Doordash Authentication
Every DoorDash developer API authenticates with a self-signed JSON Web Token presented as a bearer token. There is no OAuth flow, no token endpoint and no refresh: the caller mints a short-lived HS256 JWT locally from three credentials issued in the Developer Portal (developer_id, key_id, signing_secret) and signs it with the base64-decoded secret. Sandbox and production are separated by which access key is used, not by hostname. The Ads API and the legacy Marketplace API are the exceptions - both declare a plain apiKey-in-Authorization scheme in their own OpenAPI rather than the DoorDash JWT.
Doordash secures its APIs with http and apiKey across 5 declared security schemes, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.