Cape Partners · Authentication Profile

Capepartners Fr Authentication

Authentication

Cape Partners secures its APIs with apiKey across 6 declared security schemes, as derived from its OpenAPI definitions.

Mergers and AcquisitionsDeal FlowValuationInvestmentFinancial ServicesAgentsA2AFranceTechnologySoftware-as-a-Service
Methods: apiKey Schemes: 6 OAuth flows: API key in: path, header

Security Schemes

SessionToken apiKey
· in: path ({session_id})
NdaSigned precondition
· in: server-side (nda_signatures record for {session_id})
exchangeKey apiKey
· in: header (X-A2A-Key)
bearerKey http
scheme: bearer
engageToken apiKey
· in: path ({token})
turnstile human-verification
· in: body (turnstileToken (optional) or supervisor {name, email, company})

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/capepartners-fr-openapi.yml (securitySchemes) upgraded from the provider's own auth documentation — https://www.capepartners.fr/api (auth + guards blocks), https://www.capepartners.fr/.well-known/ai-plugin.json (auth.instructions), https://www.capepartners.fr/llms.txt, https://www.capepartners.fr/agent-exchange.html and the Agent Card securitySchemes.
docs: https://www.capepartners.fr/api
spec: openapi/capepartners-fr-openapi.yml
summary:
  types:
  - apiKey
  api_key_in:
  - path
  - header
  oauth2_flows: []
  transport: HTTPS only; Cloudflare in front; Referrer-Policy strict-origin-when-cross-origin on every response
  note: 'No API key at any tier and no OAuth. The provider''s auth model (its own words, /api and ai-plugin.json) is "path-capability-token + NDA": a workspace session UUID-v4 carried in the URL path is the credential for the workspace API, a recorded human NDA/Terms signature is a second precondition for confidential resources, and the agent exchange / A2A surface uses a separate capability key (the msgid issued with the first message, or the answer_key given on first read) sent as X-A2A-Key or a Bearer token. The OpenAPI models the first two as apiKey-in-header schemes only because securitySchemes cannot express a path credential — the header names X-Session-Id and X-Nda-Signed are NOT literal headers, and the spec says so in each description.'
schemes:
- name: SessionToken
  type: apiKey
  in: path
  parameter: '{session_id}'
  declared_in_spec_as: apiKey in header X-Session-Id (documentary only)
  description: The workspace session UUID is a capability token carried in the URL PATH. A valid request must present a well-formed UUID-v4 in the {session_id} path segment AND either no Origin/Referer or a first-party one (capepartners.fr, www.capepartners.fr, sniffer.capepartners.fr, localhost, 127.0.0.1). A malformed id answers 400 "Invalid session identifier"; a known-foreign Origin/Referer answers 403 "Cross-origin request rejected"; a headless agent should simply send no Origin/Referer. Applies to every /api/*/{session_id} operation and to body-keyed writes that carry session_id.
  issued_by: POST /api/workspace/join (returns session_id / uuid). An agent (no Turnstile token) must present an ACCEPTED exchange manifest key as exchange_key before a NEW uuid is issued — otherwise 403 handshake_required. A join never takes over an existing workspace (403 workspace_not_yours).
  sources:
  - openapi/capepartners-fr-openapi.yml
  - https://www.capepartners.fr/api
  - https://www.capepartners.fr/.well-known/ai-plugin.json
- name: NdaSigned
  type: precondition
  in: server-side
  parameter: nda_signatures record for {session_id}
  declared_in_spec_as: apiKey in header X-Nda-Signed (documentary only)
  description: 'NDA-gated resources — GET /api/matched-names/{session_id}, GET /api/seller-name/{session_id}, GET /api/infomemo/{session_id}, GET /api/infomemo/{session_id}/download, and GET /api/search/{session_id} — serve data only after a signature is recorded via POST /api/nda/sign. Unsigned answers 403 with nda_required:true. A signature alone is not sufficient: the session''s registered email must also be a validated mailbox (fix_required names the field). Signing requires a declared HUMAN supervisor bound at registration; an agent-initiated signature is recorded as pending and unlocks nothing until the supervisor approves via an emailed link.'
  sources:
  - openapi/capepartners-fr-openapi.yml
  - https://www.capepartners.fr/api
  - https://www.capepartners.fr/llms.txt
- name: exchangeKey
  type: apiKey
  in: header
  parameter: X-A2A-Key
  surface: 'A2A (POST /a2a, POST /a2a/message:send, GET /a2a/tasks, GET /a2a/tasks/{id}) and the REST twins (GET /api/exchange/answer/{msgid}, POST /api/exchange/reply body.key)'
