First Street · Authentication Profile
First Street Authentication
Authentication
One static API key authenticates every First Street machine surface — REST tiles, both GraphQL endpoints, and the MCP server. There is no OAuth, no OIDC, no token exchange and no scope vocabulary. What replaces scopes is a contractual, per-schema-node entitlement model applied server-side, which is why a valid key can still be refused an individual field.
First Street secures its APIs with apiKey and http across 2 declared security schemes, as derived from its OpenAPI definitions.
ClimateRisk ManagementEnvironmentModelingGeospatialInsuranceReal EstateDataGraphQLMapping
Methods: apiKey, http
Schemes: 2
OAuth flows:
API key in: query, header
Security Schemes
apiKeyQuery apiKey
bearerAuth http
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.