Cisco Psirt Authentication
The OpenAPI declares only the WIRE format — HTTP bearer with a JWT. That is half the contract. Cisco's authentication docs supply the other half: the token is an OAuth 2.0 client-credentials access token minted by Cisco's Okta-backed identity service at id.cisco.com, from a client_id/client_secret pair issued when you register an application against this specific API in the Cisco API Console. The spec cannot express that, so an integrator reading the spec alone would not know where a token comes from.
Cisco PSIRT openVuln API secures its APIs with http and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.