Catnip · Authentication Profile
Catnip Authentication
Authentication
Catnip secures its APIs with apiKey and http across 3 declared security schemes, as derived from its OpenAPI definitions.
CompanyChatbotsMessagingConversational AIMarketing AutomationFacebook MessengerInstagramWhatsAppTikTokCustomer EngagementLead Qualification
Methods: apiKey, http
Schemes: 3
OAuth flows:
API key in: query
Security Schemes
ContactsApiToken http
scheme: bearer
BroadcastingToken apiKey
· in: query (chatfuel_token)
DashboardApiToken http
scheme: bearer
Source
Authentication Profile
generated: '2026-08-13'
method: searched
source: >-
https://help.chatfuel.com/create-contacts-in-chatfuel-via-api-23134b06ecf8800683b6efacab24b68d
(the only live Chatfuel API reference as of 2026-08-13), plus live 400/401/422
probes of https://api.chatfuel.com, https://dashboard.chatfuel.com/api and
https://panel.chatfuel.com/api. Chatfuel publishes no OpenAPI, so this auth
profile is captured from documentation and observed responses.
provider: Chatfuel
providerId: catnip
summary:
types:
- apiKey
- http
api_key_in:
- query
http_schemes:
- bearer
oauth2_flows: []
openid_connect: false
mutual_tls: false
schemes:
- name: ContactsApiToken
type: http
scheme: bearer
description: >-
An account API token generated in the product at Settings → API, sent as an
Authorization Bearer header on Contacts API requests. The automation_id in the
path (taken from the automation's URL) scopes the call to one automation.
applies_to:
- Chatfuel Contacts API
base_url: https://panel.chatfuel.com/api
header: 'Authorization: Bearer {token}'
token_source: Settings → API (in-product)
docs: https://help.chatfuel.com/create-contacts-in-chatfuel-via-api-23134b06ecf8800683b6efacab24b68d
observed:
probe: POST /api/contacts/{automation_id}/whatsapp/ with no Authorization header
status: 401
body: empty
trace_header: chatfuel-trace-id
- name: BroadcastingToken
type: apiKey
in: query
parameter: chatfuel_token
description: >-
A unique token issued per bot, passed as the chatfuel_token query parameter on
every Broadcasting API request. Scopes the call to a single bot. Carrying the
credential in the query string means it is logged by every intermediary — an
agent should treat the token as exposed.
applies_to:
- Chatfuel Broadcasting API
base_url: https://api.chatfuel.com
docs: null
docs_retired: https://docs.chatfuel.com/en/articles/790461-broadcasting-api
docs_status: 404
observed:
probe: POST /bots/{bot_id}/users/{user_id}/send with no token
status: 400
body: '{"result":"Bad Request: Missing required chatfuel_token parameter","success":false,...}'
note: >-
With an unrecognised token the API answers 422 "Bad Data: Bot not found"
rather than 401/403, so a bad credential and a bad bot id are indistinguishable.
- name: DashboardApiToken
type: http
scheme: bearer
description: >-
A Dashboard API Token generated from the account profile (profile photo →
Dashboard API Token → generate). Sent as an Authorization Bearer header on every
Dashboard API request. The Dashboard API was documented as primarily for
internal use and subject to change.
applies_to:
- Chatfuel Dashboard API
base_url: https://dashboard.chatfuel.com/api
header: 'Authorization: Bearer {token}'
docs: null
docs_retired: https://docs.chatfuel.com/en/articles/2706667-dashboard-api
docs_status: 404
observed:
probe: GET /api/bots with no Authorization header
status: 401
body: '{"result":"User not found","success":false,"errors":["User not found"],"message":null}'
scopes:
supported: false
note: >-
No OAuth2 or scope surface exists. Tokens are all-or-nothing at the bot,
automation or account level; there is no way to issue a read-only or
least-privilege credential, which is the sharpest auth gap for agent use.
rotation:
documented: false
note: No token rotation, expiry or revocation policy is published for any of the three tokens.
notes: >-
The JSON API plugin (formerly documented at
https://docs.chatfuel.com/en/articles/735122-json-api, now 404) is an outbound
integration — the bot calls the developer's own backend — so its auth is defined
by the external endpoint, not by Chatfuel. No OAuth2, OIDC or mTLS surface is
published: /.well-known/oauth-authorization-server and
/.well-known/openid-configuration 404 on every real Chatfuel host.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/catnip-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.