Beaconstac · Authentication Profile

Beaconstac Authentication

Authentication

Beaconstac secures its APIs with apiKey, oauth2, and openIdConnect across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, deviceCode, and refreshToken flow(s).

CompanyBig DataQR CodesDigital Business CardsMarketingAnalyticsSoftware-as-a-ServiceProximityWebhookMCP
Methods: apiKey, oauth2, openIdConnect Schemes: 4 OAuth flows: authorizationCode, clientCredentials, deviceCode, refreshToken API key in: header

Security Schemes

TokenAuth apiKey
· in: header ()
OrganizationId apiKey
· in: query ()
UniqodeMCPOAuth oauth2
· flows: authorizationCode, deviceCode, clientCredentials
UniqodeOIDC openIdConnect

Source

Authentication Profile

Raw ↑
generated: '2026-08-13'
method: searched
source: >-
  https://apidocs.uniqode.com/ (published Postman collection),
  https://docs.uniqode.com/en/articles/6064771-getting-started-with-static-and-dynamic-qr-code-api,
  https://mcp.uniqode.com/.well-known/oauth-protected-resource,
  https://auth.uniqode.com/.well-known/openid-configuration
docs: https://docs.uniqode.com/en/articles/6064771-getting-started-with-static-and-dynamic-qr-code-api
# Uniqode runs TWO distinct auth models on two distinct surfaces, and they do not share a
# credential. No OpenAPI is published; the REST model is read from the provider's own published
# Postman collection + help-center article, the MCP model from probed discovery documents.
summary:
  types: [apiKey, oauth2, openIdConnect]
  api_key_in: [header]
  oauth2_flows: [authorizationCode, clientCredentials, deviceCode, refreshToken]
surfaces:
- surface: REST API (https://api.uniqode.com/api/2.0/)
  model: static account token
- surface: MCP server (https://mcp.uniqode.com/mcp)
  model: OAuth 2.1 bearer, authorization server https://auth.uniqode.com/
schemes:
- name: TokenAuth
  type: apiKey
  in: header
  parameter_name: Authorization
  format: "Authorization: Token <API_KEY>"
  applies_to: REST API
  description: >-
    A dashboard-issued API key sent as a Token in the Authorization header. The key is found in
    the API section of the Uniqode dashboard sidebar. All requests must be made over HTTPS;
    plain HTTP and unauthenticated requests fail. API access requires a Pro plan or above.
  example: >-
    curl -X "GET" "https://api.uniqode.com/api/2.0/qrcodes/"
    -H "Authorization: Token <API_KEY>" -H "Content-Type: application/json"
  sources:
  - https://apidocs.uniqode.com/
  - https://docs.uniqode.com/en/articles/6064771-getting-started-with-static-and-dynamic-qr-code-api
- name: OrganizationId
  type: apiKey
  in: query
  parameter_name: organization
  applies_to: REST API
  description: >-
    Organization identifier from the dashboard API section. Required for accounts with
    multi-user access management, to scope a request to a specific organization. The published
    collection sends it as an `organization` query parameter on Digital Business Card, Analytics
    and Feedback Form requests (the collection variable is ORG_ID); the help-center article
    describes it as a value copied alongside the API key.
  sources:
  - https://apidocs.uniqode.com/
  - https://docs.uniqode.com/en/articles/6064771-getting-started-with-static-and-dynamic-qr-code-api
- name: UniqodeMCPOAuth
  type: oauth2
  applies_to: MCP server
  bearer_methods_supported: [header]
  flows:
  - flow: authorizationCode
    authorizationUrl: https://auth.uniqode.com/authorize
    tokenUrl: https://auth.uniqode.com/oauth/token
    pkce: [S256, plain]
    scope_count: 6
  - flow: deviceCode
    deviceAuthorizationUrl: https://auth.uniqode.com/oauth/device/code
    tokenUrl: https://auth.uniqode.com/oauth/token
  - flow: clientCredentials
    tokenUrl: https://auth.uniqode.com/oauth/token
  description: >-
    The hosted MCP server is an OAuth 2.0 protected resource (RFC 9728). Anonymous calls return
    401 with a WWW-Authenticate Bearer challenge naming the resource metadata document.
    Dynamic client registration is open at https://auth.uniqode.com/oidc/register.
  ref: scopes/beaconstac-scopes.yml
  sources:
  - https://mcp.uniqode.com/.well-known/oauth-protected-resource
  - https://auth.uniqode.com/.well-known/oauth-authorization-server
- name: UniqodeOIDC
  type: openIdConnect
  openIdConnectUrl: https://auth.uniqode.com/.well-known/openid-configuration
  issuer: https://auth.uniqode.com/
  applies_to: Dashboard + MCP identity
  id_token_signing_alg_values_supported: [HS256, RS256, PS256]
  token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt, none]
  backchannel_logout_supported: true
  platform: Auth0, on Uniqode's own auth.uniqode.com custom domain
  sources: [https://auth.uniqode.com/.well-known/openid-configuration]
notes:
- Dashboard sign-in additionally supports 2FA and SAML-based SSO with role-based access control (uniqode.com/security).
- >-
  The REST token and the MCP OAuth token are separate credentials on separate hosts; an MCP
  access token is not accepted by api.uniqode.com and vice versa.
- No API key rotation, expiry, or scoping policy is published for the REST token.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/beaconstac-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.