Automotive Grade Linux · Authentication Profile
Automotive Grade Linux Authentication
Authentication
Automotive Grade Linux secures its APIs with http and token across 2 declared security schemes, as derived from its OpenAPI definitions.
AutomotiveConnected VehiclesEmbedded LinuxIn-Vehicle InfotainmentIoTLinux FoundationOpen SourceSoftware Defined Vehicles
Methods: http, token
Schemes: 2
OAuth flows:
API key in:
Security Schemes
BasicAuth http
scheme: basic
LavaToken apiKey
· in: header ()
Source
Authentication Profile
generated: '2026-09-14'
method: searched
source: >-
openapi/automotive-grade-linux-events-tec-v1-openapi.json (securitySchemes),
https://www.automotivelinux.org/wp-json/ (authentication block in the WordPress REST root),
skills/automotive-grade-linux-lava-skill.md (AGL's own auth section), and live anonymous probes
on 2026-09-14
docs:
- https://raw.githubusercontent.com/automotive-grade-linux/lava-mcp-toolkit/main/lava-skill.md
- https://www.automotivelinux.org/wp-json/tec/v1/docs
summary:
types:
- http
- token
oauth2: false
openid_connect: false
mutual_tls: false
note: >-
No OAuth, no OIDC, no mTLS anywhere in the AGL estate. All six hosts probed return 404 for
/.well-known/openid-configuration, /.well-known/oauth-authorization-server and
/.well-known/oauth-protected-resource, and AGL's own LAVA reference states plainly:
"No OAuth, no refresh flow. Tokens are static until revoked in the UI."
schemes:
- name: BasicAuth
type: http
scheme: basic
surface: AGL Events API (tec/v1 and tribe/events/v1)
applies_to: all write operations (POST, PUT, DELETE)
anonymous_read: true
implementation: >-
WordPress Application Passwords. The site's /wp-json/ root advertises
authentication.application-passwords.endpoints.authorization =
https://www.automotivelinux.org/wp-admin/authorize-application.php
sources:
- openapi/automotive-grade-linux-events-tec-v1-openapi.json
- https://www.automotivelinux.org/wp-json/
- name: LavaToken
type: apiKey
in: header
header: Authorization
value_prefix: "Token "
surface: AGL LAVA Test Lab API
applies_to: job submission, cancellation and all writes; GET on jobs/, devices/, devicetypes/ is anonymous
rotation: manual - created and revoked in the LAVA web UI under API > Authentication Tokens
expiry: none; static until revoked
also_used_by: the legacy XML-RPC root, as https://<user>:<token>@lava.automotivelinux.org/RPC2
authorization_model: >-
Token identity is separate from object permission. AGL warns that a 401/403 on LAVA can mean the
token is fine but the identity lacks per-device or per-devicetype submit permission - an important
distinction for an agent deciding whether to retry with a different credential or stop.
sources:
- skills/automotive-grade-linux-lava-skill.md
credential_handling_guidance:
published: true
detail: >-
Unusually for this catalog, AGL publishes guidance on where an agent's credential should live.
lava-skill.md opens with "Do not embed credentials in prompts, code, or committed files" and gives
a three-row table of where the token lives per access method: an environment variable for MCP
stdio, a server-side users.json mapping for the multi-tenant MCP server (the caller presents a
different bearer token that the server exchanges), and $LAVA_TOKEN / $LAVA_TOKEN_FILE /
~/.config/lava/token for the shell scripts.
source: skills/automotive-grade-linux-lava-skill.md
anonymous_surfaces:
- url: https://www.automotivelinux.org/wp-json/tribe/events/v1/events
status: 200
- url: https://www.automotivelinux.org/wp-json/tribe/events/v1/venues
status: 200
- url: https://www.automotivelinux.org/wp-json/tec/v1/docs
status: 200
- url: https://lava.automotivelinux.org/api/v0.2/
status: 200
- url: https://lava.automotivelinux.org/api/v0.2/jobs/?format=json&limit=1
status: 200
- url: https://gerrit.automotivelinux.org/gerrit/projects/
status: 200
gated_surfaces:
- url: https://www.automotivelinux.org/wp-json/wp-abilities/v1/abilities
status: 401
code: rest_forbidden
- url: https://www.automotivelinux.org/wp-json/tribe/power-automate/v1/new-events
status: 401
- url: https://www.automotivelinux.org/wp-json/tec/v1/events/calendar-embed
status: 401
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/automotive-grade-linux-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.