Axonius Authentication
Authentication profile for the Axonius REST API, read from the public docs (no OpenAPI is published outside the login-gated developer.axonius.com reference). The API is reachable only through a dedicated SERVICE ACCOUNT (Axonius v6.1.74 and later; regular user accounts worked through v6.1.73) whose role grants API access and the permissions it needs. A service account authenticates one of two ways: an API key + API secret pair sent as request headers (the default, and the scheme the provider's own Postman collections and Python client use), or OAuth 2.1 client credentials exchanged at the instance's /api/oauth2/token endpoint for a one-hour bearer token. The instance host is customer-specific ({axonius-instance}).
Axonius secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.