DRINKOTEC · Authentication Profile
Drinkotec Authentication
Authentication
DRINKOTEC declares 1 security scheme(s) across its OpenAPI definitions.
BeveragesBeverage DispensingHospitalityPoint of SaleIoTAnalyticsPayments
Methods:
Schemes: 1
OAuth flows:
API key in:
Security Schemes
oauth2
· flows:
Source
Authentication Profile
generated: '2026-09-06'
method: searched
source: >-
https://drinkotec.ch/drinkotec-api/ — the provider's own API page. Live probe on
2026-09-06 returned 503 (origin-wide Infomaniak maintenance), so the content was read
from the Internet Archive capture of that same URL taken 2026-04-19
(http://web.archive.org/web/20260419112516id_/https://drinkotec.ch/drinkotec-api/, 200).
provider: DRINKOTEC
providerId: drinkotec
documented: false
documented_note: >-
DRINKOTEC does NOT publish an authentication reference. The single public statement about
authentication is one bullet on the API page — "supports OAuth2 authentication". There is
no authorization endpoint, token endpoint, grant type, scope list, client-registration
flow, key-issuance process or example request published anywhere on any DRINKOTEC host.
Because this artifact records a claim rather than documentation, NO `Authentication`
pointer is wired into apis.yml — emitting one would assert a reference page the provider
does not serve.
claim_only: true
schemes:
- id: oauth2
type: oauth2
status: claimed
evidence: >-
"The DRINKOTEC API: is a RESTful API. supports XML and JSON supports OAuth2
authentication" — verbatim from https://drinkotec.ch/drinkotec-api/
flows: unknown
authorization_url: null
token_url: null
scopes: []
scopes_documented: false
note: >-
No OAuth 2.0 metadata is discoverable. /.well-known/oauth-authorization-server and
/.well-known/openid-configuration return 404 on api.drinkotec.ch and iot.drinkotec.ch
and 503 on drinkotec.ch — see well-known/drinkotec-well-known.yml.
media_types:
- application/json
- application/xml
media_types_source: >-
"supports XML and JSON" on https://drinkotec.ch/drinkotec-api/
key_issuance:
self_serve: false
process: >-
None published. The only call to action on the API page is a "MEET OUR SOFTWARE
ENGINEERS" button linking to https://drinkotec.ch/book-a-visit/ — a scheduling form
for an in-person or phone consultation at the company's Nyon (VAUD, Switzerland)
office. Access to the API, and to the "complete reference documentation" the page says
exists, runs through that conversation.
reference_documentation:
claimed: true
claim_text: >-
"A complete reference documentation is available and includes every endpoint, attribute
and supported method for the most recent release of the API."
public_url: null
note: >-
The claim is made but no link, host, or path is given, and no reference was found on
drinkotec.ch, api.drinkotec.ch, iot.drinkotec.ch, info.drinkotec.ch, in the Internet
Archive's index of drinkotec.ch, or in web search. Note also that the page's own
heading carries a leftover HTML title attribute reading "Integrating with the
Lightspeed Retail API", indicating the copy was adapted from Lightspeed's API page —
recorded here as an observation about the source of the wording, not a claim about
the API itself.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/drinkotec-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.