Conta Azul · Authentication Profile

Dvpj Authentication

Authentication

Conta Azul secures its APIs with oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

CompanyFintechAccountingERPBrazilSmall BusinessFinancial ManagementInvoicingPayments
Methods: oauth2 Schemes: 2 OAuth flows: authorizationCode API key in:

Security Schemes

OAuth2 oauth2
BearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-07-18'
method: searched
source: https://developers.contaazul.com/auth
docs: https://developers.contaazul.com/auth
summary:
  types: [oauth2]
  oauth2_flows: [authorizationCode]
  client_authentication: basic
  bearer_format: JWT
notes: >-
  Conta Azul API authenticates with OAuth 2.0 Authorization Code flow backed by
  AWS Cognito. The client exchanges the authorization code for tokens at the
  token endpoint using HTTP Basic auth (Base64 of client_id:client_secret).
  API calls carry the access_token as a Bearer JWT in the Authorization header.
  access_token TTL is 3600s (1h); refresh_token is valid up to 5 years or until
  the next renewal (a new refresh_token is returned on every renewal).
schemes:
  - name: OAuth2
    type: oauth2
    flow: authorizationCode
    authorizationUrl: https://auth.contaazul.com/login
    tokenUrl: https://auth.contaazul.com/oauth2/token
    client_authentication: basic
    scopes:
      - openid
      - profile
      - aws.cognito.signin.user.admin
    sources: [https://developers.contaazul.com/auth]
  - name: BearerAuth
    type: http
    scheme: bearer
    bearerFormat: JWT
    description: Bearer JWT access_token sent on every API request
    sources: [https://developers.contaazul.com/makingcalls, https://developers.contaazul.com/docs/financial-apis-openapi]

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dvpj-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.