Beamy · Authentication Profile

Beamy Authentication

Authentication

Authentication profile observed at the edge. Beamy publishes no OpenAPI and no public auth reference, so this records only what the hosts themselves assert to an anonymous caller.

Beamy declares 2 security scheme(s) across its OpenAPI definitions.

SaaS ManagementShadow ITIT Asset ManagementCloud GovernanceSecurityApplication Portfolio ManagementUsage AnalyticsAI Governance
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

apiKey
http
scheme: bearer

Source

Authentication Profile

beamy-authentication.yml Raw ↑
generated: '2026-09-18'
method: probed
source:
- https://api.beamy.io/
- https://clientapi.prod.beamy.io/
- https://app.beamy.io/
- https://auth.beamy.io/
provider: Beamy
providerId: beamy
description: >-
  Authentication profile observed at the edge. Beamy publishes no OpenAPI and no public auth
  reference, so this records only what the hosts themselves assert to an anonymous caller.
schemes:
- id: kong-key-auth
  type: apiKey
  host: api.beamy.io
  observed:
    status: 401
    www_authenticate: Key
    body: '{"message":"No API key found in request","request_id":"..."}'
    server: kong/3.9.3
  detail: >-
    Kong's key-auth plugin fronts every path on api.beamy.io. The plugin accepts the key in a
    header or query parameter whose name is configured per gateway; Beamy does not publish which
    name it uses, so the parameter name is recorded as unknown rather than assumed.
  key_parameter: unknown
  key_location: unknown
  self_service_keys: false
  docs: null
- id: bearer-token
  type: http
  scheme: bearer
  host: clientapi.prod.beamy.io
  observed:
    status: 401
    body: '{"statusCode":401,"message":"TOKEN_EMPTY"}'
  detail: >-
    Internal client API called by the app.beamy.io single-page app; TOKEN_EMPTY indicates a bearer
    token issued by the app's login flow (auth.beamy.io is a Firebase-hosted login page). Not a
    public integration surface.
oauth2: null
openid_configuration: null
mutual_tls: false
sso:
  detail: >-
    The product integrates with Okta and Azure AD for SSO (apis.yml Integrations); the identity
    provider metadata is not published on any Beamy host — /.well-known/openid-configuration 404s
    on auth.beamy.io and is key-gated on api.beamy.io.
how_to_get_credentials: >-
  No public path. Keys are issued to customers; the implementation documentation is behind the
  docs.beamy.io lead form (email, name, company) and the full library behind a Beamy account.
x-evidence:
- url: https://api.beamy.io/
  http_status: 401
  fetched: '2026-09-18'
- url: https://clientapi.prod.beamy.io/
  http_status: 401
  fetched: '2026-09-18'
- url: https://auth.beamy.io/.well-known/openid-configuration
  http_status: 404
  fetched: '2026-09-18'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/beamy-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.