CommsHarbor · Authentication Profile

Commsharbor Authentication

Authentication

CommsHarbor secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

EmailTransactional EmailEmail MarketingCommunicationsMessagingDeliverabilityCRMMulti-tenant SaaSAgent-NativeMCPWeb3 paymentsx402
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

bearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-05'
method: searched
source: openapi/commsharbor-openapi.json
docs: https://commsharbor.com/api/
summary:
  types:
  - http
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  description: Human session or scoped organization API key. Organization identity remains explicit.
  sources:
  - openapi/commsharbor-openapi.json
auth_modes:
  note: >-
    The machine-readable API index (GET /api/, 200) documents eleven per-endpoint auth modes beyond
    the single bearer scheme the OpenAPI declares. API keys are organization-scoped with named
    permissions; keys cannot manage credentials or membership, and platform access is a separate
    explicit grant never implied by tenant ownership. Keys and webhook secrets are revealed exactly
    once at creation; revocation is immediate.
  modes:
    - name: none
      detail: Public endpoint. No tenant data is returned.
    - name: session
      detail: Bearer session or secure session cookie. No organization is implied.
    - name: organization
      detail: Session plus X-Organization-Id membership, or a scoped API key that determines the organization (and rejects a conflicting header).
    - name: organization_template_write
      detail: Active organization identity with template:write permission.
    - name: organization_messages_send
      detail: Active organization identity with messages:send permission. Idempotency-Key is mandatory.
    - name: organization_campaign_write
      detail: Active organization identity with campaign:write permission. Campaign launches require Idempotency-Key.
    - name: organization_admin
      detail: Human organization member with the required role; API keys cannot manage credentials or membership.
    - name: platform_admin
      detail: Session with an explicit platform_roles grant. Tenant ownership does not grant platform access.
    - name: aws_sns
      detail: Amazon SNS signature, regional certificate URL and the exact configured TopicArn. Never accepts a user credential.
    - name: preference_capability
      detail: Signed, expiring capability scoped to one organization and contact. No login required; no email address embedded in the token.
    - name: credito
      detail: 'Prepaid credit token in Authorization: Bearer cred_... (or the X-Credito header). Not an account: a bearer of balance.'
  permissions:
    - messages:send
    - template:write
    - campaign:write

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/commsharbor-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.