CodeNOW · Authentication Profile

Codenow Authentication

Authentication

CodeNOW secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyDevOpsSoftware DeliveryPlatform EngineeringGovernanceAI AgentsCI/CDDeploymentKubernetesModel Context Protocol
Methods: apiKey, oauth2 Schemes: 2 OAuth flows: authorizationCode API key in: header

Security Schemes

ApiKeyAuth apiKey
· in: header ()
OAuth2 oauth2

Source

Authentication Profile

codenow-authentication.yml Raw ↑
generated: '2026-07-18'
method: searched
source: https://docs.codenow.com/api/overview/authentication/
summary:
  types: [apiKey, oauth2]
  api_key_in: [header]
  oauth2_flows: [authorizationCode]
schemes:
  - name: ApiKeyAuth
    type: apiKey
    in: header
    parameter_name: X-Codenow-Api-Key
    description: >-
      Pass your unique CodeNOW API key in the X-Codenow-Api-Key request header.
      Keys are obtained from the CodeNOW user profile and their permissions are
      tied to the user's Role-Based Access Control (RBAC) settings. Keys can be
      regenerated from account settings.
    docs: https://docs.codenow.com/api/overview/authentication/
    sources: [docs]
  - name: OAuth2
    type: oauth2
    description: >-
      OAuth 2.0 is the recommended authentication method for the CodeNOW MCP
      server (browser-based login with JWT token refresh). The REST API itself
      is authenticated with the X-Codenow-Api-Key header.
    applies_to: mcp-server
    docs: https://docs.codenow.com/api/overview/mcp-server/
    sources: [docs]
notes:
  - The REST API base URL is https://api.codenow.com/.
  - API key permissions inherit the calling user's RBAC role.
  - No public OpenAPI/Swagger document was found to derive schemes mechanically; this profile is captured from the published authentication documentation.