  description: 'The capability key issued when an agent sends its first message — its msgid — or the stronger answer_key given on first read. Authorizes the caller''s own tasks/thread and nothing else. "The id identifies, the key authorizes": a task id alone is never enough, and a non-matching key is reported exactly like a missing task (TASK_NOT_FOUND / 404 "no record for that key"). Sending the first message needs no key at all.'
  declared_in: a2a/capepartners-fr-agent-card.json (securitySchemes.exchangeKey, apiKeySecurityScheme)
  sources:
  - a2a/capepartners-fr-agent-card.json
  - https://www.capepartners.fr/agent-exchange.html
- name: bearerKey
  type: http
  scheme: bearer
  parameter: 'Authorization: Bearer <msgid or answer_key>'
  surface: A2A
  description: The same exchange capability key, presented as an HTTP bearer credential instead of X-A2A-Key.
  declared_in: a2a/capepartners-fr-agent-card.json (securitySchemes.bearerKey, httpAuthSecurityScheme)
  sources:
  - a2a/capepartners-fr-agent-card.json
- name: engageToken
  type: apiKey
  in: path
  parameter: '{token}'
  surface: 'GET /engage/{token}/thread, POST /engage/{token}/reply, GET /engage/{token}/matches, GET /engage/{token}/summary'
  description: An opaque, operator-issued token bound to an exchange participant (issued by POST /engage/issue, admin-gated). Gives read-only assistants that cannot POST or hold a session a UUID-free view of a thread or of pre-NDA redacted matches. An unbound token answers 400; an unknown or revoked token answers 401. The raw session UUID is never exposed through this gateway.
  sources:
  - openapi/capepartners-fr-openapi.yml
  - https://www.capepartners.fr/engage
  - https://www.capepartners.fr/llms.txt
- name: turnstile
  type: human-verification
  in: body
  parameter: turnstileToken (optional) or supervisor {name, email, company}
  surface: POST /api/submit, POST /api/workspace/join
  description: Registration is human-gated by Cloudflare Turnstile. A human solving the widget sends turnstileToken, which the server verifies when present (403 on failure). An agent POSTing directly sends none and is classified as an agent; POST /api/submit then requires a declared human supervisor in the body ({"supervisor":{"name","email","company"}}) or answers 403 "Human verification failed". Consumer webmail addresses (gmail/outlook/hotmail/yahoo) are rejected on join — a verified business email is required.
  sources:
  - https://www.capepartners.fr/api
  - https://www.capepartners.fr/llms.txt
guards:
  uuid: 400 — Invalid session identifier (UUID-v4 required), checked before anything else is touched
  cross_origin: 403 — a present Origin/Referer must be a Cape Partners first-party host; absent is allowed
  rate_limit: 429 — rolling per-IP 60 requests / 60 s per endpoint family on confidential reads, retry_after (seconds) in the JSON body
  nda: 403 — nda_required:true until a human-approved signature is recorded; then the registered email must be a validated mailbox
  turnstile: 403 — Human verification failed on POST /api/submit and POST /api/workspace/join unless a human supervisor is declared
credentials:
  - id: workspace-session-uuid
    where: URL path segment {session_id} (and body session_id on some writes)
    prefix: null
    format: UUID v4
    use: Every workspace operation (session, matches, valuation, pairings, deal flow, interest signals, activity, info memos, mandate)
    issued_by: POST /api/workspace/join
    note: 'The provider''s homepage tells agents to "treat it like a password" — anyone holding the UUID can read name, email, company and financials. Do not log it or put it in a Referer (the server sets Referrer-Policy strict-origin-when-cross-origin for this reason).'
  - id: exchange-key
    where: X-A2A-Key header, Authorization Bearer, or body.key on POST /api/exchange/reply
    prefix: null
    format: msgid from the submission receipt, or answer_key from the first read
    use: Reading and answering the agent's own exchange thread / A2A tasks; presented as exchange_key on POST /api/workspace/join to upgrade to a workspace
    issued_by: The first SendMessage / POST /api/exchange/manifest (no credential needed to obtain it)
  - id: engage-token
    where: URL path segment {token}
    prefix: null
    format: opaque
    use: Read-only broker gateway for assistants that cannot POST
    issued_by: Operator, out of band (POST /engage/issue is admin-gated)
oauth: null
scopes: null

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/capepartners-fr-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.