Fixture · Authentication Profile

Fixture Authentication

Authentication

Fixture secures its APIs with http, apiKey, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.

CompanyCRMSalesB2BArtificial IntelligenceAgentsMCPCustomer Relationship Management
Methods: http, apiKey, oauth2 Schemes: 3 OAuth flows: API key in:

Security Schemes

bearerAuth http
scheme: bearer
api-key apiKey
· in: header ()
fixture-oauth oauth2
· flows:

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: https://fixture.app/docs/authentication/api-keys, https://fixture.app/docs/authentication/scopes,
  https://fixture.app/docs/api-reference/overview, https://beta-api.fixture.app/.well-known/oauth-authorization-server,
  openapi/fixture-v1-openapi.json
docs: https://fixture.app/docs/authentication/api-keys
summary:
  types:
  - http
  - apiKey
  - oauth2
  transport: Authorization header, bearer token only
  session_cookies_accepted: false
  notes: Session cookies are explicitly not accepted on /api/v1/*. Every request must carry
    an Authorization bearer header, or the API returns 401 unauthorized.
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: API key or OAuth access token
  description: Send either a Fixture API key or a Fixture OAuth access token in the Authorization
    header as a bearer token.
  sources:
  - openapi/fixture-v1-openapi.json
  - https://fixture.app/docs/api-reference/overview
- name: api-key
  type: apiKey
  in: header
  header: Authorization
  value_format: Bearer [example key]
  key_prefix: fx_
  description: Workspace API keys are the service-to-service credential for external integrations.
    Owner-only to list, create, or revoke. Shown once at creation; scopes are chosen explicitly
    at creation time with no implicit full-access default. Revocation is immediate and permanent.
  used_by: External integrations and service jobs
  docs: https://fixture.app/docs/authentication/api-keys
  sources:
  - https://fixture.app/docs/authentication/api-keys
- name: fixture-oauth
  type: oauth2
  description: Fixture OAuth is used by first-party Agent and CLI clients and by remote MCP
    clients. Authorization Server metadata is published at /.well-known/oauth-authorization-server
    on the API host, and the MCP endpoint publishes /.well-known/oauth-protected-resource.
    Public clients with PKCE S256; dynamic client registration is supported.
  issuer: https://beta-api.fixture.app
  flows:
    authorizationCode:
      authorizationUrl: https://beta-api.fixture.app/api/oauth/authorize
      tokenUrl: https://beta-api.fixture.app/api/oauth/token
      refreshUrl: https://beta-api.fixture.app/api/oauth/token
      scopes:
        crm:read: Read CRM records
        crm:write: Create and update CRM records
        tasks:read: Read Tasks
        tasks:write: Create and update Tasks
        users:read: Read team Users
  endpoints:
    authorization: https://beta-api.fixture.app/api/oauth/authorize
    token: https://beta-api.fixture.app/api/oauth/token
    revocation: https://beta-api.fixture.app/api/oauth/revoke
    registration: https://beta-api.fixture.app/api/oauth/register
  grant_types_supported:
  - authorization_code
  - refresh_token
  response_types_supported:
  - code
  token_endpoint_auth_methods_supported:
  - none
  code_challenge_methods_supported:
  - S256
  token_format: JWT-shaped bearer (eyJ...)
  used_by: Fixture CLI, in-app Agent clients, and remote MCP clients
  sources:
  - https://beta-api.fixture.app/.well-known/oauth-authorization-server
  - https://beta-api.fixture.app/.well-known/oauth-protected-resource
  - https://fixture.app/docs/guides/agents/fixture-mcp
failure_modes:
- status: 401
  code: unauthorized
  when: Missing or invalid bearer token.
- status: 403
  code: forbidden
  when: Valid bearer token but missing the required scope. Message names the missing scope.