Channel99 · Authentication Profile
Channel99 Authentication
Authentication
Channel99 secures its APIs with apiKey, http, oauth2, and openIdConnect across 4 declared security schemes, as derived from its OpenAPI definitions.
CompanyMarketingAnalyticsAttributionB2BAdvertisingMarketing TechnologyArtificial IntelligenceAccount Based MarketingReportingMCPAgent ReadyIntent DataAccount IdentificationData Export
Methods: apiKey, http, oauth2, openIdConnect
Schemes: 4
OAuth flows:
API key in: header
Security Schemes
bearerAuth http
scheme: bearer
clientId apiKey
· in: header (x-client-id)
mcpOAuth oauth2
· flows:
stytchOIDC openIdConnect
Source
Authentication Profile
generated: '2026-08-12'
method: searched
source: https://support.channel99.com/hc/en-us/articles/49766041989787-Channel99-Reporting-API-Developer-Guide
docs:
- https://support.channel99.com/hc/en-us/articles/49766041989787-Channel99-Reporting-API-Developer-Guide
- https://pulsar.channel99.com/docs/#/
- https://mcp.channel99.com/.well-known/oauth-authorization-server
derived_from:
- openapi/channel99-pulsar-openapi.json
- well-known/channel99-mcp-oauth-authorization-server.json
- well-known/channel99-mcp-oauth-protected-resource.json
note: >-
Channel99 runs two distinct authentication models. The Pulsar Reporting API uses a
machine-to-machine client_credentials exchange against its own /auth/token endpoint, returning
a short-lived Stytch-issued JWT that must be paired with a matching x-client-id header on
every request. The MCP server and the web application use interactive OAuth 2.1 /
OpenID Connect against a Stytch authorization server hosted on a Channel99 subdomain.
summary:
types:
- apiKey
- http
- oauth2
- openIdConnect
api_key_in:
- header
credential_issuance: >-
Channel99 issues the M2M client_id and client_secret per customer instance; there is no
self-service key page. Credentials are bound to a single Channel99 instance, so a token can
only read data belonging to that tenant.
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: JWT
api: Pulsar Reporting API
description: |-
M2M Bearer token issued by Stytch. Pass as `Authorization: Bearer <token>`.
token_endpoint: https://pulsar.channel99.com/auth/token
token_request:
method: POST
content_type: application/json
body_fields:
- client_id
- client_secret
token_response_fields:
- access_token
- token_type
- expires_in
token_lifetime_seconds: 3600
refresh: >-
No refresh token. Re-POST /auth/token to mint a new access token after expiry. The
developer guide instructs callers to cache the token securely only for its stated lifetime.
rate_limit: 20 requests/minute per client_id on POST /auth/token (plus a WAF per-IP limit)
sources:
- openapi/channel99-pulsar-openapi.json
- https://support.channel99.com/hc/en-us/articles/49766041989787-Channel99-Reporting-API-Developer-Guide
- name: clientId
type: apiKey
in: header
parameter: x-client-id
api: Pulsar Reporting API
required: true
description: |-
Client identifier that must match the `client_id` claim in the Bearer token. Required on
EVERY route including /openapi.json - omitting it returns HTTP 401
err:pulsar.core.missing-header. A mismatch between the header and the token returns HTTP 403.
example_shape: m2m-client-00000000-0000-0000-0000-000000000000
sources:
- openapi/channel99-pulsar-openapi.json
- https://support.channel99.com/hc/en-us/articles/49766041989787-Channel99-Reporting-API-Developer-Guide
- name: mcpOAuth
type: oauth2
api: Channel99 MCP Server
standard: OAuth 2.1
flows:
authorizationCode:
authorizationUrl: https://app.channel99.com/oauth/authorize
tokenUrl: https://api.stytch.app.channel99.com/v1/oauth2/token
scopes:
openid: Authenticate the user and issue an ID token
email: Read the authenticated user's email address
profile: Read the authenticated user's basic profile
pkce_required: true
code_challenge_methods:
- S256
grant_types:
- authorization_code
- refresh_token
token_endpoint_auth_methods:
- none
dynamic_client_registration: false
client_id_metadata_document_supported: true
protected_resource: https://mcp.channel99.com
sources:
- well-known/channel99-mcp-oauth-authorization-server.json
- well-known/channel99-mcp-oauth-protected-resource.json
- https://support.channel99.com/hc/en-us/articles/47105598392475-MCP-Server-General-FAQ
- name: stytchOIDC
type: openIdConnect
api: Channel99 web application
openIdConnectUrl: https://api.stytch.app.channel99.com/.well-known/openid-configuration
issuer: https://api.stytch.app.channel99.com
jwks_uri: https://api.stytch.app.channel99.com/.well-known/jwks.json
userinfo_endpoint: https://api.stytch.app.channel99.com/v1/oauth2/userinfo
id_token_signing_alg_values_supported:
- RS256
scopes_supported:
- openid
- profile
- email
- phone
- offline_access
- full_access
subject_types_supported:
- public
sso: >-
The app publishes /sign-in/sso and per-organization sign-in routes
(/sign-in/inst/:orgSlug), so enterprise SSO is supported through Stytch B2B organizations.
sources:
- well-known/channel99-stytch-openid-configuration.json
secrets_handling:
guidance_published: true
guidance: >-
"Store the client secret securely. Do not include client secrets or access tokens in emails,
support tickets, browser screenshots, logs, source control, or client-side code." Support
tickets must exclude tokens and secrets.
source: https://support.channel99.com/hc/en-us/articles/49766041989787-Channel99-Reporting-API-Developer-Guide
separately_permissioned:
- surface: Channel99 IP API (GET /ip/{ipAddress})
note: >-
"Access to separately permissioned services, including the Channel99 IP API, is not enabled
unless explicitly granted." A valid token for the Reporting API does not imply access.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/channel99-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.