Baker Hughes · Authentication Profile

Baker Hughes Authentication

Authentication

Baker Hughes declares 1 security scheme(s) across its OpenAPI definitions.

Energy TechnologyIndustrial IoTOil and GasAsset Performance ManagementDigital EnergyFortune 500
Methods: Schemes: 1 OAuth flows: API key in:

Security Schemes

oidc openIdConnect

Source

Authentication Profile

baker-hughes-authentication.yml Raw ↑
generated: '2026-09-17'
method: probed
source: https://auth-developer.bakerhughes.com/auth/realms/dedicated/.well-known/openid-configuration
provider: Baker Hughes
providerId: baker-hughes
scope: Identity for the Baker Hughes Developer Portal (developer.bakerhughes.com, a Backstage instance) and the
  Cordant platform tenants it fronts. No public API reference documents how a Cordant/BHC3 API call itself is authenticated;
  everything below is read from the provider's own OIDC discovery document, not inferred.
summary: 'OpenID Connect / OAuth 2.0 via a Keycloak realm (''dedicated''). The developer portal''s sign-in (GET
  /api/auth/keycloak/start?env=development on developer.bakerhughes.com) 302s to this realm''s authorization endpoint
  with client_id=app-cdp, PKCE S256 and scope ''openid profile email''. Anonymous calls to the portal''s catalog
  API (/api/catalog/entities) return 401 {"AuthenticationError": "Missing credentials"}; there is no self-serve
  sign-up — the portal''s support contact is cordant_success@bakerhughes.com.'
schemes:
- name: oidc
  type: openIdConnect
  openIdConnectUrl: https://auth-developer.bakerhughes.com/auth/realms/dedicated/.well-known/openid-configuration
  issuer: https://auth-developer.bakerhughes.com/auth/realms/dedicated
  authorization_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/auth
  token_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/token
  userinfo_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/userinfo
  jwks_uri: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/certs
  introspection_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/token/introspect
  revocation_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/revoke
  end_session_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/logout
  device_authorization_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/auth/device
  pushed_authorization_request_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/ext/par/request
  backchannel_authentication_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/protocol/openid-connect/ext/ciba/auth
  registration_endpoint: https://auth-developer.bakerhughes.com/auth/realms/dedicated/clients-registrations/openid-connect
  grant_types_supported:
  - authorization_code
  - client_credentials
  - implicit
  - password
  - refresh_token
  - urn:ietf:params:oauth:grant-type:device_code
  - urn:ietf:params:oauth:grant-type:token-exchange
  - urn:ietf:params:oauth:grant-type:uma-ticket
  - urn:openid:params:grant-type:ciba
  response_types_supported:
  - code
  - none
  - id_token
  - token
  - id_token token
  - code id_token
  - code token
  - code id_token token
  code_challenge_methods_supported:
  - plain
  - S256
  token_endpoint_auth_methods_supported:
  - private_key_jwt
  - client_secret_basic
  - client_secret_post
  - tls_client_auth
  - client_secret_jwt
  tls_client_certificate_bound_access_tokens: true
  require_pushed_authorization_requests: false
  scopes_supported:
  - openid
  - tenant-scope
  - abac_scope
  - email
  - profile
  id_token_signing_alg_values_supported:
  - PS384
  - RS384
  - EdDSA
  - ES384
  - HS256
  - HS512
  - ES256
  - RS256
  - HS384
  - ES512
  - PS256
  - PS512
  - RS512
  observed_client:
    client_id: app-cdp
    redirect_uri: https://developer.bakerhughes.com/api/auth/keycloak/handler/frame
    scope: openid profile email
    code_challenge_method: S256
    evidence: Location header of GET https://developer.bakerhughes.com/api/auth/keycloak/start?env=development (302)
portal_gate:
  url: https://developer.bakerhughes.com/api/catalog/entities
  status: 401
  body: '{"error":{"name":"AuthenticationError","message":"Missing credentials"}}'
  probed: '2026-09-17'
credential_issuance: Not self-serve. No public sign-up or key-issuance page was found; the portal's only published
  contact is cordant_success@bakerhughes.com and the Cordant site routes to CordantTechSupport@BakerHughes.com.
notes:
- The realm advertises a registration_endpoint (Keycloak clients-registrations/openid-connect); anonymous GET returns
  404 and no initial-access-token policy is published, so open dynamic client registration is NOT asserted.
- The realm-level public_key and JWKS (RS256 sig + RSA-OAEP enc keys) are served anonymously at the jwks_uri.
- Cordant marketing copy says the platform 'offers APIs for integration' (OT/IT connectivity) but publishes no auth
  scheme for them; treat API-call authentication as undocumented.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/baker-hughes-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.