Corti · Authentication Profile

Corti Authentication

Authentication

Corti uses OAuth 2.0 client credentials (Keycloak / OpenID Connect) for server-to-server access to the Corti API. Clients exchange a client_id and client_secret at the realm token endpoint for a short-lived (5 minute) bearer access token, then call the API with an Authorization: Bearer header plus a required Tenant-Name header identifying the tenant context (default "base"). Limited-scope tokens (scope "openid transcribe" / "openid streams") can be minted for browser-side real-time streaming. The Embedded Assistant uses a separate token flow. Corti recommends client credentials over static API keys for short blast radius, scope granularity, and enterprise IdP/tenancy integration.

Corti secures its APIs with oauth2 and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials and authorizationCode flow(s).

CompanyHealthHealthcareArtificial IntelligenceSpeech-to-TextMedical CodingClinical DocumentationAgentsMachine-Learning
Methods: oauth2, openIdConnect Schemes: 2 OAuth flows: clientCredentials, authorizationCode API key in:

Security Schemes

CortiAuth oauth2
· flows: clientCredentials
BearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-07-18'
method: searched
source: https://docs.corti.ai/authentication/overview
docs: https://docs.corti.ai/authentication/overview
description: >-
  Corti uses OAuth 2.0 client credentials (Keycloak / OpenID Connect) for
  server-to-server access to the Corti API. Clients exchange a client_id and
  client_secret at the realm token endpoint for a short-lived (5 minute) bearer
  access token, then call the API with an Authorization: Bearer header plus a
  required Tenant-Name header identifying the tenant context (default "base").
  Limited-scope tokens (scope "openid transcribe" / "openid streams") can be
  minted for browser-side real-time streaming. The Embedded Assistant uses a
  separate token flow. Corti recommends client credentials over static API keys
  for short blast radius, scope granularity, and enterprise IdP/tenancy integration.
summary:
  types: [oauth2, openIdConnect]
  oauth2_flows: [clientCredentials, authorizationCode]
  token_ttl_seconds: 300
  required_headers: [Authorization, Tenant-Name]
  identity_provider: Keycloak (OpenID Connect)
schemes:
- name: CortiAuth
  type: oauth2
  description: OAuth 2.0 client credentials via Corti Auth (Keycloak realm)
  flows:
  - flow: clientCredentials
    tokenUrl: https://auth.eu.corti.app/realms/{tenant}/protocol/openid-connect/token
    scopes_count: 57
  token_endpoint_auth_methods: [client_secret_basic, client_secret_post, client_secret_jwt, private_key_jwt, tls_client_auth]
  sources: [docs, well-known/corti-openid-configuration.json]
- name: BearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: Short-lived JWT access token presented on each API request
  sources: [docs]
environments:
- name: eu
  auth_server: https://auth.eu.corti.app
  api_base: https://api.eu.corti.app/v2
- name: us
  auth_server: https://auth.us.corti.app
  api_base: https://api.us.corti.app/v2
- name: beta-eu
  auth_server: https://auth.beta-eu.corti.app
  api_base: https://api.beta-eu.corti.app/v2
notes:
- The Embedded Assistant authenticates differently; see https://docs.corti.ai/assistant/authentication
- Agents (A2A) MCP calls support authorizationType none/inherit; inherit reuses the caller bearer token.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/corti-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.