  - flow: password
    tokenUrl: https://dispatch-login-demo.audatex.com/connect/token
    scopes: 1
  description: Authorization using the JWT Bearer scheme
  sources:
  - openapi/audatex-dashboard-assignment-api-openapi.yml
  - openapi/audatex-gic-integration-api-openapi.yml
docs: https://audaconnect.ax-aee.co.uk/AudaAPI.BMSAPI/home/help
documented_flows:
  source: https://audaconnect.ax-aee.co.uk/AudaAPI.BMSAPI/home/help
  note: The developers' guide documents THREE OAuth 2.0 flows for AudaConnect while the Swagger securityDefinitions
    declare only implicit — the spec under-describes the auth surface.
  flows:
  - flow: authorization_code
    rfc: RFC 6749 §1.3.1
    recommended_for: applications hosted on a secure server needing long-term access
    authorize: GET https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/OAuth20?client_id=&redirect_uri=&scope=&response_type=code
    token: 'POST https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/OAuth20/token (application/x-www-form-urlencoded:
      code, client_id, client_secret, redirect_uri, grant_type=authorization_code)'
    access_token_lifetime_seconds: 1800
    refresh_token: true
  - flow: refresh_token
    token: POST https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/oauth20/token (client_id, client_secret, refresh_token,
      grant_type=refresh_token) — or client_id/client_secret as HTTP Basic credentials
    note: Returns a new access token and a new refresh token; losing the refresh token forces the user back through
      consent.
  - flow: implicit
    rfc: RFC 6749 §1.3.2
    recommended_for: applications running locally on a user device (secret cannot be protected)
    authorize: GET https://audaconnect.ax-aee.co.uk/AudaAPI.Portal/OAuth20?client_id=&redirect_uri=&scope=&response_type=token
    access_token_lifetime_seconds: 1800
    refresh_token: false
    caveat: 'Guide: ''Some Audatex APIs will not work with the implicit flow. You should make us aware if you plan
      to use this flow.'''
  - flow: password
    rfc: RFC 6749 §4.3
    serves:
    - Audatex GIC API
    - Solera Dashboard Assignment API
    token: POST https://dispatch-login-demo.audatex.com/connect/token
    scope: b2b.fnol.api
    note: Declared in the GIC and Dashboard Assignment OpenAPIs; the OIDC discovery document also advertises device_authorization_endpoint,
      introspection and revocation.
  token_usage: 'Authorization: Bearer <access_token> on every request (e.g. GET /AudaAPI.WebAPI/api/users/me).'
  scope_delimiter: space (URL-encoded), e.g. scope=BMS.Basic BMS.Extended
  registration: Applications must be registered and approved in the AudaConnect Portal (My Client Applications);
    client id, secret and server endpoints are emailed after approval — https://audaconnect.ax-aee.co.uk/AudaAPI.BMSAPI/home/register
  unauthenticated_response:
    audaconnect: 401 text/plain "Unauthorised. Please provide valid user credentials." with a Correlation-Id header
    api_gateway_and_gic: 401 (JWT Bearer; GIC additionally 400 ApiVersionUnspecified when api-version is missing)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/audatex-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.