Dify · Authentication Profile
Dify Authentication
Authentication
Dify authenticates every Service API request with a bearer API key. There is exactly one securityScheme across all 82 operations, but two distinct key FAMILIES flow through it, with very different blast radii — a fact the spec states in prose and the scheme itself cannot express.
Dify secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.
Artificial IntelligenceLLMOpsBackend-as-a-ServiceAgentsWorkflowsKnowledge ManagementRAGModel Context ProtocolLow CodeOpen Source
Methods: http
Schemes: 1
OAuth flows:
API key in:
Security Schemes
ApiKeyAuth http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.