AxonFlow · Authentication Profile
Axonflow Authentication
Authentication
AxonFlow secures its APIs with apiKey and http across 6 declared security schemes, as derived from its OpenAPI definitions.
CompanyAI GovernanceAI AgentsPolicy EnforcementAudit LoggingComplianceMCPOpen Source
Methods: apiKey, http
Schemes: 6
OAuth flows:
API key in: header
Security Schemes
BasicAuth http
scheme: basic
InternalServiceID apiKey
· in: header (X-Internal-Service-ID)
InternalServiceToken apiKey
· in: header (X-Internal-Service-Token)
OrgHeader apiKey
· in: header (X-Org-ID)
UserHeader apiKey
· in: header (X-User-ID)
BearerAuth http
scheme: bearer
Source
Authentication Profile
generated: '2026-10-09'
method: searched
source:
- https://docs.getaxonflow.com/docs/sdk/authentication/
- https://docs.getaxonflow.com/docs/api/auth-header-matrix/
- openapi/axonflow-agent-openapi.yml
- openapi/axonflow-masfeat-openapi.yml
- openapi/axonflow-orchestrator-openapi.yml
summary:
types:
- apiKey
- http
api_key_in:
- header
schemes:
- name: BasicAuth
type: http
scheme: basic
description: 'OAuth2-style Basic authentication using `clientId:clientSecret` credentials.
**Header format:** `Authorization: Basic base64(clientId:clientSecret)`
- `clientId` (required): Your organization/client identifier
- `clientSecret` (optional): Authentication credential. Optional for community/self-hosted mode.
**Example:**
```bash
# With clientSecret (enterprise)
curl -H "Authorization: Basic $(echo'
sources:
- openapi/axonflow-agent-openapi.yml
- openapi/axonflow-orchestrator-openapi.yml
- name: InternalServiceID
type: apiKey
in: header
parameter: X-Internal-Service-ID
description: 'Internal-service (operator lane) credential — **part one of two**.
Must be sent together with `X-Internal-Service-Token`; either header
alone is not a credential.
This is the HMAC identity the Orchestrator and the Enterprise
customer-portal use to call agent endpoints without holding a
customer license. `apiAuthMiddleware` lifts both headers (plus an
optional `X-Tenant-ID` scope) into `AuthHints`'
sources:
- openapi/axonflow-agent-openapi.yml
- name: InternalServiceToken
type: apiKey
in: header
parameter: X-Internal-Service-Token
description: 'Internal-service (operator lane) credential — **part two of two**.
Must be sent together with `X-Internal-Service-ID`.
Format: `AXON-INTERNAL-{unix_ts}-{sig}`, where `sig` is the first 16
hex characters of HMAC-SHA256 over `orchestrator-internal:{unix_ts}`
keyed with `AXONFLOW_INTERNAL_SERVICE_SECRET`. Validated by
`platform/shared/serviceauth` within a 5-minute clock-skew window, so
it must be r'
sources:
- openapi/axonflow-agent-openapi.yml
- name: OrgHeader
type: apiKey
in: header
parameter: X-Org-ID
description: 'Organization ID (required). `X-Tenant-ID` is accepted as a fallback.
Requests without either header are rejected with HTTP 400.'
sources:
- openapi/axonflow-masfeat-openapi.yml
- name: UserHeader
type: apiKey
in: header
parameter: X-User-ID
description: 'Acting user for audit attribution (optional). `X-User-Email` is
accepted as a fallback; when absent, actions are attributed to
`"system"`.'
sources:
- openapi/axonflow-masfeat-openapi.yml
- name: BearerAuth
type: http
scheme: bearer
bearerFormat: JWT
description: Enterprise JWT token (see /scripts/generate-jwt.sh)
sources:
- openapi/axonflow-orchestrator-openapi.yml
docs: https://docs.getaxonflow.com/docs/sdk/authentication/
docs_summary: 'AxonFlow uses OAuth2-style Basic authentication for all deployments: Authorization: Basic base64(clientId:clientSecret).
The client secret is optional in community mode and required in enterprise deployments. Community SaaS requests may add
X-License-Token (AXON-...) with X-Axonflow-Client set automatically by the SDKs. AWS Marketplace credentials are generated
at deployment and stored in AWS Secrets Manager at axonflow/customers/{your-org-id}/credentials.'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/axonflow-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.