Biogen · Authentication Profile

Biogen Authentication

Authentication

Biogen secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.

BiotechnologyHealthcareLife SciencesPharmaceuticalsNeurologyFortune 500
Methods: apiKey Schemes: 2 OAuth flows: API key in: header

Security Schemes

apiKeyAuth apiKey
· in: header (x-api-key)
apiKeyAuth apiKey
· in: header (X-API-Key)

Source

Authentication Profile

Raw ↑
generated: '2026-09-04'
method: searched
source: >-
  https://developer1.biogen.com/swagger/export/23683 (the provider's own API definition, which
  declares the auth scheme), https://developer1.biogen.com/io-docs and
  https://developer.biogen.com/io-docs.
docs: https://developer.biogen.com/io-docs
summary:
  types:
    - apiKey
  api_key_in:
    - header
  oauth2: false
  mtls: false
schemes:
  - name: apiKeyAuth
    type: apiKey
    in: header
    parameter: x-api-key
    description: >-
      API key issued through the Biogen developer portal, sent on every request. Declared by Biogen's
      own published definition as auth.key { param: "x-api-key", location: "header" }.
    sources:
      - https://developer1.biogen.com/swagger/export/23683
      - openapi/_original/biogen-cdp-export-api-iodoc.json
      - openapi/biogen-cdp-export-api-openapi.yml
  - name: apiKeyAuth
    type: apiKey
    in: header
    parameter: X-API-Key
    description: >-
      Portal-management key form documented for the developer portal's own key and service
      endpoints. Note the case difference from the gateway's x-api-key — this scheme comes from
      AE-authored specs transcribed from portal documentation, not from a Biogen-published contract.
    sources:
      - openapi/biogen-keys-api-openapi.yml
      - openapi/biogen-services-api-openapi.yml
issuance:
  self_service: false
  flow: >-
    Keys are requested through the portal's "Request Access Key" / Manage Keys screens, which require
    a portal account. Registration is not open: the portal's Register link carries an empty href and
    the portal stylesheet hides the register control, with sign-in handled by external SSO
    (https://developer.biogen.com/login/external). Access is therefore employee/partner-issued.
oauth2:
  declared: false
  note: >-
    The Mashery/Boomi io-docs page renders an OAuth 2.0 flow selector (authorization code, client
    credentials, password, implicit) for every portal it hosts. That is platform chrome, not a Biogen
    claim — the one Biogen API definition readable anonymously declares data-auth-type="key". No
    OAuth2 scheme is asserted here and no scopes/ artifact is written.
transport:
  https_only: true
  evidence: >-
    Biogen portal reference: the API "strictly uses HTTPS in the transport layer". TLS confirmed live
    on every host (security/biogen-domain-security.yml).
discovery:
  openid_configuration: false
  oauth_authorization_server: false
  protected_resource_metadata: false
  evidence: well-known/biogen-well-known.yml — all five named paths missed on all six hosts.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/biogen-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.