Campbell Soup · Authentication Profile

Campbell Soup Authentication

Authentication

Campbell Soup declares 2 security scheme(s) across its OpenAPI definitions.

FoodConsumer Packaged GoodsRecipesProductsNutritionBrandsFortune 500Content APIWordPress
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

none
http
scheme: basic

Source

Authentication Profile

Raw ↑
generated: '2026-09-05'
method: derived
source: openapi/campbell-soup-content-api-openapi.yml (derived from https://www.campbells.com/wp-json/wp/v2) + live anonymous probes
provider: The Campbell's Company
providerId: campbell-soup
summary: >-
  The public surface is anonymous-read. Campbell's issues no developer credentials of any kind:
  there is no signup, no key request, no OAuth server and no documented auth page. Reads require
  nothing; writes are gated by WordPress core's own operator credentials, which are not available
  to the public.
schemes:
  - id: anonymous
    type: none
    applies_to: all GET operations
    evidence: >-
      GET https://www.campbells.com/wp-json/wp/v2/recipe?per_page=1 returned 200 with no
      Authorization header on 2026-09-05, carrying `Allow: GET` and `X-WP-Total: 316`.
  - id: basicAuth
    type: http
    scheme: basic
    applies_to: all POST/PUT/PATCH/DELETE operations declared by the wp/v2 route document
    public: false
    evidence: >-
      WordPress application passwords over HTTP Basic. The route discovery document declares the
      write methods and the surface exposes /wp/v2/users/{id}/application-passwords, but the live
      response advertises `Allow: GET` to anonymous callers and Campbell's publishes no way for a
      third party to obtain credentials.
oauth: false
openid_connect: false
mutual_tls: false
api_keys: false
signup_url: null
docs: null
notes: >-
  The retired Campbell's Kitchen developer API (developer.campbellskitchen.com) issued API keys via
  a developer portal. That host is NXDOMAIN as of 2026-09-05, so the key-issuing program is gone;
  what survives is an unauthenticated read surface with no onboarding at all.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/campbell-soup-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.