ClinicalTrials.gov · Authentication Profile

Clinical Trials Gov Authentication

Authentication

ClinicalTrials.gov declares 0 security scheme(s) across its OpenAPI definitions.

Clinical TrialsGovernmentHealthNIHOpen DataPublic HealthResearch
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-06'
method: probed
source: >-
  openapi/_original/clinical-trials-gov-openapi.yml (no securitySchemes) plus live
  unauthenticated probes of https://clinicaltrials.gov/api/v2/* on 2026-09-06
summary:
  authentication_required: false
  scheme_count: 0
  registration_required: false
  api_key_required: false
  oauth: false
schemes: []
finding: >-
  The ClinicalTrials.gov Data API v2 requires no authentication of any kind. No
  securityScheme is declared in the contract, no credential is requested anywhere on
  https://clinicaltrials.gov/data-api, and unauthenticated GETs against every documented
  path return 200 with data. There is no signup, no key issuance and no account.
evidence:
- url: https://clinicaltrials.gov/api/v2/studies?pageSize=1
  status: 200
  note: unauthenticated, returned a full study record (application/json)
- url: https://clinicaltrials.gov/api/v2/version
  status: 200
  note: unauthenticated
- url: https://clinicaltrials.gov/api/v2/studies/metadata
  status: 200
  note: unauthenticated, 175,633 bytes of field metadata
- url: https://clinicaltrials.gov/.well-known/oauth-authorization-server
  status: 200
  note: SPA HTML shell, not an authorization-server metadata document — no OAuth surface exists
transport:
  https_required: true
  tls_version: TLSv1.3
  hsts: true
  note: See security/clinical-trials-gov-domain-security.yml for the full TLS/DNS posture.
data_rights:
  note: >-
    Data is U.S. Government work in the public domain and available "to all requesters, both
    within and outside the United States, at no charge"
    (https://clinicaltrials.gov/about-site/terms-conditions). Some records may carry
    third-party copyright; the terms tell consumers to consult those entities directly.
    Attribution to NLM and ClinicalTrials.gov is requested.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clinical-trials-gov-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.