CRM Bonus · Authentication Profile

Crm Bonus Authentication

Authentication

CRM Bonus secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

CompanyRetailLoyaltyCashbackCRMRetail MediaE-CommerceBrazilWhatsAppCustomer DataData IngestionPoint-of-Sale
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

HTTPBearer http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-08-12'
method: searched
source: openapi/crm-bonus-oto-data-api-openapi.yml
docs: https://ajuda.otocrm.com.br/support/solutions/articles/150000031734-cadastro-r%C3%A1pido-via-api
summary:
  types:
  - http
  http_schemes:
  - bearer
  oauth2_flows: []
  api_key_in: []
  scopes: 0
  note: >-
    Single-scheme, single-credential model. No OAuth 2.0, no OpenID Connect, no
    API-key header, no mTLS, and therefore no scope surface — which is why this
    repo emits no scopes/ artifact.
schemes:
- name: HTTPBearer
  type: http
  scheme: bearer
  bearer_format: JWT
  description: |-
    Você deverá enviar sua chave privada
    no cabeçalho HTTP `Authorization`, com o padrão `Bearer <token>`. Exemplo:

    ```
    GET / HTTP/1.1
    Host: data-api.otocrm.com.br
    Authorization: Bearer abcdef123456
    ```
  applied_to: >-
    All 12 /v1/* ingestion operations declare security: [{HTTPBearer: []}].
    POST /auth/login is the one unauthenticated operation.
  sources:
  - openapi/crm-bonus-oto-data-api-openapi.yml
token_issuance:
  self_service: false
  process: >-
    "Solicite ao time de suporte o token de acesso para utilização da API
    pública" — the access token is requested from Oto/CRMBonus support. There is
    no developer portal, no key-management console and no self-serve sign-up.
  per_environment: true
  per_environment_note: >-
    Production and homologação require separate credentials
    ("Ambos os ambientes requerem credenciais específicas").
  login_endpoint:
    operation_id: login_auth_login_post
    path: POST /auth/login
    request: 'LoginRequest {username, password}'
    response: 'TokenResponse {access_token, expires_in}'
    token_type: JWT
    expires_in: 3600
    claims_note: >-
      The operation description states the JWT carries user information and
      permissions, and that credentials are validated against a `users`
      collection. Those permissions are not exposed as OAuth scopes and are not
      documented anywhere public.
    failure_modes:
    - status: 401
      meaning: Credenciais inválidas
    - status: 403
      meaning: Conta de usuário inativa
    - status: 500
      meaning: Erro interno por exceção não esperada
runtime_behaviour:
  missing_credential:
    status: 403
    body: '{"detail": "Not authenticated"}'
    observed: '2026-08-12'
    note: >-
      403 rather than 401, and no WWW-Authenticate challenge header is returned.
      A client that branches on 401 for "needs auth" will mis-handle this API.
  transport:
    https_only: true
    hsts: 'max-age=31536000; includeSubDomains'
other_surfaces:
- name: CRMBonus Giftback / Vale Bonus API
  host: api.crmbonus.com
  documented: false
  auth: >-
    Partner-issued token. Third-party integration docs state the brand must ask
    the CRM&Bônus team to create a token, scoped to stores and with CPF
    collection enabled. No public reference, no published header name, no spec.
  note: >-
    Recorded for completeness; not part of the derived scheme set because no
    machine-readable contract exists for it.
gaps:
- No OAuth 2.0 or OIDC — no /.well-known/openid-configuration on any host (404).
- No documented token rotation, revocation or expiry policy for support-issued tokens.
- No WWW-Authenticate header on an unauthenticated request.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/crm-bonus-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.