Ferguson Authentication
Ferguson's Enterprise APIs are OAuth 2.0 protected. A partner registers on the Ferguson Developer Portal, is approved, creates a Developer/Team App, and receives a Key and Secret. The Key and Secret are base64-encoded into an HTTP Basic Authorization header on a call to the OAuth 2.0 token endpoint with grant_type=client_credentials; the returned access token is then presented on API calls as an Authorization header with the Bearer token type per RFC 6750. Ferguson's own portal documentation also covers the Authorization Code and Resource Owner Password Credentials (ROPC) grants. The token and API host names are published only inside the gated portal, so no endpoint URLs are recorded here.
Ferguson declares 4 security scheme(s) across its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.