Daloopa · Authentication Profile
Daloopa Authentication
Authentication
Daloopa secures its APIs with http, oauth2, and apiKey across 4 declared security schemes, as derived from its OpenAPI definitions.
financial-datafundamental-datamarket-datainvestment-researchequity-researchsec-filingsearningsfintechmcpagent-nativeagent-skillswebhooksdata-warehouse
Methods: http, oauth2, apiKey
Schemes: 4
OAuth flows:
API key in:
Security Schemes
apiKeyAuth http
scheme: basic
mcpOAuth oauth2
mcpBearerToken http
scheme: bearer
mcpApiKeyHeader apiKey
· in: header ()
Source
Authentication Profile
generated: '2026-08-11'
method: searched
source: https://docs.daloopa.com/docs/api-authentication
docs: https://docs.daloopa.com/docs/api-authentication
mcp_docs: https://docs.daloopa.com/docs/mcp-authentication
summary:
types:
- http
- oauth2
- apiKey
note: >-
Two independent surfaces with different auth. The REST API v3 accepts ONLY HTTP Basic carrying
base64(email:api_key). The hosted MCP server accepts three methods: MCP OAuth 2.1 (dynamic client
registration + PKCE S256), a 24-hour bearer token minted from an API key, or a direct X-API-KEY header.
schemes:
- name: apiKeyAuth
surface: rest
type: http
scheme: basic
description: 'Basic authentication with base64-encoded credentials. Format: "Basic base64(email:apiKey)"'
header: Authorization
credential_format: base64(<email>:<api_key>)
example_form: 'Authorization: Basic base64(email:api_key)'
applies_to: https://app.daloopa.com/api/v3
sources:
- openapi/daloopa-api-openapi.yml
- https://docs.daloopa.com/docs/api-authentication
- name: mcpOAuth
surface: mcp
type: oauth2
description: >-
MCP OAuth per the Model Context Protocol authorization specification. Anonymous discovery is served
from the MCP host; an unauthenticated tools/list returns 401 with a WWW-Authenticate Bearer challenge
naming the protected-resource metadata document.
applies_to: https://mcp.daloopa.com/server/mcp
issuer: https://mcp.daloopa.com
authorization_endpoint: https://mcp.daloopa.com/authorize
token_endpoint: https://mcp.daloopa.com/token
registration_endpoint: https://mcp.daloopa.com/register
grant_types: [authorization_code]
response_types: [code]
pkce: S256
token_endpoint_auth_methods: [client_secret_post]
dynamic_client_registration: true
scopes_supported: null
scopes_note: >-
The authorization-server metadata document does NOT advertise a scopes_supported array, and no scope
reference is published in the docs. No OAuthScopes artifact is emitted because there are no published
scopes to record — an honest absence, not an unchecked field.
discovery:
authorization_server: well-known/daloopa-mcp-oauth-authorization-server.json
protected_resource: well-known/daloopa-mcp-oauth-protected-resource.json
sources:
- https://docs.daloopa.com/docs/mcp-authentication
- https://mcp.daloopa.com/.well-known/oauth-authorization-server
- https://mcp.daloopa.com/.well-known/oauth-protected-resource
- name: mcpBearerToken
surface: mcp
type: http
scheme: bearer
description: >-
API-key-for-token exchange. POST an existing Daloopa API key to the token endpoint to mint a bearer
token without running the OAuth flow. Tokens are valid for 24 hours, after which a new token must be requested.
token_exchange_endpoint: https://mcp.daloopa.com/auth/token
token_lifetime: 24h
operation: api_key_token_auth_token_post
sources:
- https://docs.daloopa.com/docs/mcp-authentication
- openapi/daloopa-mcp-service-openapi.json
- name: mcpApiKeyHeader
surface: mcp
type: apiKey
in: header
header: X-API-KEY
description: >-
Direct header-based API key authentication for callers who prefer not to mint or refresh a token.
The API key is sent with every request; no token generation or refresh is required.
sources:
- https://docs.daloopa.com/docs/mcp-authentication
key_management:
rotation: >-
"API keys will be rotated on a six-month cycle to ensure ongoing security" — published policy on the
authentication page.
rotation_period: 6 months
ip_allowlisting:
available: true
note: IP validation can be enabled on request to restrict API access to pre-approved addresses.
sso:
available: true
protocol: SAML/OIDC via Microsoft Entra (Azure AD)
docs: https://docs.daloopa.com/docs/single-sign-on
note: Applies to the Daloopa application account, not to API credentials directly.
observations:
- >-
The REST API v3 deliberately RETIRED the legacy plaintext-API-key scheme; v3 accepts only the encoded
email+key Basic form. v2 still accepts both during the migration window. This is a genuine auth
hardening, versioned rather than shipped silently.
- >-
The two surfaces do not share an auth mechanism. An agent that holds a working REST credential cannot
call the MCP server with it as-is without either the token exchange or the X-API-KEY header form.
cross_links:
conventions: conventions/daloopa-conventions.yml
conformance: conformance/daloopa-conformance.yml
well_known: well-known/daloopa-well-known.yml
lifecycle: lifecycle/daloopa-lifecycle.yml