Avery Dennison · Authentication Profile

Avery Dennison Authentication

Authentication

Avery Dennison declares 2 security scheme(s) across its OpenAPI definitions.

Fortune 500IoTRFIDLabelsSupply ChainManufacturingDigital Product Passport
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

atma-oauth2 oauth2
· flows: ,
developer-portal-okta openIdConnect

Source

Authentication Profile

avery-dennison-authentication.yml Raw ↑
generated: '2026-09-18'
method: probed
source: https://login.atma.io/.well-known/openid-configuration
docs: null
summary: >-
  The atma.io connected product cloud API (audience https://open.atma.io) is gated by OAuth 2.0 /
  OpenID Connect issued from an Auth0 tenant on the provider's own custom domain, login.atma.io.
  The documentation portal docs.atma.io itself redirects anonymous visitors into that authorization
  flow (authorization code + PKCE S256, scopes openid profile email offline_access), so no public
  authentication guide, API-key scheme or scope reference could be read. The profile below is what
  the identity provider publishes about itself; API-level scopes for open.atma.io are undocumented.
schemes:
- name: atma-oauth2
  type: oauth2
  issuer: https://login.atma.io/
  flows:
    authorizationCode:
      authorizationUrl: https://login.atma.io/authorize
      tokenUrl: https://login.atma.io/oauth/token
      refreshUrl: https://login.atma.io/oauth/token
      pkce: S256
    deviceCode:
      deviceAuthorizationUrl: https://login.atma.io/oauth/device/code
      tokenUrl: https://login.atma.io/oauth/token
  audience: https://open.atma.io
  identity_scopes: [openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone, address]
  api_scopes: undocumented
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post, private_key_jwt, none]
  jwks_uri: https://login.atma.io/.well-known/jwks.json
  dynamic_client_registration: https://login.atma.io/oidc/register
  evidence:
  - url: https://login.atma.io/.well-known/openid-configuration
    status: 200
  - url: https://docs.atma.io/
    status: 302
    note: redirects to https://login.atma.io/authorize?...&audience=https%3A%2F%2Fopen.atma.io&code_challenge_method=S256
- name: developer-portal-okta
  type: openIdConnect
  issuer: https://averydennison.okta.com/oauth2/v1
  note: >-
    developer.averydennison.com is a Vouch-proxied portal whose every path 302s to an Okta
    authorization request (scope openid email). This gates the portal, not an API; it is recorded
    so the wall is on record.
  evidence:
  - url: https://developer.averydennison.com/developers/
    status: 302

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/avery-dennison-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.