Fixture · Authentication Profile
Fixture Authentication
Authentication
Fixture secures its APIs with http, apiKey, and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.
CompanyCRMSalesB2BArtificial IntelligenceAgentsMCP
Methods: http, apiKey, oauth2
Schemes: 3
OAuth flows:
API key in:
Security Schemes
bearerAuth http
scheme: bearer
api-key apiKey
· in: header ()
fixture-oauth oauth2
· flows:
Source
Authentication Profile
generated: '2026-07-20'
method: searched
source: https://fixture.app/docs/authentication/api-keys, https://fixture.app/docs/authentication/scopes,
https://fixture.app/docs/api-reference/overview, https://beta-api.fixture.app/.well-known/oauth-authorization-server,
openapi/fixture-v1-openapi.json
docs: https://fixture.app/docs/authentication/api-keys
summary:
types:
- http
- apiKey
- oauth2
transport: Authorization header, bearer token only
session_cookies_accepted: false
notes: Session cookies are explicitly not accepted on /api/v1/*. Every request must carry
an Authorization bearer header, or the API returns 401 unauthorized.
schemes:
- name: bearerAuth
type: http
scheme: bearer
bearerFormat: API key or OAuth access token
description: Send either a Fixture API key or a Fixture OAuth access token in the Authorization
header as a bearer token.
sources:
- openapi/fixture-v1-openapi.json
- https://fixture.app/docs/api-reference/overview
- name: api-key
type: apiKey
in: header
header: Authorization
value_format: Bearer [example key]
key_prefix: fx_
description: Workspace API keys are the service-to-service credential for external integrations.
Owner-only to list, create, or revoke. Shown once at creation; scopes are chosen explicitly
at creation time with no implicit full-access default. Revocation is immediate and permanent.
used_by: External integrations and service jobs
docs: https://fixture.app/docs/authentication/api-keys
sources:
- https://fixture.app/docs/authentication/api-keys
- name: fixture-oauth
type: oauth2
description: Fixture OAuth is used by first-party Agent and CLI clients and by remote MCP
clients. Authorization Server metadata is published at /.well-known/oauth-authorization-server
on the API host, and the MCP endpoint publishes /.well-known/oauth-protected-resource.
Public clients with PKCE S256; dynamic client registration is supported.
issuer: https://beta-api.fixture.app
flows:
authorizationCode:
authorizationUrl: https://beta-api.fixture.app/api/oauth/authorize
tokenUrl: https://beta-api.fixture.app/api/oauth/token
refreshUrl: https://beta-api.fixture.app/api/oauth/token
scopes:
crm:read: Read CRM records
crm:write: Create and update CRM records
tasks:read: Read Tasks
tasks:write: Create and update Tasks
users:read: Read team Users
endpoints:
authorization: https://beta-api.fixture.app/api/oauth/authorize
token: https://beta-api.fixture.app/api/oauth/token
revocation: https://beta-api.fixture.app/api/oauth/revoke
registration: https://beta-api.fixture.app/api/oauth/register
grant_types_supported:
- authorization_code
- refresh_token
response_types_supported:
- code
token_endpoint_auth_methods_supported:
- none
code_challenge_methods_supported:
- S256
token_format: JWT-shaped bearer (eyJ...)
used_by: Fixture CLI, in-app Agent clients, and remote MCP clients
sources:
- https://beta-api.fixture.app/.well-known/oauth-authorization-server
- https://beta-api.fixture.app/.well-known/oauth-protected-resource
- https://fixture.app/docs/guides/agents/fixture-mcp
failure_modes:
- status: 401
code: unauthorized
when: Missing or invalid bearer token.
- status: 403
code: forbidden
when: Valid bearer token but missing the required scope. Message names the missing scope.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fixture-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.