Cardtonic · Authentication Profile
Cardtonic Authentication
Authentication
The Cardtonic Business API publishes no OpenAPI securitySchemes (components.securitySchemes is empty and every operation carries security: []), so this profile is read from the documented operations themselves rather than derived from the spec. Access is a two-stage model: a business user signs up and logs in to obtain a session token, then mints a long-lived API key through POST /users/generate-key. Every documented request additionally requires an X-Tonic-Env environment-selector header.
Cardtonic declares 3 security scheme(s) across its OpenAPI definitions.
AfricaBill PaymentseSIMFinanceFintechGift CardsGhanaNigeriaPaymentsVirtual Dollar Cards
Methods:
Schemes: 3
OAuth flows:
API key in:
Security Schemes
X-Tonic-Env apiKey
http
apiKey
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.