IRIZ Platform · Authentication Profile

Fashionbyu Com Authentication

Authentication

IRIZ Platform secures its APIs with apiKey, http, none, hmac-signature, and http-message-signature across 6 declared security schemes, as derived from its OpenAPI definitions.

CompanyFashionE-CommerceAgentic CommerceStorefrontProduct FeedsMCPA2AAI AgentsCheckoutCartOrderCloudflare Workers
Methods: apiKey, http, none, hmac-signature, http-message-signature Schemes: 6 OAuth flows: API key in: query

Security Schemes

apiKey apiKey
· in: query (p)
bearerAuth http
scheme: bearer
agent-commerce-bearer http
scheme: bearer
peerHmac apiKey
· in: header (x-iriz-peer-sig)
interop-bearer http
scheme: bearer
webBotAuth http
scheme: signature

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: openapi/fashionbyu-com-iriz-platform-api-openapi.yml (securitySchemes) upgraded with the live 401 bodies observed
  on 2026-09-19, the MCP server instructions (initialize) and GET /iriz/v1/agent/mcp write_auth, and the securitySchemes
  of both A2A agent cards
summary:
  types:
  - apiKey
  - http
  - none
  - hmac-signature
  - http-message-signature
  api_key_in:
  - query
  public_surface: Agent-commerce read routes and MCP tools/list, initialize and read tools answer with no credentials
  auth_levels:
    standard: GET /iriz/status, /iriz/version, /iriz/interop/status, /iriz/interop/a2ui/catalog -> 401 {"code":"UNAUTHORIZED","auth_level":"standard"}
    boss: GET /iriz/agent-commerce/status -> 401 auth_level boss; robots.txt disallows /boss/
    issuance: not documented publicly on any readable page
schemes:
- name: apiKey
  type: apiKey
  in: query
  parameter: p
  description: Platform gateway password or token
  sources:
  - openapi/fashionbyu-com-iriz-platform-api-openapi.yml
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  sources:
  - openapi/fashionbyu-com-iriz-platform-api-openapi.yml
- name: agent-commerce-bearer
  type: http
  scheme: bearer
  applies_to:
  - MCP create_cart, mutate_cart, quote_cart, confirm_checkout
  - POST /iriz/v1/agent/cart/session (401 "Agent token required when configured")
  conditional: true
  description: '"Authorization: Bearer <IRIZ_AGENT_COMMERCE_TOKEN> when configured" — the commerce agent card records token_required:
    false and the read tools were called live without a token'
  sources:
  - mcp/fashionbyu-com-mcp-initialize.json
  - a2a/fashionbyu-com-agent-card.json
- name: peerHmac
  type: apiKey
  in: header
  parameter: x-iriz-peer-sig
  applies_to:
  - 'A2A interop: POST /iriz/interop/tasks (401 peer_credentials_required without it)'
  description: HMAC-SHA256(peer_secret, "<peer>.<ts>.<nonce>.<sha256(body)>") sent with x-iriz-peer-id, x-iriz-peer-ts,
    x-iriz-peer-nonce headers
  sources:
  - a2a/fashionbyu-com-interop-agent-card.json
- name: interop-bearer
  type: http
  scheme: bearer
  applies_to:
  - A2A interop
  description: Short-lived token from POST /iriz/interop/token { peer_id, secret } (GET on that path is 404 endpoint_not_found;
    POST not attempted — requires a registered peer secret)
  sources:
  - a2a/fashionbyu-com-interop-agent-card.json
- name: webBotAuth
  type: http
  scheme: signature
  applies_to:
  - A2A interop
  description: RFC 9421 HTTP message signature; verified signatures raise trust tier (declared, not verifiable anonymously)
  sources:
  - a2a/fashionbyu-com-interop-agent-card.json
docs: https://mirror.fashionbyu.com/iriz/docs
oauth:
  present: false
  evidence: no oauth2/openIdConnect scheme in the spec; /.well-known/oauth-authorization-server, oauth-protected-resource
    and openid-configuration are 403 on fashionbyu.com and on the MCP host mirror.fashionbyu.com
note: The OpenAPI declares two schemes but applies neither to any operation (security is absent on 107 of 108 operations),
  so the spec cannot say which routes need which credential; the applicability above is what the live server answered.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fashionbyu-com-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.