DEV Community · Authentication Profile

Dev To Authentication

Authentication

DEV Community secures its APIs with apiKey and http across 2 declared security schemes, as derived from its OpenAPI definitions.

Developer CommunityContentPublishingSocialBloggingOpen SourceArticlesWebhook
Methods: apiKey, http Schemes: 2 OAuth flows: API key in: header

Security Schemes

api-key apiKey
· in: header (api-key)
bearer_auth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: https://dev.to/openapi.json (components.securitySchemes) + https://developers.forem.com/api
docs: https://developers.forem.com/api
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
  notes: >-
    Forem API V1 accepts two credentials. The universal one is the per-user `api-key` header,
    generated by the account holder at https://dev.to/settings/extensions. Instances that enable
    delegated access additionally accept an RFC 9068 `Authorization: Bearer` JWT minted by the
    instance's configured delegation service and verified against its JWKS. Every V1 request must
    also carry `Accept: application/vnd.forem.api-v1+json` — the Accept header is the version
    selector, not a path segment, and omitting it silently routes the call to the deprecated V0 API.
schemes:
- name: api-key
  type: apiKey
  in: header
  parameter: api-key
  description: >-
    Per-user API key. Authentication for write operations (Articles, Reactions, Follows, Webhooks)
    requires a DEV API key; many read endpoints are accessible publicly without one. All
    authenticated endpoints are CORS-disabled — the key is intended for non-browser scripts.
  obtain: https://dev.to/settings/extensions
  sources:
  - https://dev.to/openapi.json
- name: bearer_auth
  type: http
  scheme: bearer
  bearer_format: JWT
  description: >-
    Short-lived RS256 RFC 9068 access token issued by the configured delegation service and verified
    against its configured JWKS. The issuer authorizes the client and requested operation before
    minting the token; Forem validates it and resolves its subject and owner to a local user. An
    invalid token returns 401; an unavailable trust dependency with no usable cached key returns 503.
    Available only on instances that enable delegated access.
  sources:
  - https://dev.to/openapi.json
required_headers:
- name: Accept
  value: application/vnd.forem.api-v1+json
  reason: >-
    Selects API version 1. Omitting it routes to the deprecated V0 API (the server replies with a
    299 Warning header pointing at the V1 Accept header).
oauth2: false
scopes_published: false
notes: >-
  No OAuth 2.0 authorization-code flow is published for the API surface, so no scopes/ artifact is
  emitted. Social sign-in (GitHub, Twitter) exists for the web application only, not for API clients.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dev-to-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.