Avnet · Authentication Profile

Avnet Authentication

Authentication

Avnet secures its APIs with apiKey, oauth2, and http across 4 declared security schemes, as derived from its OpenAPI definitions.

Fortune 500ElectronicsComponentsSupply ChainIoTManufacturingDistributionProcurementDevice ManagementFirmware
Methods: apiKey, oauth2, http Schemes: 4 OAuth flows: API key in: header, query

Security Schemes

Ocp-Apim-Subscription-Key apiKey
· in: header (Ocp-Apim-Subscription-Key)
OAuth2 client credentials oauth2
Bearer apiKey
· in: header (Authorization)
solution-key apiKey
· in: header (solution-key)

Source

Authentication Profile

Raw ↑
generated: '2026-09-18'
method: searched
source: >-
  Avnet API Portal How-To (https://apiportal.avnet.com/help/HowTo) and FAQ (https://apiportal.avnet.com/help/FAQ),
  the /IOTCONNECT Authenticate API Swagger (https://auth.iotconnect.io/api/v2/swagger-json, saved to
  openapi/avnet-iotconnect-auth-openapi.yml) and the securityDefinitions shared by all eight /IOTCONNECT module specs,
  plus the iotc-python-rest-api README (https://github.com/avnet-iotconnect/iotc-python-rest-api).
docs: https://apiportal.avnet.com/help/HowTo
summary:
  types: [apiKey, oauth2, http]
  api_key_in: [header, query]
  note: >-
    Two unrelated auth systems. The Avnet API Portal (procurement) layers an Azure API Management subscription key on top
    of an Entra ID OAuth 2.0 client-credentials bearer token. /IOTCONNECT issues its own JWT from a username/password
    login that also carries a per-tenant solution key in a header.
surfaces:
  - surface: Avnet API Portal (procurement APIs, gateway apigw.avnet.com)
    schemes:
      - name: Ocp-Apim-Subscription-Key
        type: apiKey
        in: header
        parameter: Ocp-Apim-Subscription-Key
        alternate: {in: query, parameter: subscription-key}
        description: >-
          Mandatory on every call. A subscription key is scoped to ONE API Product; a second product needs a second key.
          Keys are issued only after an Avnet API owner approves the subscription request, and each subscription carries a
          primary/secondary key pair so one can be regenerated while the other stays live. Avnet recommends renewing every
          6 months.
      - name: OAuth2 client credentials
        type: oauth2
        flow: clientCredentials
        tokenUrl: https://apigw.avnet.com/external/getToken/oauth2/v2.0/token
        description: >-
          grant_type=client_credentials with the client_id, client_secret and scope shown on the portal Profile page after
          approval (none of the three is published). The token endpoint proxies Microsoft Entra ID — an anonymous POST
          returns AADSTS7000216 invalid_client. The access token is sent as Authorization: Bearer <token>. Client secrets
          expire and must be renewed every 6 months; at most 2 active secrets per client; a Developer Utility endpoint
          POST https://apigw.avnet.com/external/clientsecret/{client_id} (bearer-authenticated) rotates a secret programmatically.
    probes:
      - url: https://apigw.avnet.com/external/getToken/oauth2/v2.0/token
        method: POST
        status: 401
        body: AADSTS7000216 invalid_client (client_assertion, client_secret or request required)
        checked: '2026-09-18'
  - surface: /IOTCONNECT REST API (eight modules on *.iotconnect.io)
    schemes:
      - name: Bearer
        type: apiKey
        in: header
        parameter: Authorization
        description: >-
          Declared as an apiKey scheme named Bearer in every module's securityDefinitions ("Please enter JWT with Bearer
          into field"); applied globally (security: [{Bearer: []}]). The JWT comes from POST /api/v2/Auth/login on
          auth.iotconnect.io, which additionally requires a solution-key header (the tenant's Solution Key, obtained through
          an /IOTCONNECT support ticket). GET /api/v2/Auth/basic-token, POST /api/v2/Auth/refresh-token, GET
          /api/v2/Auth/verify-token and POST /api/v2/Auth/m-login complete the flow. The first-party REST client stores the
          token locally, treats it as valid for 24 hours and refreshes it on use after one hour.
        sources:
          - openapi/avnet-iotconnect-auth-openapi.yml
          - openapi/avnet-iotconnect-device-openapi.yml
          - openapi/avnet-iotconnect-event-openapi.yml
          - openapi/avnet-iotconnect-file-openapi.yml
          - openapi/avnet-iotconnect-firmware-openapi.yml
          - openapi/avnet-iotconnect-master-openapi.yml
          - openapi/avnet-iotconnect-telemetry-openapi.yml
          - openapi/avnet-iotconnect-user-openapi.yml
      - name: solution-key
        type: apiKey
        in: header
        parameter: solution-key
        description: Required on the login and mobile-login operations only (openapi/avnet-iotconnect-auth-openapi.yml).
schemes:
- name: Ocp-Apim-Subscription-Key
  type: apiKey
  in: header
  parameter: Ocp-Apim-Subscription-Key
  surface: Avnet API Portal
- name: OAuth2 client credentials
  type: oauth2
  flow: clientCredentials
  tokenUrl: https://apigw.avnet.com/external/getToken/oauth2/v2.0/token
  surface: Avnet API Portal
- name: Bearer
  type: apiKey
  in: header
  parameter: Authorization
  surface: /IOTCONNECT
- name: solution-key
  type: apiKey
  in: header
  parameter: solution-key
  surface: /IOTCONNECT (login only)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/avnet-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.