Flagsmith · Authentication Profile

Flagsmith Authentication

Authentication

Flagsmith secures its APIs with apiKey, http, and oauth2 across 7 declared security schemes, as derived from its OpenAPI definitions.

Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Methods: apiKey, http, oauth2 Schemes: 7 OAuth flows: API key in: header

Security Schemes

Environment API Key apiKey
· in: header (X-Environment-Key)
Master API Key apiKey
· in: header (Authorization)
tokenAuth apiKey
· in: header (Authorization)
Cohort Sync Key http
scheme: bearer
Cohort Sync Key (Basic) http
scheme: basic
basicAuth http
scheme: basic
OAuth 2.0 oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: >-
  https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/management-api/authentication,
  https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/flags-api/authentication,
  https://docs.flagsmith.com/integrating-with-flagsmith/mcp-server,
  https://api.flagsmith.com/.well-known/oauth-authorization-server (200), and
  openapi/_original/flagsmith-api-openapi.json#/components/securitySchemes (six declared schemes).
docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/
supersedes: >-
  The 2026-09-17 derived pass, which read only the nine split specs in openapi/ and saw a single
  apiKey scheme. The harvested first-party contract declares six, and OAuth 2.0 is declared in none
  of them — it is only visible in the .well-known metadata.
summary:
  types: [apiKey, http, oauth2]
  api_key_in: [header]
  oauth2: true
  mtls: false
  openid_connect: false
key_insight: >-
  Two API surfaces, two different keys, and they are not interchangeable — this is the thing to get
  right first. The SDK/Flags API on edge.api.flagsmith.com takes a NON-SECRET environment key in
  X-Environment-Key and is safe in client-side code. The Management API on api.flagsmith.com takes a
  SECRET organisation key in Authorization with a mandatory `Api-Key ` prefix and must never reach a
  browser. A third path, OAuth 2.0, exists only for the MCP server and the Management API and is
  absent from the OpenAPI entirely.
schemes:
- name: Environment API Key
  type: apiKey
  in: header
  parameter: X-Environment-Key
  secret: false
  surface: SDK / Flags API (https://edge.api.flagsmith.com)
  description: >-
    Per-environment client-side key, found in the dashboard under the project's Environments tab.
    Safe to ship in client-side code by design. SDKs set the header for you on initialisation; direct
    HTTP callers must set it on every request.
  docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/flags-api/authentication
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Master API Key
  type: apiKey
  in: header
  parameter: Authorization
  value_format: 'Api-Key <key>'
  secret: true
  surface: Management API (https://api.flagsmith.com/api/v1)
  description: >-
    Organisation-level secret token. The `Api-Key ` prefix is required — the header must read
    `Api-Key ser.abc123…`, not the bare key. Requests act with the permissions of the key's user, so
    administrator privileges are not required and RBAC still applies.
  docs: https://docs.flagsmith.com/integrating-with-flagsmith/flagsmith-api-overview/management-api/authentication
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: tokenAuth
  type: apiKey
  in: header
  parameter: Authorization
  value_format: 'Token <key>'
  secret: true
  surface: Management API
  description: Django REST Framework token authentication, used by session/user tokens rather than organisation keys.
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Cohort Sync Key
  type: http
  scheme: bearer
  secret: true
  surface: Cohort sync webhooks
  description: For cohort-sync endpoints called by an external cohort source, such as Amplitude.
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: Cohort Sync Key (Basic)
  type: http
  scheme: basic
  secret: true
  surface: Cohort sync webhooks
  description: >-
    For cohort sources that can only send Basic credentials, such as Mixpanel. The key is the
    password; the username is ignored.
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: basicAuth
  type: http
  scheme: basic
  secret: true
  surface: Management API (legacy/internal)
  sources: [openapi/_original/flagsmith-api-openapi.json]
- name: OAuth 2.0
  type: oauth2
  flow: authorization_code
  pkce: S256
  scopes: [mcp, admin-api]
  surface: MCP server (https://mcp.flagsmith.com) and Management API
  authorization_server: https://api.flagsmith.com
  discovery: https://api.flagsmith.com/.well-known/oauth-authorization-server
  dynamic_client_registration: https://api.flagsmith.com/o/register/
  description: >-
    Not declared anywhere in the OpenAPI — discoverable only from the RFC 8414 document on the API
    host and the RFC 9728 document on the MCP host. Interactive MCP clients use it to avoid handling
    an API key at all.
  docs: https://docs.flagsmith.com/integrating-with-flagsmith/mcp-server
  see: scopes/flagsmith-scopes.yml
sso:
  note: >-
    End-user sign-in to the Flagsmith dashboard (not API authentication) supports SAML 2.0, Okta,
    ADFS, LDAP, Google and GitHub OAuth, plus 2FA. SAML, LDAP and SCIM provisioning are Enterprise;
    2FA is available from the Start-Up plan.
  docs: https://docs.flagsmith.com/administration-and-security/access-control/
  standards: [SAML 2.0, LDAP, SCIM 2.0]
authorization:
  model: RBAC
  note: >-
    Roles, permission groups and per-project/per-environment permissions gate every Management API
    call; custom roles are Enterprise. 34 operations in the contract are tagged Permissions.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flagsmith-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.