AxonFlow · Authentication Profile

Axonflow Authentication

Authentication

AxonFlow secures its APIs with apiKey and http across 6 declared security schemes, as derived from its OpenAPI definitions.

CompanyAI GovernanceAI AgentsPolicy EnforcementAudit LoggingComplianceMCPOpen Source
Methods: apiKey, http Schemes: 6 OAuth flows: API key in: header

Security Schemes

BasicAuth http
scheme: basic
InternalServiceID apiKey
· in: header (X-Internal-Service-ID)
InternalServiceToken apiKey
· in: header (X-Internal-Service-Token)
OrgHeader apiKey
· in: header (X-Org-ID)
UserHeader apiKey
· in: header (X-User-ID)
BearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-10-09'
method: searched
source:
- https://docs.getaxonflow.com/docs/sdk/authentication/
- https://docs.getaxonflow.com/docs/api/auth-header-matrix/
- openapi/axonflow-agent-openapi.yml
- openapi/axonflow-masfeat-openapi.yml
- openapi/axonflow-orchestrator-openapi.yml
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
schemes:
- name: BasicAuth
  type: http
  scheme: basic
  description: 'OAuth2-style Basic authentication using `clientId:clientSecret` credentials.


    **Header format:** `Authorization: Basic base64(clientId:clientSecret)`


    - `clientId` (required): Your organization/client identifier

    - `clientSecret` (optional): Authentication credential. Optional for community/self-hosted mode.


    **Example:**

    ```bash

    # With clientSecret (enterprise)

    curl -H "Authorization: Basic $(echo'
  sources:
  - openapi/axonflow-agent-openapi.yml
  - openapi/axonflow-orchestrator-openapi.yml
- name: InternalServiceID
  type: apiKey
  in: header
  parameter: X-Internal-Service-ID
  description: 'Internal-service (operator lane) credential — **part one of two**.

    Must be sent together with `X-Internal-Service-Token`; either header

    alone is not a credential.


    This is the HMAC identity the Orchestrator and the Enterprise

    customer-portal use to call agent endpoints without holding a

    customer license. `apiAuthMiddleware` lifts both headers (plus an

    optional `X-Tenant-ID` scope) into `AuthHints`'
  sources:
  - openapi/axonflow-agent-openapi.yml
- name: InternalServiceToken
  type: apiKey
  in: header
  parameter: X-Internal-Service-Token
  description: 'Internal-service (operator lane) credential — **part two of two**.

    Must be sent together with `X-Internal-Service-ID`.


    Format: `AXON-INTERNAL-{unix_ts}-{sig}`, where `sig` is the first 16

    hex characters of HMAC-SHA256 over `orchestrator-internal:{unix_ts}`

    keyed with `AXONFLOW_INTERNAL_SERVICE_SECRET`. Validated by

    `platform/shared/serviceauth` within a 5-minute clock-skew window, so

    it must be r'
  sources:
  - openapi/axonflow-agent-openapi.yml
- name: OrgHeader
  type: apiKey
  in: header
  parameter: X-Org-ID
  description: 'Organization ID (required). `X-Tenant-ID` is accepted as a fallback.

    Requests without either header are rejected with HTTP 400.'
  sources:
  - openapi/axonflow-masfeat-openapi.yml
- name: UserHeader
  type: apiKey
  in: header
  parameter: X-User-ID
  description: 'Acting user for audit attribution (optional). `X-User-Email` is

    accepted as a fallback; when absent, actions are attributed to

    `"system"`.'
  sources:
  - openapi/axonflow-masfeat-openapi.yml
- name: BearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: Enterprise JWT token (see /scripts/generate-jwt.sh)
  sources:
  - openapi/axonflow-orchestrator-openapi.yml
docs: https://docs.getaxonflow.com/docs/sdk/authentication/
docs_summary: 'AxonFlow uses OAuth2-style Basic authentication for all deployments: Authorization: Basic base64(clientId:clientSecret).
  The client secret is optional in community mode and required in enterprise deployments. Community SaaS requests may add
  X-License-Token (AXON-...) with X-Axonflow-Client set automatically by the SDKs. AWS Marketplace credentials are generated
  at deployment and stored in AWS Secrets Manager at axonflow/customers/{your-org-id}/credentials.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/axonflow-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.