Datarails Authentication
Datarails runs two unrelated authentication models across two surfaces. The FinanceOS MCP server uses OAuth 2.1 with PKCE and dynamic client registration (discoverable at RFC 8414 / RFC 9728 well-known endpoints). The Data Gateway Service upload endpoint uses HTTP Basic with the base64 of a Datarails user's username:password — a service account that Datarails documents must not have MFA enabled. Human sign-in to the application supports SAML SSO.
Datarails secures its APIs with oauth2 and http across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/datarails-authentication"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.