Biogen · Authentication Profile
Biogen Authentication
Authentication
Biogen secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.
BiotechnologyHealthcareLife SciencesPharmaceuticalsNeurologyFortune 500
Methods: apiKey
Schemes: 2
OAuth flows:
API key in: header
Security Schemes
apiKeyAuth apiKey
· in: header (x-api-key)
apiKeyAuth apiKey
· in: header (X-API-Key)
Source
Authentication Profile
generated: '2026-09-04'
method: searched
source: >-
https://developer1.biogen.com/swagger/export/23683 (the provider's own API definition, which
declares the auth scheme), https://developer1.biogen.com/io-docs and
https://developer.biogen.com/io-docs.
docs: https://developer.biogen.com/io-docs
summary:
types:
- apiKey
api_key_in:
- header
oauth2: false
mtls: false
schemes:
- name: apiKeyAuth
type: apiKey
in: header
parameter: x-api-key
description: >-
API key issued through the Biogen developer portal, sent on every request. Declared by Biogen's
own published definition as auth.key { param: "x-api-key", location: "header" }.
sources:
- https://developer1.biogen.com/swagger/export/23683
- openapi/_original/biogen-cdp-export-api-iodoc.json
- openapi/biogen-cdp-export-api-openapi.yml
- name: apiKeyAuth
type: apiKey
in: header
parameter: X-API-Key
description: >-
Portal-management key form documented for the developer portal's own key and service
endpoints. Note the case difference from the gateway's x-api-key — this scheme comes from
AE-authored specs transcribed from portal documentation, not from a Biogen-published contract.
sources:
- openapi/biogen-keys-api-openapi.yml
- openapi/biogen-services-api-openapi.yml
issuance:
self_service: false
flow: >-
Keys are requested through the portal's "Request Access Key" / Manage Keys screens, which require
a portal account. Registration is not open: the portal's Register link carries an empty href and
the portal stylesheet hides the register control, with sign-in handled by external SSO
(https://developer.biogen.com/login/external). Access is therefore employee/partner-issued.
oauth2:
declared: false
note: >-
The Mashery/Boomi io-docs page renders an OAuth 2.0 flow selector (authorization code, client
credentials, password, implicit) for every portal it hosts. That is platform chrome, not a Biogen
claim — the one Biogen API definition readable anonymously declares data-auth-type="key". No
OAuth2 scheme is asserted here and no scopes/ artifact is written.
transport:
https_only: true
evidence: >-
Biogen portal reference: the API "strictly uses HTTPS in the transport layer". TLS confirmed live
on every host (security/biogen-domain-security.yml).
discovery:
openid_configuration: false
oauth_authorization_server: false
protected_resource_metadata: false
evidence: well-known/biogen-well-known.yml — all five named paths missed on all six hosts.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/biogen-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.