Avery Dennison · Authentication Profile
Avery Dennison Authentication
Authentication
Avery Dennison declares 2 security scheme(s) across its OpenAPI definitions.
Fortune 500IoTRFIDLabelsSupply ChainManufacturingDigital Product Passport
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
atma-oauth2 oauth2
· flows: ,
developer-portal-okta openIdConnect
Source
Authentication Profile
generated: '2026-09-18'
method: probed
source: https://login.atma.io/.well-known/openid-configuration
docs: null
summary: >-
The atma.io connected product cloud API (audience https://open.atma.io) is gated by OAuth 2.0 /
OpenID Connect issued from an Auth0 tenant on the provider's own custom domain, login.atma.io.
The documentation portal docs.atma.io itself redirects anonymous visitors into that authorization
flow (authorization code + PKCE S256, scopes openid profile email offline_access), so no public
authentication guide, API-key scheme or scope reference could be read. The profile below is what
the identity provider publishes about itself; API-level scopes for open.atma.io are undocumented.
schemes:
- name: atma-oauth2
type: oauth2
issuer: https://login.atma.io/
flows:
authorizationCode:
authorizationUrl: https://login.atma.io/authorize
tokenUrl: https://login.atma.io/oauth/token
refreshUrl: https://login.atma.io/oauth/token
pkce: S256
deviceCode:
deviceAuthorizationUrl: https://login.atma.io/oauth/device/code
tokenUrl: https://login.atma.io/oauth/token
audience: https://open.atma.io
identity_scopes: [openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address]
api_scopes: undocumented
token_endpoint_auth_methods: [client_secret_basic, client_secret_post, private_key_jwt, none]
jwks_uri: https://login.atma.io/.well-known/jwks.json
dynamic_client_registration: https://login.atma.io/oidc/register
evidence:
- url: https://login.atma.io/.well-known/openid-configuration
status: 200
- url: https://docs.atma.io/
status: 302
note: redirects to https://login.atma.io/authorize?...&audience=https%3A%2F%2Fopen.atma.io&code_challenge_method=S256
- name: developer-portal-okta
type: openIdConnect
issuer: https://averydennison.okta.com/oauth2/v1
note: >-
developer.averydennison.com is a Vouch-proxied portal whose every path 302s to an Okta
authorization request (scope openid email). This gates the portal, not an API; it is recorded
so the wall is on record.
evidence:
- url: https://developer.averydennison.com/developers/
status: 302
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/avery-dennison-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.