CJ Affiliate · Authentication Profile
Cj Affiliate Authentication
Authentication
One credential covers CJ's entire platform: a long-lived Personal Access Token sent as an HTTP Bearer credential. The same token authenticates all three GraphQL endpoints, all the classic REST APIs and both click-tracking APIs. There is no OAuth 2.0, no OpenID Connect, no scopes, no refresh and no token endpoint a client may call — /.well-known/openid-configuration and /.well-known/oauth-authorization-server return 404 on every CJ host including iam.cj.com, the internal PAT service the developer portal itself calls.
CJ Affiliate secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
Affiliate MarketingAffiliate NetworkCommissionProduct SearchPublishersAdvertiserGraphQLE-CommerceProduct FeedsConversion TrackingAttributionPerformance MarketingRetailCoupons
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
personalAccessToken http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.