Best Buy · Authentication Profile
Best Buy Authentication
Authentication
Best Buy uses a single unscoped API key passed as a QUERY-STRING parameter (apiKey=) on every request. There is no OAuth, no OIDC, no bearer token, no signing, no key rotation endpoint and no scope model — one key grants everything the tier allows. The Commerce API uses a second, separately-issued key ("CAPI key") obtained by contacting Best Buy directly.
Best Buy secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
Fortune 100RetailConsumer ElectronicsE-CommerceProductStores
Methods: apiKey
Schemes: 2
OAuth flows:
API key in: query
Security Schemes
apiKey apiKey
capiKey apiKey
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.