Clix · Authentication Profile
Clix So Authentication
Authentication
Clix secures its APIs with apiKey across 5 declared security schemes, as derived from its OpenAPI definitions.
Push NotificationsMobileMessagingCampaignsEvent TrackingCustomer EngagementA2AMCPAgentsSDKUnited StatesCompany
Methods: apiKey
Schemes: 5
OAuth flows:
API key in: header
Security Schemes
ProjectIdAuth apiKey
· in: header (X-Clix-Project-ID)
ApiKeyAuth apiKey
· in: header (X-Clix-API-Key)
apiKey (A2A) apiKey
· in: header (X-API-Key)
none (MCP) none
device flow (CLI) human-login
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://docs.clix.so/api-reference/overview
derived_from: openapi/clix-so-openapi.yml
docs:
- https://docs.clix.so/api-reference/overview
- https://docs.clix.so/a2a/overview
- https://docs.clix.so/clix-cli
summary:
types: [apiKey]
api_key_in: [header]
oauth2: false
oidc: false
mtls: false
note: >-
Static API keys throughout. REST needs two headers on every call (project id + key); A2A needs one
(secret key, from which the project is resolved). Two key TYPES exist — public for client SDKs, secret
(clix_sk_ prefix) for server-side writes — and the docs are explicit that public keys are rejected on
/a2a and should not be used for user management, sending or triggering. Keys are issued in the console
(console.clix.so, login-gated); no OAuth metadata is served on any host.
schemes:
- name: ProjectIdAuth
type: apiKey
in: header
parameter: X-Clix-Project-ID
description: Project ID for authentication — identifies the project; rate limits are tracked on it.
required_with: ApiKeyAuth
surfaces: [REST]
sources: [openapi/clix-so-openapi.yml, 'https://docs.clix.so/api-reference/overview']
- name: ApiKeyAuth
type: apiKey
in: header
parameter: X-Clix-API-Key
description: API Key for authentication — public or secret depending on the operation.
key_types:
- {kind: public, prefix: not stated, use: 'Client-side SDKs in mobile apps, browsers, or public environments', visibility: Safe to expose}
- {kind: secret, prefix: clix_sk_, use: 'Server-to-server communication, secure backend operations — user management, message sending, campaign triggering', visibility: Must keep confidential}
surfaces: [REST]
sources: [openapi/clix-so-openapi.yml, 'https://docs.clix.so/api-reference/overview']
- name: apiKey (A2A)
type: apiKey
in: header
parameter: X-API-Key
description: Secret API key for A2A authentication (agent card securitySchemes.apiKey). Secret keys only; public keys are rejected; the project is resolved from the key so no project header is sent.
surfaces: [A2A — POST https://api.clix.so/a2a]
sources: [a2a/clix-so-agent-card.json, 'https://docs.clix.so/a2a/overview']
observed: 'POST /a2a without the header -> 401 text/plain "Missing API key" (2026-09-19)'
- name: none (MCP)
type: none
description: Neither MCP server takes a credential — the stdio @clix-so/clix-mcp-server and the Mintlify docs endpoint at https://docs.clix.so/mcp both search public documentation only.
surfaces: [MCP]
- name: device flow (CLI)
type: human-login
description: '`clix login` authenticates the CLI with a Clix account via device flow; `clix logout` removes stored credentials; `clix whoami` shows the user. A developer-session login, not an API scheme.'
surfaces: [CLI]
sources: ['https://docs.clix.so/clix-cli']
key_management:
issued_in: Clix console (https://console.clix.so — every path 307s to /auth/login)
rotation: 'Docs advise: store keys in environment variables or a secrets manager, rotate, least privilege (public in clients, secret only in trusted backends), audit and revoke unused keys, alert on unusual activity. No rotation API is documented.'
scopes: none — no scoped or restricted keys beyond the public/secret split
errors:
'401': 'Verify API key and Project ID are correct and valid. Observed bodies: "Missing project id" (REST), "Missing API key" (A2A).'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/clix-so-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.