Dokki · Authentication Profile
Dokki One Authentication
Authentication
Dokki secures its APIs with http, oauth2, and openIdConnect across 3 declared security schemes, as derived from its OpenAPI definitions.
CollaborationKnowledge ManagementDocumentsAgentsMCPArtificial IntelligenceProductivityWorkspacePublishingSearchSingapore
Methods: http, oauth2, openIdConnect
Schemes: 3
OAuth flows:
API key in:
Security Schemes
BearerAuth http
scheme: bearer
DokkiOAuth oauth2
· flows:
DokkiOIDC openIdConnect
Source
Authentication Profile
generated: '2026-09-19'
method: searched
source: https://dokki.one/pub/api/authentication
docs: https://dokki.one/pub/api/authentication
spec: openapi/dokki-one-openapi.yml
corroborating_sources:
- https://dokki.one/pub/api/api-keys-and-scopes
- https://dokki.one/pub/docs/clients
- https://dokki.one/pub/docs/workspace-connectors
- https://dokki.one/.well-known/oauth-authorization-server
- https://dokki.one/.well-known/oauth-protected-resource
summary:
types: [http, oauth2, openIdConnect]
transport: Authorization header, Bearer scheme, HTTPS only
note: >-
The REST API (https://dokki.one/api/v1) authenticates with a bearer credential — a Dokki API key
(dk_...), a Supabase access token, or the browser session — and authorizes through three gates
(token scope, tenant boundary, object permission). The MCP servers add OAuth 2.0 / OIDC with
discovery and dynamic client registration (RFC 8414, RFC 9728, RFC 7591) so interactive clients
can sign in without a key, plus workspace-scoped connector tokens for machines. The generated
OpenAPI models the REST side as one http bearer scheme; the OAuth side is documented here and in
scopes/dokki-one-scopes.yml because it is not visible from the REST reference.
schemes:
- name: BearerAuth
type: http
scheme: bearer
applies_to: REST API (/api/v1) and MCP endpoints
description: Authorization Bearer header carrying a dk_ API key, a Supabase bearer token, or (MCP) an OAuth access token.
sources: [openapi/dokki-one-openapi.yml, https://dokki.one/pub/api/authentication]
- name: DokkiOAuth
type: oauth2
applies_to: MCP endpoints (https://dokki.one/mcp/v2, https://dokki.one/api/mcp)
flows:
authorizationCode:
authorizationUrl: https://schcrwqbgkcmhdltwgcz.supabase.co/auth/v1/oauth/authorize
tokenUrl: https://dokki.one/api/oauth/token
refreshUrl: https://dokki.one/api/oauth/token
scopes:
openid: OpenID Connect identity
profile: Profile claims (name, picture, preferred_username)
email: Email claims
phone: Phone claims
offline_access: Refresh tokens
pkce: [S256, plain]
dynamic_client_registration: https://schcrwqbgkcmhdltwgcz.supabase.co/auth/v1/oauth/clients/register
token_endpoint_auth_methods: [client_secret_basic, client_secret_post, none]
consent: On the consent screen the user selects any combination of Personal, one or more Organizations and specific Workspaces; the grant is the union of that selection and never exceeds the user's own permissions.
sources: [https://dokki.one/.well-known/oauth-authorization-server, https://dokki.one/pub/docs/clients]
- name: DokkiOIDC
type: openIdConnect
openIdConnectUrl: https://dokki.one/.well-known/openid-configuration
issuer: https://dokki.one
id_token_signing_alg_values_supported: [RS256, HS256, ES256]
jwks_uri: https://schcrwqbgkcmhdltwgcz.supabase.co/auth/v1/.well-known/jwks.json
sources: [https://dokki.one/.well-known/openid-configuration]
credentials:
- id: api-key
header: 'Authorization: Bearer dk_...'
prefix: dk_
use: Server-to-server integrations and trusted non-interactive MCP clients
issued_by: Dokki account API key manager or POST /api/v1/api-keys (scope api_key:write)
tenant: Personal, or exactly one Org (an Org key cannot access a different Org; a Personal key cannot access Org workspaces)
scopes: Per-key scope list; new public keys default to read scopes (see scopes/dokki-one-scopes.yml)
shown_once: true
rotation: Create a replacement key, deploy it, verify GET /api/v1/me, then revoke the old key; record the key id, not the secret.
- id: supabase-bearer-token
header: 'Authorization: Bearer <supabase_access_token>'
prefix: null
use: First-party clients acting as a signed-in user
issued_by: Supabase Auth (Dokki's identity provider)
- id: browser-session
header: cookie session
use: The Dokki web app
- id: oauth-access-token
header: 'Authorization: Bearer <access_token>'
use: Interactive MCP clients (Claude, Claude Desktop, Claude Code, Codex, Cursor, ChatGPT) after OAuth discovery + consent
issued_by: Dokki token endpoint https://dokki.one/api/oauth/token
- id: workspace-connector-token
header: query parameters in the generated connector URL (workspace id, connector id, one-time token)
use: CI jobs, shared automations, dedicated agents locked to ONE workspace (Documents, Publish or Memory flavor)
issued_by: Workspace admins under Workspace -> Extensions -> Connectors; raw token shown once, Dokki keeps a hash and visible prefix
note: The client must preserve the exact connector URL and query parameters; a different workspace id or connector id is rejected.
verify_principal:
endpoint: GET /api/v1/me
returns: [type (authentication mode), user_id, org_id (null for Personal), key_id (API keys), scopes (effective)]
failures:
'401 unauthorized': missing, invalid, expired or revoked credentials
'403 insufficient_scope': credential valid but lacks the endpoint scope
'403 forbidden': scope valid but tenant or object permission denies access
'404': may be returned instead of 403 where revealing existence would leak information
mcp_challenge:
http_status: 401
www_authenticate: Bearer resource_metadata="https://dokki.one/.well-known/oauth-protected-resource?resource=https%3A%2F%2Fdokki.one%2Fapi%2Fmcp"
body: '{"jsonrpc":"2.0","error":{"code":-32001,"message":"Unauthorized"},"id":null}'
agent_guidance: '"Do not ask users to paste secrets into a chat. Ask them to create or authorize a key in Dokki, then store it in the host application''s secret manager."'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dokki-one-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.