Facilio · Authentication Profile

Facilio Authentication

Authentication

Facilio secures its APIs with apiKey and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and password flow(s).

CompanyAiFacility ManagementCMMSProperty OperationsMaintenanceAsset ManagementReal EstateIoTBuildings
Methods: apiKey, oauth2 Schemes: 2 OAuth flows: authorizationCode, password API key in: header

Security Schemes

apiKey apiKey
· in: header (x-api-key)
oauth2 oauth2
· flows: authorizationCode, password

Source

Authentication Profile

Raw ↑
generated: '2026-07-19'
method: searched
source: openapi/facilio-openapi-original.yaml
docs: https://facilio.com/developers/docs/api-reference/
notes: >-
  Two auth models. API-key requests use the 'maintenance' app on the regional
  host (x-api-key header). OAuth2 requests use the 'developer' app. Host template
  is https://{region}.facilioapis.com/{app_name}/api/v5 with region in
  [us, au, ae, uk, us-azure, sa]. OAuth2 identity endpoints are region-scoped
  (e.g. https://us.facilioapis.com/identity/oauth2/...). The hosted MCP server
  (mcp.facilio.com) is a separate OAuth 2.0 authorization server with granular
  scopes — see scopes/facilio-scopes.yml.
summary:
  types:
  - apiKey
  - oauth2
  api_key_in:
  - header
  oauth2_flows:
  - authorizationCode
  - password
schemes:
- name: apiKey
  type: apiKey
  in: header
  parameter: x-api-key
  description: Personal access token
  sources:
  - openapi/facilio-openapi-original.yaml
- name: oauth2
  type: oauth2
  flows:
  - flow: authorizationCode
    authorizationUrl: https://us.facilioapis.com/identity/oauth2/authorize
    tokenUrl: https://us.facilioapis.com/identity/oauth2/token
    scopes: 0
  - flow: password
    tokenUrl: https://us.facilioapis.com/identity/oauth2/token
    scopes: 0
  description: Supports authorization_code and password grant types
  sources:
  - openapi/facilio-openapi-original.yaml