Brevo Authentication
Brevo offers two authentication schemes. API key is the default and the only one the published OpenAPI specs declare: a secret token sent in a lowercase `api-key` request header, scoped to the whole account with no per-key permissions. OAuth 2.0 was added for apps acting on behalf of a Brevo user and is where the granular permission model lives — 37 scopes on a partner realm, created and managed entirely through the Brevo CLI with no application form or manual approval. The two are documented together but only one is described in the machine-readable contract, so an agent reading the specs alone will not discover OAuth at all.
Brevo secures its APIs with apiKey and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and clientCredentials flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.