Dronecode Foundation · Authentication Profile
Dronecode Authentication
Authentication
Dronecode Foundation declares 0 security scheme(s) across its OpenAPI definitions.
DronesUAVRoboticsMAVLinkPX4AutopilotAerial RoboticsgRPCOpen SourceLinux Foundation
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-09-06'
method: probed
source: >-
derive-authentication.py found nothing (there is no OpenAPI to read). Written instead from the 39
verbatim MAVSDK protobuf contracts under grpc/, from the MAVSDK/PX4 guides, and from a live
unauthenticated probe of https://dronecode.org/wp-json/ and its wp-abilities routes on 2026-09-06.
provider: Dronecode Foundation
providerId: dronecode
summary: >-
Two very different surfaces. The MAVSDK gRPC contract — the real API — declares NO authentication at
all, by design: the consumer runs the server themselves. The dronecode.org WordPress REST API, which
the Foundation's own /.well-known/api-catalog advertises, authenticates with WordPress Application
Passwords and refuses anonymous callers on everything but the discovery document.
surfaces:
- api: MAVSDK gRPC API
contract: grpc/_index.yml
schemes: []
scheme_count: 0
transport_security: none
detail: >-
No securityScheme equivalent appears in any of the 39 protos. mavsdk_server accepts plaintext
gRPC on 0.0.0.0:50051 with no TLS, no token, no mTLS and no per-call credential, and the
contract defines no scopes. This is not an omission the provider could close in the contract:
the server is a binary the CONSUMER runs on their own machine or companion computer, so the
trust boundary is the network they place it on, not a credential the Foundation issues.
consequences:
- >-
Anything that can reach port 50051 can arm, take off, and terminate the aircraft. The
ActionService contract has Arm, ArmForce, Kill and Terminate and none of them are gated.
- >-
There is no delegated identity, no consent surface, and no way to distinguish one caller from
another — every request is anonymous and fully privileged.
- >-
Binding mavsdk_server to anything other than loopback, or to a network an untrusted party can
reach, is an unauthenticated remote flight-control surface.
mitigation_documented: >-
The MAVSDK guide documents the --port/bind arguments and the usual deployment is loopback or a
dedicated companion-computer link, but no authentication guidance is published as part of the
contract.
docs: https://mavsdk.mavlink.io/main/en/
- api: dronecode.org WordPress REST API
contract: null
baseURL: https://dronecode.org/wp-json/
schemes:
- type: http
scheme: application-password
name: WordPress Application Passwords
location: Authorization header (HTTP Basic, user + application password)
authorization_endpoint: https://dronecode.org/wp-admin/authorize-application.php
source: >-
Read verbatim from the `authentication` block of the API's own discovery document at
https://dronecode.org/wp-json/ (HTTP 200, application/json, probed 2026-09-06).
scheme_count: 1
oauth2: false
openid_connect: false
detail: >-
The discovery root is anonymous and lists 74 routes across 7 namespaces. Everything behind it is
not. The wp/v2 content namespace is declared in `namespaces` but its routes are absent from the
route index and /wp-json/wp/v2/posts returns rest_no_route (404) — the content API has been
switched off rather than left open. /wp-json/wp-abilities/v1/abilities, the WordPress Abilities
API (an agent-callable tool surface, with a POST .../run endpoint), returns rest_forbidden 401
anonymously.
probes:
- url: https://dronecode.org/wp-json/
status: 200
note: 74 routes, namespaces yoast/v1, objectcache/v1, regenerate-thumbnails/v1, wp/v2, wp-site-health/v1, wp-block-editor/v1, wp-abilities/v1
- url: https://dronecode.org/wp-json/wp/v2/posts?per_page=1
status: 404
note: '{"code":"rest_no_route"} — the wp/v2 content routes are not registered'
- url: https://dronecode.org/wp-json/wp-abilities/v1/abilities
status: 401
note: '{"code":"rest_forbidden"} — the Abilities (agent tool) surface requires authentication'
docs: https://developer.wordpress.org/rest-api/
docs_note: >-
Third-party (WordPress core) documentation, not Dronecode's — but it is exactly what the
Foundation's own /.well-known/api-catalog names as this API's service-doc.
gaps:
- No OAuth 2.0, OpenID Connect, or delegated-identity surface anywhere in the estate.
- No scopes, so scopes/ is genuinely N/A rather than missing.
- >-
No /.well-known/oauth-authorization-server or /.well-known/oauth-protected-resource on any of the
eight hosts probed — all 404. See well-known/dronecode-well-known.yml.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dronecode-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.