Fixture · Authentication Profile

Fixture Authentication

Authentication

Fixture secures its APIs with http, apiKey, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.

CompanyCRMSalesB2BArtificial IntelligenceAgentsMCP
Methods: http, apiKey, oauth2 Schemes: 3 OAuth flows: API key in:

Security Schemes

bearerAuth http
scheme: bearer
api-key apiKey
· in: header ()
fixture-oauth oauth2
· flows:

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: https://fixture.app/docs/authentication/api-keys, https://fixture.app/docs/authentication/scopes,
  https://fixture.app/docs/api-reference/overview, https://beta-api.fixture.app/.well-known/oauth-authorization-server,
  openapi/fixture-v1-openapi.json
docs: https://fixture.app/docs/authentication/api-keys
summary:
  types:
  - http
  - apiKey
  - oauth2
  transport: Authorization header, bearer token only
  session_cookies_accepted: false
  notes: Session cookies are explicitly not accepted on /api/v1/*. Every request must carry
    an Authorization bearer header, or the API returns 401 unauthorized.
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: API key or OAuth access token
  description: Send either a Fixture API key or a Fixture OAuth access token in the Authorization
    header as a bearer token.
  sources:
  - openapi/fixture-v1-openapi.json
  - https://fixture.app/docs/api-reference/overview
- name: api-key
  type: apiKey
  in: header
  header: Authorization
  value_format: Bearer [example key]
  key_prefix: fx_
  description: Workspace API keys are the service-to-service credential for external integrations.
    Owner-only to list, create, or revoke. Shown once at creation; scopes are chosen explicitly
    at creation time with no implicit full-access default. Revocation is immediate and permanent.
  used_by: External integrations and service jobs
  docs: https://fixture.app/docs/authentication/api-keys
  sources:
  - https://fixture.app/docs/authentication/api-keys
- name: fixture-oauth
  type: oauth2
  description: Fixture OAuth is used by first-party Agent and CLI clients and by remote MCP
    clients. Authorization Server metadata is published at /.well-known/oauth-authorization-server
    on the API host, and the MCP endpoint publishes /.well-known/oauth-protected-resource.
    Public clients with PKCE S256; dynamic client registration is supported.
  issuer: https://beta-api.fixture.app
  flows:
    authorizationCode:
      authorizationUrl: https://beta-api.fixture.app/api/oauth/authorize
      tokenUrl: https://beta-api.fixture.app/api/oauth/token
      refreshUrl: https://beta-api.fixture.app/api/oauth/token
      scopes:
        crm:read: Read CRM records
        crm:write: Create and update CRM records
        tasks:read: Read Tasks
        tasks:write: Create and update Tasks
        users:read: Read team Users
  endpoints:
    authorization: https://beta-api.fixture.app/api/oauth/authorize
    token: https://beta-api.fixture.app/api/oauth/token
    revocation: https://beta-api.fixture.app/api/oauth/revoke
    registration: https://beta-api.fixture.app/api/oauth/register
  grant_types_supported:
  - authorization_code
  - refresh_token
  response_types_supported:
  - code
  token_endpoint_auth_methods_supported:
  - none
  code_challenge_methods_supported:
  - S256
  token_format: JWT-shaped bearer (eyJ...)
  used_by: Fixture CLI, in-app Agent clients, and remote MCP clients
  sources:
  - https://beta-api.fixture.app/.well-known/oauth-authorization-server
  - https://beta-api.fixture.app/.well-known/oauth-protected-resource
  - https://fixture.app/docs/guides/agents/fixture-mcp
failure_modes:
- status: 401
  code: unauthorized
  when: Missing or invalid bearer token.
- status: 403
  code: forbidden
  when: Valid bearer token but missing the required scope. Message names the missing scope.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fixture-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.