Audigent · Authentication Profile

Audigent Authentication

Authentication

Audigent declares 2 security scheme(s) across its OpenAPI definitions.

CompanyAdvertisingAdTechDataIdentityProgrammaticAudienceMarketingPrivacyPrebidHeader BiddingData Curation
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

partner_id identifier
· in: query ()
session
· in: cookie ()

Source

Authentication Profile

audigent-authentication.yml Raw ↑
generated: '2026-08-06'
method: searched
source: >-
  https://docs.prebid.org/dev-docs/modules/hadronRtdProvider.html ;
  https://github.com/prebid/Prebid.js/blob/master/modules/hadronIdSystem.js ;
  live anonymous probes of id.hadron.ad.gt / seg.hadron.ad.gt / api.audigent.com

summary: >-
  Audigent publishes no OpenAPI and no developer auth reference. Its public
  ad-tech endpoints are unauthenticated by design — they are browser-side
  identity and segment calls that carry a non-secret numeric partner_id rather
  than a credential. The authenticated surface is the platform console at
  admin.audigent.com, whose API host 302s every anonymous request to a login.
  There is no API-key issuance page, no OAuth surface, and no documented token.

schemes:
- id: partner_id
  type: identifier
  in: query
  name: partner_id
  secret: false
  applies_to:
  - https://id.hadron.ad.gt/api/v1/pbhid
  - https://seg.hadron.ad.gt/api/v1/rtd
  - https://analytics.hadron.ad.gt/api/v1/analytics
  - https://cdn.hadronid.net/hadron.js
  description: >-
    Numeric Audigent Partner ID, issued by Audigent to a publisher or partner
    during onboarding and passed as a query parameter. The Prebid docs call it
    required for the RTD module ("This is the Audigent Partner ID obtained from
    Audigent"), but it is a tenant identifier embedded in client-side page
    JavaScript, not a secret — it is visible to anyone viewing the page source.
  x-evidence:
    fetched: '2026-08-06'
    url: https://id.hadron.ad.gt/api/v1/pbhid?partner_id=0&_it=prebid&t=1&src=id&domain=example.com
    http_status: 200
    note: >-
      Returned application/json with a freshly minted hadronId for an anonymous
      caller with partner_id=0 and no credential of any kind. Response values are
      per-browser identifiers and are deliberately not recorded here.

- id: console_session
  type: session
  in: cookie
  secret: true
  applies_to:
  - https://api.audigent.com
  - https://admin.audigent.com
  description: >-
    Customer/partner console login. The API host runs gunicorn behind a Django
    stack and issues a 302 to https://admin.audigent.com for anonymous requests;
    response headers advertise session cookie handling (Vary: Origin, Cookie),
    X-Frame-Options DENY and Cross-Origin-Opener-Policy same-origin. No public
    sign-up, no documented token endpoint, no OAuth metadata.
  x-evidence:
    fetched: '2026-08-06'
    url: https://api.audigent.com/
    http_status: 302
    location: https://admin.audigent.com

no_oauth: true
no_oauth_reason: >-
  No oauth2 or openIdConnect surface exists. /.well-known/oauth-authorization-server
  and /.well-known/openid-configuration returned 404 on every Audigent and Hadron
  host probed (id.hadron.ad.gt, analytics.hadron.ad.gt, seg.hadron.ad.gt,
  cdn.hadronid.net, api.audigent.com). scopes/ is therefore correctly absent.

cors:
  access_control_allow_origin: '*'
  access_control_allow_methods: GET, POST, OPTIONS
  access_control_allow_headers: '*'
  observed_on: https://id.hadron.ad.gt/api/v1/pbhid
  note: >-
    Fully open CORS on the identity endpoint, consistent with a surface intended
    to be called from any publisher page.

consent_as_access_control:
  note: >-
    In place of authentication, the public endpoints gate behavior on privacy
    consent signals passed by the page. See conformance/audigent-conformance.yml.
  parameters:
  - gdpr
  - gdprString
  - us_privacy
  - gpp
  - gpp_sid

gaps:
- No published authentication documentation on any Audigent-owned host.
- No API-key or credential self-service; partner IDs are issued via sales/onboarding.
- No machine-readable security scheme (no OpenAPI securitySchemes to derive from).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/audigent-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.