Clarivate Authentication
Every Clarivate API is fronted by one API gateway at api.clarivate.com (the portal runs wicked.haufe.io over Kong). The gateway supports two credential styles and the choice is per-API, not per-caller: an API key in the X-ApiKey header — used by 20 of the 26 published contracts — or OAuth 2.0 Client Credentials. Keys are issued per registered APPLICATION, not per user, and the portal states explicitly that a key must not be re-used across applications because the gateway cannot detect it. Two contracts deviate: the Converis Read API uses HTTP Basic against the customer's own Converis instance, and the EndNote API declares an OAuth 2.0 authorization-code flow.
Clarivate secures its APIs with apiKey, http, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.