Cubby · Authentication Profile
Cubby Authentication
Authentication
Cubby runs two distinct authentication models on one host. The Operator and Storefront APIs use a long-lived, out-of-band-issued API key presented as an HTTP bearer token, scoped to an Organization and further constrained by one of eight named key roles plus a separate PII entitlement. The MCP server on the same host uses OAuth 2.1 with PKCE and dynamic client registration. There is no self-service credential issuance for the REST surface — keys are obtained by emailing support.
Cubby declares 2 security scheme(s) across its OpenAPI definitions.
CompanySelf StorageProperty ManagementFacility ManagementReal EstatePaymentsSaaSArtificial IntelligenceRevenue ManagementE-Commerce
Methods:
Schemes: 2
OAuth flows:
API key in:
Security Schemes
http
oauth2