Celestia · Authentication Profile

Celestia Authentication

Authentication

The Celestia Node API authenticates with a single HTTP bearer token, but the interesting part is not the scheme — it is who issues it and what it carries. The token is a JWT minted by the operator's own node through the `celestia auth ` CLI (or node.AuthNew over an already-authorized connection), not by any Celestia Labs service. There is no vendor account, no API key to rotate in a dashboard, and no authorization server. Each token encodes one of four capability levels, and the provider declares the required level per method inside its OpenRPC document — which makes this a genuinely machine-readable permission model even though it is not OAuth.

Celestia secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

BlockchainData AvailabilityWeb3InfrastructureOpen SourceJSON-RPCModular BlockchainRollupCryptographyDeveloper Tools
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

BearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
docs: https://docs.celestia.org/build/rpc/node-api.md
source: >-
  https://docs.celestia.org/build/rpc/node-api.md,
  https://docs.celestia.org/operate/data-availability/light-node/advanced.md,
  openapi/celestia-node-api-openrpc.json,
  openapi/celestia-blob-api-openapi.yml, openapi/celestia-blobstream-api-openapi.yml,
  openapi/celestia-da-api-openapi.yml, openapi/celestia-das-api-openapi.yml,
  openapi/celestia-fraud-api-openapi.yml, openapi/celestia-header-api-openapi.yml,
  openapi/celestia-node-api-openapi.yml, openapi/celestia-p2-p-api-openapi.yml,
  openapi/celestia-share-api-openapi.yml, openapi/celestia-state-api-openapi.yml
description: >-
  The Celestia Node API authenticates with a single HTTP bearer token, but the interesting
  part is not the scheme — it is who issues it and what it carries. The token is a JWT minted
  by the operator's own node through the `celestia <node_type> auth <level>` CLI (or
  node.AuthNew over an already-authorized connection), not by any Celestia Labs service.
  There is no vendor account, no API key to rotate in a dashboard, and no authorization
  server. Each token encodes one of four capability levels, and the provider declares the
  required level per method inside its OpenRPC document — which makes this a genuinely
  machine-readable permission model even though it is not OAuth.
summary:
  types:
  - http
  vendor_issued: false
  self_issued: true
  scopes_machine_readable: true
schemes:
- name: BearerAuth
  type: http
  scheme: bearer
  format: JWT
  header: 'Authorization: Bearer <token>'
  issuer: the operator's own celestia-node instance
  sources:
  - openapi/celestia-node-api-openrpc.json
  - openapi/celestia-blob-api-openapi.yml
  - openapi/celestia-blobstream-api-openapi.yml
  - openapi/celestia-da-api-openapi.yml
  - openapi/celestia-das-api-openapi.yml
  - openapi/celestia-fraud-api-openapi.yml
  - openapi/celestia-header-api-openapi.yml
  - openapi/celestia-node-api-openapi.yml
  - openapi/celestia-p2-p-api-openapi.yml
  - openapi/celestia-share-api-openapi.yml
  - openapi/celestia-state-api-openapi.yml
issuance:
  cli: celestia <node_type> auth <public|read|write|admin> --p2p.network <network>
  example: celestia light auth admin --p2p.network mocha
  rpc: node.AuthNew
  verification_rpc: node.AuthVerify
  skip_auth_flag: --rpc.skip-auth
  note: >-
    Each invocation mints a NEW token; the CLI does not return an existing one.
permission_levels:
- level: public
  description: Methods callable without a token.
- level: read
  description: Read-only access across the data surface.
  method_count: 41
- level: write
  description: Submitting blobs and state transactions.
  method_count: 12
- level: admin
  description: Node administration, including the whole p2p module and key node.* methods.
  method_count: 27
level_declared_per_method: true
level_evidence: >-
  Every method in openrpc-v0.31.4.json carries its requirement in the description field, as
  "Auth level: read. Requests must include the HTTP header: Authorization: Bearer <token>."
  Counts above were computed across all 80 methods.
level_by_module:
  blob:
    read: 6
    write: 1
  blobstream:
    read: 2
  da:
    read: 6
    write: 2
  das:
    read: 2
  header:
    read: 10
  node:
    admin: 5
    read: 1
  p2p:
    admin: 22
  share:
    read: 7
  state:
    read: 7
    write: 9
oauth2: false
openid_connect: false
mtls: false
revocation:
  supported: false
  evidence: >-
    "Each time you run this, you will receive a new token. It's not possible to revoke
    tokens once they are issued." — https://docs.celestia.org/operate/data-availability/light-node/advanced.md
  consequence: >-
    A leaked admin token grants permanent control of the node's libp2p and administrative
    surface until the node's JWT signing key is rotated. For an agent deployment this is the
    single sharpest operational risk on the API: issue read-level tokens by default and mint
    write or admin only for the specific job that needs them.
expiry:
  published: false
  note: No token lifetime or expiry policy is documented.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/celestia-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.