Dotcms Authentication
Authentication profile for the dotCMS REST and GraphQL APIs, sourced from the provider's own auth documentation. It is `searched` rather than `derived` for a specific reason worth recording: the first-party OpenAPI dotCMS serves at /api/openapi.json declares NO components.securitySchemes and no top-level security requirement, across all 754 operations — while 368 of those operations declare a 401 response. The contract knows auth is required and does not say what it is. Everything below therefore comes from the docs, not from the spec.
dotCMS secures its APIs with http, apiKey-as-bearer, and session across 5 declared security schemes, as derived from its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.