Black Crow AI · Authentication Profile
Black Crow Ai Authentication
Authentication
Black Crow AI secures its APIs with none and session across 3 declared security schemes, as derived from its OpenAPI definitions.
CompanyE-CommerceArtificial IntelligenceMachine-LearningMarketingAdvertisingPersonalizationConversion OptimizationAnalyticsEvent IngestTag ManagementShopify
Methods: none, session
Schemes: 3
OAuth flows:
API key in:
Security Schemes
unauthenticated-tag-ingest none
portal-session session
platform-oauth-delegation delegated
Source
Authentication Profile
generated: '2026-08-12'
method: probed
source: >-
Live probes of https://api.blackcrow.ai/v1/events/* (2026-08-12) plus the first-party
browser bundle https://init.blackcrow.ai/js/core/example.js (HTTP 200) and the Black Crow AI
help center article "JavaScript"
(https://blackcrow.zendesk.com/hc/en-us/articles/20203743583387-JavaScript).
docs: https://blackcrow.zendesk.com/hc/en-us/articles/20203743583387-JavaScript
note: >-
Black Crow AI publishes no OpenAPI, so no securitySchemes could be derived. This profile is
built from what the ingest endpoint actually accepts and from how the provider's own tag
authenticates itself. There is NO developer-facing API key programme: access to the platform
is provisioned by Black Crow (a Customer Success Manager enables features), and the browser
tag is identified by site rather than by a secret.
summary:
types: [none, session]
api_key_in: []
oauth2_flows: []
developer_credentials_issued: false
schemes:
- name: unauthenticated-tag-ingest
type: none
applies_to: POST https://api.blackcrow.ai/v1/events/{event_name}
description: >-
The event ingest endpoint accepts anonymous cross-origin requests. A POST with an empty
JSON body was answered 400 with field-validation errors (siteName / pageId / visitorId
must not be null) — never 401 or 403 — so no credential is required to reach validation.
CORS is fully open: Access-Control-Allow-Origin "*", Access-Control-Allow-Methods
"GET, POST, PUT", Access-Control-Allow-Headers "Content-Type" (no Authorization header
is permitted through preflight, which confirms no bearer scheme is in use).
identity_carried_in:
- {field: siteName, in: body, note: 'customer/site identifier; the tag derives it from the bundle filename (xyz.js -> "xyz") or from Shopify.shop'}
- {field: visitorId, in: body, note: 'first-party visitor identifier, persisted in the _bcai_z cookie (set browser-side, or at the edge by @bcai/edge-sdk)'}
- {field: pageId, in: body}
evidence:
- {url: 'https://api.blackcrow.ai/v1/events/view', method: POST, http_status: 400, fetched: '2026-08-12'}
- {url: 'https://api.blackcrow.ai/v1/events/view', method: OPTIONS, http_status: 200, fetched: '2026-08-12'}
- name: portal-session
type: session
applies_to: https://app.blackcrow.ai/
description: >-
The Black Crow Portal (settings, product toggles, dashboards, Predictive Offer and
Enhanced CAPI controls) is behind an interactive sign-in at
https://app.blackcrow.ai/sign-in. No OpenID Connect or OAuth discovery document is
served: /.well-known/openid-configuration and /.well-known/oauth-authorization-server
returned 404 on both app.blackcrow.ai and api.blackcrow.ai on 2026-08-12.
evidence:
- {url: 'https://app.blackcrow.ai/.well-known/openid-configuration', http_status: 404, fetched: '2026-08-12'}
- {url: 'https://api.blackcrow.ai/.well-known/oauth-authorization-server', http_status: 404, fetched: '2026-08-12'}
- name: platform-oauth-delegation
type: delegated
applies_to: customer marketing platforms (Klaviyo, Attentive, Postscript, Sendlane, Mailchimp, Alia, Justuno, Meta, Google Ads, TikTok, Shopify)
description: >-
Black Crow does not issue credentials; it CONSUMES them. Onboarding is a sequence of
granting Black Crow access to the customer's own marketing platforms (help center
"Step 2 - Connect your platforms", plus one "Platform Access" article per platform),
and installing the Shopify app. The credential model is therefore inbound-delegated,
not outbound-issued.
docs: https://blackcrow.zendesk.com/hc/en-us/articles/20768291848475-Step-2-Connect-your-platforms
gaps:
- No public API key, token, or OAuth client registration exists for third-party developers.
- No .well-known/oauth-protected-resource, no scopes surface — scopes/ is correctly absent.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/black-crow-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.